2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14851 | — | — | 4.3% | Aug 2, 2018 | exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2... |
| CVE-2018-1155 | MEDIUM | 5.4 | 0.6% | Aug 2, 2018 | In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to i... |
| CVE-2018-1154 | HIGH | 8.8 | 0.7% | Aug 2, 2018 | In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to autom... |
| CVE-2018-10922 | HIGH | 7.5 | 0.9% | Aug 2, 2018 | An input validation flaw exists in ttembed. With a crafted input file, an attacker may be able to trigger a denial of se... |
| CVE-2018-10921 | MEDIUM | 4.3 | 1.0% | Aug 2, 2018 | Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially le... |
| CVE-2018-7649 | — | — | 0.6% | Aug 2, 2018 | Monitorix before 3.10.1 allows XSS via CGI variables. |
| CVE-2018-8037 | — | — | 12.1% | Aug 2, 2018 | If an async request was completed by the application at the same time as the container triggered the async timeout, a ra... |
| CVE-2018-1554 | MEDIUM | 5.4 | 1.0% | Aug 2, 2018 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2018-1336 | HIGH | 7.5 | 20.6% | Aug 2, 2018 | An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the d... |
| CVE-2018-8032 | MEDIUM | 6.1 | 10.6% | Aug 2, 2018 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/serv... |
| CVE-2018-1329 | — | — | — | Aug 2, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-12448 | — | — | 0.8% | Aug 2, 2018 | Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar wh... |
| CVE-2018-10920 | MEDIUM | 6.8 | 3.2% | Aug 2, 2018 | Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison c... |
| CVE-2018-3109 | — | — | 2.0% | Aug 2, 2018 | Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder... |
| CVE-2018-3108 | — | — | 1.8% | Aug 2, 2018 | Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: Oracle Notification S... |
| CVE-2018-2933 | — | — | 1.0% | Aug 2, 2018 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S... |
| CVE-2018-14847 | CRITICAL | 9.1 | 96.1% | Aug 2, 2018 | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated ... |
| CVE-2018-14840 | — | — | 3.7% | Aug 2, 2018 | uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for exam... |
| CVE-2018-14838 | — | — | 0.7% | Aug 2, 2018 | rejucms 2.1 has stored XSS via the admin/book.php content parameter. |
| CVE-2018-14836 | — | — | 1.0% | Aug 2, 2018 | Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able... |
| CVE-2018-14835 | — | — | 0.7% | Aug 2, 2018 | Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed i... |
| CVE-2018-10624 | — | — | 0.8% | Aug 1, 2018 | In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerabilit... |
| CVE-2018-3939 | HIGH | 8.8 | 2.3% | Aug 1, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.... |
| CVE-2018-3924 | HIGH | 8.8 | 44.1% | Aug 1, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version... |
| CVE-2018-3881 | CRITICAL | 9.4 | 1.2% | Aug 1, 2018 | An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticate... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now