2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17376 | — | — | 3.2% | Sep 28, 2018 | SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter... |
| CVE-2018-17375 | — | — | 3.3% | Sep 28, 2018 | SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter. |
| CVE-2018-17056 | — | — | 0.8% | Sep 28, 2018 | Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows re... |
| CVE-2018-17055 | — | — | 1.0% | Sep 28, 2018 | An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads. |
| CVE-2018-16659 | CRITICAL | 9.8 | 2.7% | Sep 28, 2018 | An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked q... |
| CVE-2018-16587 | — | — | 1.8% | Sep 28, 2018 | In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker coul... |
| CVE-2018-16586 | — | — | 1.5% | Sep 28, 2018 | In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker coul... |
| CVE-2018-16277 | — | — | 0.6% | Sep 28, 2018 | The Image Import function in XWiki through 10.7 has XSS. |
| CVE-2018-14957 | — | — | 1.6% | Sep 28, 2018 | CMS ISWEB 3.5.3 is vulnerable to directory traversal and local file download, as demonstrated by moduli/downloadFile.php... |
| CVE-2018-14956 | — | — | 2.6% | Sep 28, 2018 | CMS ISWEB 3.5.3 is vulnerable to multiple SQL injection flaws. An attacker can inject malicious queries into the applica... |
| CVE-2018-14037 | — | — | 1.2% | Sep 28, 2018 | Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbit... |
| CVE-2018-15611 | MEDIUM | 6.3 | 0.3% | Sep 27, 2018 | A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authentica... |
| CVE-2018-14824 | — | — | 2.0% | Sep 27, 2018 | Delta Electronics Delta Industrial Automation PMSoft v2.11 or prior has an out-of-bounds read vulnerability that can be ... |
| CVE-2018-14650 | MEDIUM | 5.9 | 0.4% | Sep 27, 2018 | It was discovered that sos-collector does not properly set the default permissions of newly created files, making all fi... |
| CVE-2018-1820 | MEDIUM | 5.4 | 1.0% | Sep 27, 2018 | IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2018-1736 | HIGH | 7.4 | 1.5% | Sep 27, 2018 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open red... |
| CVE-2018-1716 | MEDIUM | 6.1 | 1.3% | Sep 27, 2018 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to em... |
| CVE-2018-1660 | MEDIUM | 5.4 | 1.1% | Sep 27, 2018 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to em... |
| CVE-2018-7109 | — | — | 1.0% | Sep 27, 2018 | HPE has addressed a remote arbitrary file modification vulnerability in HPE enhanced Internet Usage Manager (eIUM) v9.0F... |
| CVE-2018-7108 | — | — | 2.5% | Sep 27, 2018 | HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote auth... |
| CVE-2018-7107 | — | — | 0.9% | Sep 27, 2018 | A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. ... |
| CVE-2018-7106 | — | — | — | Sep 27, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-7105 | — | — | 4.1% | Sep 27, 2018 | A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lig... |
| CVE-2018-7104 | — | — | 8.9% | Sep 27, 2018 | A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manage... |
| CVE-2018-7103 | — | — | 8.9% | Sep 27, 2018 | A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manage... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now