2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000171 | — | — | — | Apr 13, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9092. Reason: This candidate is a reservation ... |
| CVE-2018-4173 | — | — | 0.7% | Apr 13, 2018 | An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The is... |
| CVE-2018-6547 | — | — | 1.1% | Apr 13, 2018 | plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming... |
| CVE-2018-6546 | — | — | 18.1% | Apr 13, 2018 | plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming... |
| CVE-2018-10096 | — | — | 0.6% | Apr 13, 2018 | joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request. |
| CVE-2018-6959 | — | — | 2.1% | Apr 13, 2018 | VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of... |
| CVE-2018-6958 | — | — | 1.1% | Apr 13, 2018 | VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scrip... |
| CVE-2018-5511 | — | — | 14.8% | Apr 13, 2018 | On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Manageme... |
| CVE-2018-5510 | — | — | 1.1% | Apr 13, 2018 | On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence... |
| CVE-2018-5508 | — | — | 0.9% | Apr 13, 2018 | On F5 BIG-IP PEM versions 13.0.0, 12.0.0-12.1.3.1, 11.6.0-11.6.2, 11.5.1-11.5.5, or 11.2.1, under certain conditions, TM... |
| CVE-2018-5507 | — | — | 1.1% | Apr 13, 2018 | On F5 BIG-IP versions 13.0.0, 12.1.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5, vCMP guests running on VIPRION 2100, 420... |
| CVE-2018-5506 | — | — | 0.7% | Apr 13, 2018 | In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_mod and mod_au... |
| CVE-2018-10087 | — | — | 0.5% | Apr 13, 2018 | The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compile... |
| CVE-2018-10066 | — | — | 1.0% | Apr 13, 2018 | An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server certificate verification allows a remote una... |
| CVE-2018-10086 | — | — | 2.0% | Apr 13, 2018 | CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because ... |
| CVE-2018-10085 | — | — | 3.9% | Apr 13, 2018 | CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data functi... |
| CVE-2018-10084 | — | — | 0.8% | Apr 13, 2018 | CMS Made Simple (CMSMS) through 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by ... |
| CVE-2018-10083 | — | — | 1.5% | Apr 13, 2018 | CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via direc... |
| CVE-2018-10082 | — | — | 1.2% | Apr 13, 2018 | CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI ... |
| CVE-2018-10081 | — | — | 1.6% | Apr 13, 2018 | CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly ... |
| CVE-2018-10080 | — | — | 0.6% | Apr 13, 2018 | Secutech RiS-11, RiS-22, and RiS-33 devices with firmware V5.07.52_es_FRI01 allow DNS settings changes via a goform/AdvS... |
| CVE-2018-6935 | — | — | 0.5% | Apr 12, 2018 | PHP Scripts Mall Student Profile Management System Script v2.0.6 has XSS via the Name field to list_student.php. |
| CVE-2018-6934 | — | — | 0.5% | Apr 12, 2018 | CSRF exists in student/personal-info in PHP Scripts Mall Online Tutoring Script 2.0.3. |
| CVE-2018-6904 | — | — | 0.5% | Apr 12, 2018 | PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the User Name field in an Edit Profile action. |
| CVE-2018-6903 | — | — | 1.1% | Apr 12, 2018 | PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail addres... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now