2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0241 | — | — | 0.9% | Apr 19, 2018 | A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjace... |
| CVE-2018-0238 | — | — | 5.2% | Apr 19, 2018 | A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director c... |
| CVE-2018-0233 | — | — | 2.5% | Apr 19, 2018 | A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firep... |
| CVE-2018-0229 | — | — | 3.6% | Apr 19, 2018 | A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication f... |
| CVE-2018-0112 | — | — | 2.7% | Apr 19, 2018 | A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server could allow... |
| CVE-2018-10236 | — | — | 1.5% | Apr 19, 2018 | POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.p... |
| CVE-2018-10235 | — | — | 1.5% | Apr 19, 2018 | POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.... |
| CVE-2018-9861 | — | — | 1.8% | Apr 19, 2018 | Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 thro... |
| CVE-2018-8118 | — | — | 9.4% | Apr 19, 2018 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet... |
| CVE-2018-10230 | — | — | 2.7% | Apr 19, 2018 | Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455. |
| CVE-2018-7920 | — | — | 0.9% | Apr 19, 2018 | Huawei AR1200 V200R006C10SPC300, AR160 V200R006C10SPC300, AR200 V200R006C10SPC300, AR2200 V200R006C10SPC300, AR3200 V200... |
| CVE-2018-7899 | — | — | 0.6% | Apr 19, 2018 | The Mali Driver of Huawei Berkeley-AL20 and Berkeley-BD smart phones with software Berkeley-AL20 8.0.0.105(C00), 8.0.0.1... |
| CVE-2018-10188 | — | — | 4.9% | Apr 19, 2018 | phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_ope... |
| CVE-2018-6306 | — | — | 2.6% | Apr 19, 2018 | Unauthorized code execution from specific DLL and is known as DLL Hijacking attack in Kaspersky Password Manager version... |
| CVE-2018-1146 | — | — | 29.1% | Apr 19, 2018 | A remote unauthenticated user can enable telnet on the Belkin N750 using firmware version 1.10.22 by sending a crafted H... |
| CVE-2018-1145 | — | — | 24.9% | Apr 19, 2018 | A remote unauthenticated user can overflow a stack buffer in the Belkin N750 using firmware version 1.10.22 by sending a... |
| CVE-2018-1144 | — | — | 7.0% | Apr 19, 2018 | A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending ... |
| CVE-2018-1143 | — | — | 55.2% | Apr 19, 2018 | A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending ... |
| CVE-2018-9137 | — | — | 2.8% | Apr 19, 2018 | Open-AudIT before 2.2 has CSV Injection. |
| CVE-2018-10227 | — | — | 0.7% | Apr 19, 2018 | MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter. |
| CVE-2018-10225 | — | — | 1.1% | Apr 19, 2018 | thinkphp 3.1.3 has SQL Injection via the index.php s parameter. |
| CVE-2018-10224 | — | — | 0.5% | Apr 19, 2018 | An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.htm... |
| CVE-2018-10223 | — | — | 0.5% | Apr 19, 2018 | An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/... |
| CVE-2018-10222 | — | — | 0.6% | Apr 19, 2018 | An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?ap... |
| CVE-2018-10221 | — | — | 0.7% | Apr 19, 2018 | An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator co... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now