2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0349 | CRITICAL | 9.8 | 3.0% | Jul 18, 2018 | A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files ... |
| CVE-2018-0348 | HIGH | 7.2 | 2.9% | Jul 18, 2018 | A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrar... |
| CVE-2018-0347 | — | — | 0.5% | Jul 18, 2018 | A vulnerability in the Zero Touch Provisioning (ZTP) subsystem of the Cisco SD-WAN Solution could allow an authenticated... |
| CVE-2018-0346 | — | — | 2.0% | Jul 18, 2018 | A vulnerability in the Zero Touch Provisioning service of the Cisco SD-WAN Solution could allow an unauthenticated, remo... |
| CVE-2018-0345 | HIGH | 8.8 | 3.0% | Jul 18, 2018 | A vulnerability in the configuration and management database of the Cisco SD-WAN Solution could allow an authenticated, ... |
| CVE-2018-0344 | — | — | 2.0% | Jul 18, 2018 | A vulnerability in the vManage dashboard for the configuration and management service of the Cisco SD-WAN Solution could... |
| CVE-2018-0343 | — | — | 2.0% | Jul 18, 2018 | A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, r... |
| CVE-2018-0342 | — | — | 0.5% | Jul 18, 2018 | A vulnerability in the configuration and monitoring service of the Cisco SD-WAN Solution could allow an authenticated, l... |
| CVE-2018-14389 | — | — | 1.5% | Jul 18, 2018 | joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter. |
| CVE-2018-14388 | — | — | 0.8% | Jul 18, 2018 | joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter. |
| CVE-2018-14387 | — | — | 1.6% | Jul 18, 2018 | An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record ... |
| CVE-2018-14364 | — | — | 50.1% | Jul 18, 2018 | GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Tra... |
| CVE-2018-7546 | — | — | 1.4% | Jul 18, 2018 | wpsmain.dll in Kingsoft WPS Office 2016 and Jinshan PDF 10.1.0.6621 allows remote attackers to cause a denial of service... |
| CVE-2018-14082 | — | — | 0.7% | Jul 18, 2018 | PHP Scripts Mall JOB SITE (aka Job Portal) 3.0.1 has Cross-site Scripting (XSS) via the search bar. |
| CVE-2018-12429 | — | — | 0.5% | Jul 18, 2018 | JEESNS through 1.2.1 allows XSS attacks by ordinary users who publish articles containing a crafted payload in order to ... |
| CVE-2018-8042 | — | — | 1.8% | Jul 18, 2018 | Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational ... |
| CVE-2018-14382 | — | — | 0.9% | Jul 18, 2018 | InstantCMS 2.10.1 has /redirect?url= XSS. |
| CVE-2018-14381 | — | — | 1.0% | Jul 18, 2018 | Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability. |
| CVE-2018-14380 | — | — | 1.0% | Jul 18, 2018 | In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and c... |
| CVE-2018-10877 | HIGH | 7.3 | 2.3% | Jul 18, 2018 | Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating... |
| CVE-2018-10616 | — | — | 1.2% | Jul 18, 2018 | ABB Panel Builder 800 all versions has an improper input validation vulnerability which may allow an attacker to insert ... |
| CVE-2018-8011 | — | — | 51.7% | Jul 18, 2018 | By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child p... |
| CVE-2018-5232 | — | — | 1.0% | Jul 18, 2018 | The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows r... |
| CVE-2018-3105 | — | — | 0.9% | Jul 18, 2018 | Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Health Care FastPath). Suppor... |
| CVE-2018-3104 | — | — | 1.5% | Jul 18, 2018 | Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now