2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5342 | — | — | 3.8% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central an... |
| CVE-2018-5341 | — | — | 8.2% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the f... |
| CVE-2018-5340 | — | — | 5.2% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser ac... |
| CVE-2018-5339 | — | — | 7.6% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database... |
| CVE-2018-5338 | — | — | 9.0% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization... |
| CVE-2018-5337 | — | — | 9.5% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NA... |
| CVE-2018-8736 | — | — | 46.9% | Apr 18, 2018 | A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC... |
| CVE-2018-8735 | — | — | 64.2% | Apr 18, 2018 | Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut... |
| CVE-2018-8734 | — | — | 53.2% | Apr 18, 2018 | SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker... |
| CVE-2018-8733 | — | — | 27.5% | Apr 18, 2018 | Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an ... |
| CVE-2018-10193 | — | — | 4.8% | Apr 18, 2018 | LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document... |
| CVE-2018-8838 | — | — | 0.3% | Apr 17, 2018 | A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 30... |
| CVE-2018-10192 | — | — | 2.4% | Apr 17, 2018 | IPVanish 3.0.11 for macOS suffers from a root privilege escalation vulnerability. The `com.ipvanish.osx.vpnhelper` Launc... |
| CVE-2018-7539 | — | — | 4.3% | Apr 17, 2018 | On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a specially crafted ... |
| CVE-2018-6913 | — | — | 10.9% | Apr 17, 2018 | Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbi... |
| CVE-2018-6798 | — | — | 4.0% | Apr 17, 2018 | An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a he... |
| CVE-2018-6797 | — | — | 7.4% | Apr 17, 2018 | An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, ... |
| CVE-2018-10190 | — | — | 0.3% | Apr 17, 2018 | A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenti... |
| CVE-2018-10189 | — | — | 1.2% | Apr 17, 2018 | An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies p... |
| CVE-2018-10187 | — | — | 0.9% | Apr 17, 2018 | In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote a... |
| CVE-2018-10186 | — | — | 0.9% | Apr 17, 2018 | In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attacke... |
| CVE-2018-7530 | — | — | 0.3% | Apr 17, 2018 | Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet ... |
| CVE-2018-10185 | — | — | 0.5% | Apr 17, 2018 | An issue was discovered in TuziCMS v2.0.6. There is a CSRF vulnerability that can add an admin account, as demonstrated ... |
| CVE-2018-1445 | — | — | 0.8% | Apr 17, 2018 | IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allow... |
| CVE-2018-1371 | — | — | 1.2% | Apr 17, 2018 | An IBM WebSphere MQ 8.0.0.8, 9.0.0.2, and 9.0.4 Client connecting to a MQ Queue Manager can cause a SIGSEGV in the AMQRM... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now