2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10173 | — | — | 5.4% | Apr 20, 2018 | Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Uplo... |
| CVE-2018-8826 | — | — | 4.3% | Apr 20, 2018 | ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT... |
| CVE-2018-10249 | — | — | 0.5% | Apr 20, 2018 | baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account. |
| CVE-2018-1292 | — | — | 2.2% | Apr 20, 2018 | Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hack... |
| CVE-2018-1291 | — | — | 2.1% | Apr 20, 2018 | Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query d... |
| CVE-2018-1290 | — | — | 3.4% | Apr 20, 2018 | In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape... |
| CVE-2018-1289 | — | — | 2.7% | Apr 20, 2018 | In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different RE... |
| CVE-2018-10250 | — | — | 0.6% | Apr 20, 2018 | iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Manageme... |
| CVE-2018-10248 | — | — | 0.6% | Apr 20, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=co... |
| CVE-2018-10245 | — | — | 1.9% | Apr 20, 2018 | A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is all... |
| CVE-2018-6960 | — | — | 2.6% | Apr 20, 2018 | VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypa... |
| CVE-2018-0564 | — | — | 1.5% | Apr 20, 2018 | Session fixation vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3..4, EC-... |
| CVE-2018-10201 | — | — | 45.6% | Apr 20, 2018 | An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible t... |
| CVE-2018-10238 | — | — | 1.7% | Apr 20, 2018 | bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of pack... |
| CVE-2018-0276 | — | — | 0.9% | Apr 19, 2018 | A vulnerability in Cisco WebEx Connect IM could allow an unauthenticated, remote attacker to conduct a cross-site script... |
| CVE-2018-0275 | — | — | 0.3% | Apr 19, 2018 | A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, loca... |
| CVE-2018-0273 | — | — | 3.3% | Apr 19, 2018 | A vulnerability in the IPsec Manager of Cisco StarOS for Cisco Aggregation Services Router (ASR) 5000 Series Routers and... |
| CVE-2018-0272 | — | — | 1.3% | Apr 19, 2018 | A vulnerability in the Secure Sockets Layer (SSL) Engine of Cisco Firepower System Software could allow an unauthenticat... |
| CVE-2018-0260 | — | — | 2.4% | Apr 19, 2018 | A vulnerability in the web interface of Cisco MATE Live could allow an unauthenticated, remote attacker to view and down... |
| CVE-2018-0259 | — | — | 0.7% | Apr 19, 2018 | A vulnerability in the web-based management interface of Cisco MATE Collector could allow an unauthenticated, remote att... |
| CVE-2018-0257 | — | — | 0.8% | Apr 19, 2018 | A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthen... |
| CVE-2018-0256 | — | — | 1.6% | Apr 19, 2018 | A vulnerability in the peer-to-peer message processing functionality of Cisco Packet Data Network Gateway could allow an... |
| CVE-2018-0255 | — | — | 0.9% | Apr 19, 2018 | A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated... |
| CVE-2018-0251 | — | — | 1.9% | Apr 19, 2018 | A vulnerability in the Web Server Authentication Required screen of the Clientless Secure Sockets Layer (SSL) VPN portal... |
| CVE-2018-0242 | — | — | 1.8% | Apr 19, 2018 | A vulnerability in the WebVPN web-based management interface of Cisco Adaptive Security Appliance could allow an unauthe... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now