2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11196 | — | — | 0.9% | Jun 1, 2018 | Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses ... |
| CVE-2018-11195 | — | — | 0.5% | Jun 1, 2018 | Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and re... |
| CVE-2018-3742 | — | — | — | Jun 1, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-3745. Reason: This candidate is a reservation ... |
| CVE-2018-11671 | — | — | 2.5% | Jun 1, 2018 | An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php... |
| CVE-2018-11670 | — | — | 2.5% | Jun 1, 2018 | An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary ... |
| CVE-2018-11581 | — | — | 1.6% | Jun 1, 2018 | Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web s... |
| CVE-2018-11552 | — | — | 28.6% | Jun 1, 2018 | There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerabili... |
| CVE-2018-11551 | — | — | 2.5% | Jun 1, 2018 | AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arb... |
| CVE-2018-10382 | — | — | 0.7% | Jun 1, 2018 | MODX Revolution 2.6.3 has XSS. |
| CVE-2018-11657 | — | — | 1.1% | Jun 1, 2018 | ngiflib.c in MiniUPnP ngiflib 0.4 has an infinite loop in DecodeGifImg and LoadGif. |
| CVE-2018-11656 | — | — | 1.8% | Jun 1, 2018 | In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, ... |
| CVE-2018-11655 | — | — | 1.7% | Jun 1, 2018 | In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCo... |
| CVE-2018-11652 | — | — | 24.7% | Jun 1, 2018 | CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the S... |
| CVE-2018-11628 | — | — | 3.5% | Jun 1, 2018 | Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malici... |
| CVE-2018-11486 | — | — | 0.8% | Jun 1, 2018 | An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plu... |
| CVE-2018-11485 | — | — | 0.8% | Jun 1, 2018 | The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an... |
| CVE-2018-7976 | — | — | 0.6% | Jun 1, 2018 | There is a stored cross-site scripting (XSS) vulnerability in Huawei eSpace Desktop V300R001C00 and V300R001C50 version.... |
| CVE-2018-7951 | — | — | 2.0% | Jun 1, 2018 | The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to... |
| CVE-2018-7950 | — | — | 2.0% | Jun 1, 2018 | The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to... |
| CVE-2018-7949 | — | — | 1.1% | Jun 1, 2018 | The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability.... |
| CVE-2018-5526 | — | — | 2.0% | Jun 1, 2018 | Under certain conditions, on F5 BIG-IP ASM 13.1.0-13.1.0.5, Behavioral DOS (BADOS) protection may fail during an attack. |
| CVE-2018-5525 | — | — | 1.0% | Jun 1, 2018 | A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.... |
| CVE-2018-5524 | — | — | 1.7% | Jun 1, 2018 | Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configu... |
| CVE-2018-5523 | — | — | 2.3% | Jun 1, 2018 | On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 and Enterprise Manager ... |
| CVE-2018-5522 | — | — | 1.5% | Jun 1, 2018 | On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions wit... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now