2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7244 | — | — | 1.1% | Apr 18, 2018 | An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse inst... |
| CVE-2018-7243 | — | — | 2.8% | Apr 18, 2018 | An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse instal... |
| CVE-2018-7242 | — | — | 1.4% | Apr 18, 2018 | Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200... |
| CVE-2018-7241 | — | — | 2.9% | Apr 18, 2018 | Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 control... |
| CVE-2018-7240 | — | — | 2.7% | Apr 18, 2018 | A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could ... |
| CVE-2018-1325 | — | — | 0.8% | Apr 18, 2018 | In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on di... |
| CVE-2018-1000167 | — | — | 4.2% | Apr 18, 2018 | OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Functi... |
| CVE-2018-1000165 | — | — | 1.3% | Apr 18, 2018 | LightSAML version prior to 1.3.5 contains a Incorrect Access Control vulnerability in signature validation in readers in... |
| CVE-2018-1000164 | — | — | 2.4% | Apr 18, 2018 | gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "... |
| CVE-2018-1000163 | — | — | 0.7% | Apr 18, 2018 | Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can resul... |
| CVE-2018-1000162 | — | — | 1.2% | Apr 18, 2018 | Parsedown version prior to 1.7.0 contains a Cross Site Scripting (XSS) vulnerability in `setMarkupEscaped` for escaping ... |
| CVE-2018-1000161 | — | — | 1.0% | Apr 18, 2018 | nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability... |
| CVE-2018-1000160 | — | — | 1.3% | Apr 18, 2018 | RisingStack protect version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in isXss() function in... |
| CVE-2018-1000159 | — | — | 0.8% | Apr 18, 2018 | tlslite-ng version 0.7.3 and earlier, since commit d7b288316bca7bcdd082e6ccff5491e241305233 contains a CWE-354: Improper... |
| CVE-2018-1000158 | — | — | 1.1% | Apr 18, 2018 | cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in ... |
| CVE-2018-8831 | — | — | 53.9% | Apr 18, 2018 | A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/s... |
| CVE-2018-1240 | — | — | 0.5% | Apr 18, 2018 | Dell EMC ViPR Controller, versions after 3.0.0.38, contain an information exposure vulnerability in the VRRP. VRRP defau... |
| CVE-2018-6413 | — | — | 1.7% | Apr 18, 2018 | There is a buffer overflow in the Hikvision Camera DS-2CD9111-S of V4.1.2 build 160203 and before, and this vulnerabilit... |
| CVE-2018-10199 | — | — | 2.3% | Apr 18, 2018 | In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_cop... |
| CVE-2018-9999 | — | — | 0.7% | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR stor... |
| CVE-2018-9990 | — | — | 0.8% | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead. |
| CVE-2018-9987 | — | — | 0.8% | Apr 18, 2018 | In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications. |
| CVE-2018-9986 | — | — | 0.8% | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor. |
| CVE-2018-8092 | — | — | 1.7% | Apr 18, 2018 | Mautic before 2.13.0 allows CSV injection. |
| CVE-2018-8071 | — | — | 0.8% | Apr 18, 2018 | Mautic before v2.13.0 has stored XSS via a theme config file. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now