2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0557 | — | — | 0.8% | Jun 26, 2018 | Stored cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary ... |
| CVE-2018-0529 | — | — | 1.1% | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors. |
| CVE-2018-0528 | — | — | 0.9% | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are no... |
| CVE-2018-0527 | — | — | 0.8% | Jun 26, 2018 | Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to inject arbitrary web scr... |
| CVE-2018-0526 | — | — | 1.0% | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.7.0 allow remote attackers to display an image located in an external server via unspecified ... |
| CVE-2018-12889 | — | — | 1.7% | Jun 26, 2018 | An issue was discovered in CCN-lite 2.0.1. There is a heap-based buffer overflow in mkAddToRelayCacheRequest and in ccnl... |
| CVE-2018-12884 | — | — | 0.8% | Jun 26, 2018 | In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create ... |
| CVE-2018-12882 | — | — | 6.6% | Jun 26, 2018 | exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_... |
| CVE-2018-12603 | — | — | 3.6% | Jun 25, 2018 | Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authen... |
| CVE-2018-11589 | — | — | 2.1% | Jun 25, 2018 | Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU par... |
| CVE-2018-11588 | — | — | 1.1% | Jun 25, 2018 | Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the usernam... |
| CVE-2018-11587 | — | — | 4.2% | Jun 25, 2018 | There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric f... |
| CVE-2018-12735 | — | — | 1.4% | Jun 25, 2018 | SAJ Solar Inverter allows remote attackers to obtain potentially sensitive information via a direct request for the inve... |
| CVE-2018-8755 | — | — | 1.1% | Jun 25, 2018 | NuCom WR644GACV devices before STA006 allow an attacker to download the configuration file without credentials. By downl... |
| CVE-2018-12602 | — | — | 3.0% | Jun 25, 2018 | A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily. |
| CVE-2018-11046 | — | — | 0.9% | Jun 25, 2018 | Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks securit... |
| CVE-2018-11041 | — | — | 0.9% | Jun 25, 2018 | Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later ... |
| CVE-2018-10956 | — | — | 56.3% | Jun 25, 2018 | IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal. |
| CVE-2018-1000555 | — | — | — | Jun 25, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10188. Reason: This candidate is a reservation... |
| CVE-2018-1000545 | — | — | — | Jun 25, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11416. Reason: This candidate is a reservation... |
| CVE-2018-1000541 | — | — | — | Jun 25, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10362. Reason: This candidate is a reservation... |
| CVE-2018-1000530 | — | — | — | Jun 25, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11522. Reason: This candidate is a reservation... |
| CVE-2018-1000522 | — | — | — | Jun 25, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10364. Reason: This candidate is a reservation... |
| CVE-2018-12084 | — | — | 0.9% | Jun 25, 2018 | The mintToken function of a smart contract implementation for BitAsean (BAS), a tradable Ethereum ERC20 token, has no pe... |
| CVE-2018-12083 | — | — | 0.9% | Jun 25, 2018 | The mintToken function of a smart contract implementation for GOAL Bonanza (GOAL), a tradable Ethereum ERC20 token, has ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now