2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-0241A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjace...
CVE-2018-0238A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director c...
CVE-2018-0233A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firep...
CVE-2018-0229A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication f...
CVE-2018-0112A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server could allow...
CVE-2018-10236POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.p...
CVE-2018-10235POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting....
CVE-2018-9861Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 thro...
CVE-2018-8118A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet...
CVE-2018-10230Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.
CVE-2018-7920Huawei AR1200 V200R006C10SPC300, AR160 V200R006C10SPC300, AR200 V200R006C10SPC300, AR2200 V200R006C10SPC300, AR3200 V200...
CVE-2018-7899The Mali Driver of Huawei Berkeley-AL20 and Berkeley-BD smart phones with software Berkeley-AL20 8.0.0.105(C00), 8.0.0.1...
CVE-2018-10188phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_ope...
CVE-2018-6306Unauthorized code execution from specific DLL and is known as DLL Hijacking attack in Kaspersky Password Manager version...
CVE-2018-1146A remote unauthenticated user can enable telnet on the Belkin N750 using firmware version 1.10.22 by sending a crafted H...
CVE-2018-1145A remote unauthenticated user can overflow a stack buffer in the Belkin N750 using firmware version 1.10.22 by sending a...
CVE-2018-1144A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending ...
CVE-2018-1143A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending ...
CVE-2018-9137Open-AudIT before 2.2 has CSV Injection.
CVE-2018-10227MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter.
CVE-2018-10225thinkphp 3.1.3 has SQL Injection via the index.php s parameter.
CVE-2018-10224An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.htm...
CVE-2018-10223An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/...
CVE-2018-10222An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?ap...
CVE-2018-10221An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator co...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now