2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0920 | — | — | 21.2% | Apr 12, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2018-0892 | — | — | 5.4% | Apr 12, 2018 | An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft ... |
| CVE-2018-0890 | — | — | 4.3% | Apr 12, 2018 | A security feature bypass vulnerability exists when Active Directory incorrectly applies Network Isolation settings, aka... |
| CVE-2018-0887 | — | — | 1.9% | Apr 12, 2018 | An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, ak... |
| CVE-2018-0870 | — | — | 15.1% | Apr 12, 2018 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet... |
| CVE-2018-10052 | — | — | 0.6% | Apr 11, 2018 | iScripts SupportDesk v4.3 has XSS via the admin/inteligentsearchresult.php txtinteligentsearch parameter. |
| CVE-2018-10051 | — | — | 0.6% | Apr 11, 2018 | iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter. |
| CVE-2018-10050 | — | — | 1.0% | Apr 11, 2018 | iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel. |
| CVE-2018-10049 | — | — | 0.5% | Apr 11, 2018 | iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel. |
| CVE-2018-10048 | — | — | 0.5% | Apr 11, 2018 | iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel. |
| CVE-2018-10033 | — | — | 0.6% | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter. |
| CVE-2018-10032 | — | — | 0.5% | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter. |
| CVE-2018-10031 | — | — | 0.5% | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php. |
| CVE-2018-10030 | — | — | 0.5% | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php. |
| CVE-2018-10029 | — | — | 0.5% | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to m... |
| CVE-2018-10028 | — | — | 1.5% | Apr 11, 2018 | joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ U... |
| CVE-2018-10026 | — | — | 0.5% | Apr 11, 2018 | The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the val... |
| CVE-2018-8954 | — | — | 7.3% | Apr 11, 2018 | CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request... |
| CVE-2018-8953 | — | — | 2.8% | Apr 11, 2018 | CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP reque... |
| CVE-2018-7930 | — | — | 0.4% | Apr 11, 2018 | The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C56... |
| CVE-2018-10024 | — | — | 1.4% | Apr 11, 2018 | ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed lo... |
| CVE-2018-10023 | — | — | 0.7% | Apr 11, 2018 | Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment). |
| CVE-2018-10021 | — | — | 0.5% | Apr 11, 2018 | drivers/scsi/libsas/sas_scsi_host.c in the Linux kernel before 4.16 allows local users to cause a denial of service (ata... |
| CVE-2018-3594 | — | — | 1.3% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon W... |
| CVE-2018-3593 | — | — | 1.3% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon W... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now