2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11495 | — | — | 1.7% | May 26, 2018 | OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via... |
| CVE-2018-11494 | — | — | 2.4% | May 26, 2018 | The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move,... |
| CVE-2018-11493 | — | — | 0.7% | May 26, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m... |
| CVE-2018-11487 | — | — | 0.7% | May 26, 2018 | PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php. |
| CVE-2018-9091 | — | — | 3.3% | May 25, 2018 | A critical vulnerability in the KEMP LoadMaster Operating System (LMOS) 6.0.44 through 7.2.41.2 and Long Term Support (L... |
| CVE-2018-11479 | — | — | 9.9% | May 25, 2018 | The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s... |
| CVE-2018-11475 | — | — | 1.1% | May 25, 2018 | Monstra CMS 3.0.4 has a Session Management Issue in the Users tab. A password change at users/1/edit does not invalidate... |
| CVE-2018-11474 | — | — | 1.1% | May 25, 2018 | Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=use... |
| CVE-2018-11473 | — | — | 2.3% | May 25, 2018 | Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration). |
| CVE-2018-11472 | — | — | 0.9% | May 25, 2018 | Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php). |
| CVE-2018-11471 | — | — | 0.6% | May 25, 2018 | Cockpit 0.5.5 has XSS via a collection, form, or region. |
| CVE-2018-8864 | — | — | 0.2% | May 25, 2018 | In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, a missing encryption ... |
| CVE-2018-8862 | — | — | 0.6% | May 25, 2018 | In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentic... |
| CVE-2018-6237 | — | — | 6.4% | May 25, 2018 | A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker t... |
| CVE-2018-6236 | — | — | 0.3% | May 25, 2018 | A Time-of-Check Time-of-Use privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could all... |
| CVE-2018-6235 | — | — | 0.5% | May 25, 2018 | An Out-of-Bounds write privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a ... |
| CVE-2018-6234 | — | — | 0.7% | May 25, 2018 | An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a... |
| CVE-2018-6233 | — | — | 0.5% | May 25, 2018 | A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local... |
| CVE-2018-6232 | — | — | 0.5% | May 25, 2018 | A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local... |
| CVE-2018-10350 | — | — | 15.2% | May 25, 2018 | A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow ... |
| CVE-2018-1459 | — | — | 0.5% | May 25, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to stack based... |
| CVE-2018-1452 | — | — | 0.4% | May 25, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha... |
| CVE-2018-1451 | — | — | 0.4% | May 25, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha... |
| CVE-2018-1450 | — | — | 0.4% | May 25, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha... |
| CVE-2018-1449 | — | — | 0.4% | May 25, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now