2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7465 | — | — | 2.4% | Apr 26, 2018 | An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by... |
| CVE-2018-10431 | — | — | 2.7% | Apr 26, 2018 | D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Tra... |
| CVE-2018-10430 | — | — | 0.7% | Apr 26, 2018 | An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0. There is a Stored XSS Vulnerability in the fourth textbox of... |
| CVE-2018-10429 | — | — | 1.8% | Apr 26, 2018 | Cosmo 1.0.0Beta6 allows attackers to execute arbitrary PHP code via the Database Prefix field on the Database Info scree... |
| CVE-2018-8072 | — | — | 2.8% | Apr 26, 2018 | An issue was discovered on EDIMAX IC-3140W through 3.06, IC-5150W through 3.09, and IC-6220DC through 3.06 devices. The ... |
| CVE-2018-6518 | — | — | 0.8% | Apr 26, 2018 | Composr CMS 10.0.13 has XSS via the site_name parameter in a page=admin-setupwizard&type=step3 request to /adminzone/ind... |
| CVE-2018-1418 | — | — | 53.4% | Apr 26, 2018 | IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM... |
| CVE-2018-10425 | — | — | 0.4% | Apr 26, 2018 | An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe, 2345SafeTray.exe, and 2345Speedup.exe al... |
| CVE-2018-9113 | — | — | 4.1% | Apr 26, 2018 | Centers for Disease Control and Prevention MicrobeTRACE 0.1.12 allows remote attackers to execute arbitrary code, relate... |
| CVE-2018-8974 | — | — | 4.1% | Apr 26, 2018 | Centers for Disease Control and Prevention MicrobeTRACE 0.1.11 allows remote attackers to execute arbitrary code, relate... |
| CVE-2018-10424 | — | — | 1.0% | Apr 26, 2018 | mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field. |
| CVE-2018-10423 | — | — | 1.3% | Apr 26, 2018 | mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of th... |
| CVE-2018-10422 | — | — | 0.5% | Apr 26, 2018 | An issue was discovered in HongCMS 3.0.0. The post news feature has Stored XSS via the content field. |
| CVE-2018-10391 | — | — | 0.7% | Apr 26, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register UR... |
| CVE-2018-10381 | — | — | 3.7% | Apr 26, 2018 | TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenan... |
| CVE-2018-8837 | — | — | 2.1% | Apr 25, 2018 | Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to w... |
| CVE-2018-8835 | — | — | 2.1% | Apr 25, 2018 | Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafte... |
| CVE-2018-5486 | — | — | 0.4% | Apr 25, 2018 | NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled... |
| CVE-2018-5226 | — | — | 1.5% | Apr 25, 2018 | There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going ... |
| CVE-2018-1339 | — | — | 2.6% | Apr 25, 2018 | A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika ... |
| CVE-2018-1338 | — | — | 2.0% | Apr 25, 2018 | A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika ... |
| CVE-2018-1335 | — | — | 94.1% | Apr 25, 2018 | From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to... |
| CVE-2018-9104 | — | — | 1.1% | Apr 25, 2018 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earli... |
| CVE-2018-9103 | — | — | 1.1% | Apr 25, 2018 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earli... |
| CVE-2018-9102 | — | — | 1.1% | Apr 25, 2018 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earli... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now