2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-5995The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sens...
CVE-2018-5953MEDIUM5.5The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensit...
CVE-2018-15132An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and...
CVE-2018-12885The randMod() function of the smart contract implementation for MyCryptoChamp, an Ethereum game, generates a random valu...
CVE-2018-11456A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network a...
CVE-2018-11455A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4), Automation License Manager...
CVE-2018-11454A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), ...
CVE-2018-11453A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), ...
CVE-2018-15130ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.
CVE-2018-1690MEDIUM5.4IBM Rhapsody Model Manager 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2018-15129ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.
CVE-2018-14869PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field i...
CVE-2018-14857Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventor...
CVE-2018-7092A potential security vulnerability has been identified in HPE Intelligent Management Center Platform (IMC Plat) 7.3 E050...
CVE-2018-7091HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 t...
CVE-2018-7090HPE XP P9000 Command View Advanced Edition Software (CVAE) has local and remote cross site scripting vulnerability in ve...
CVE-2018-7078A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integra...
CVE-2018-7075A remote cross-site scripting (XSS) vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT version...
CVE-2018-7074A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT 7.3 E0506P07. The v...
CVE-2018-7073A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.
CVE-2018-7072A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.2...
CVE-2018-7071HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Directo...
CVE-2018-7070HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier tha...
CVE-2018-7069HPE has identified a remote unauthenticated access to files vulnerability in HPE CentralView Fraud Risk Management earli...
CVE-2018-7068HPE has identified a remote HOST header attack vulnerability in HPE CentralView Fraud Risk Management earlier than versi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now