2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6220 | — | — | 10.4% | Mar 15, 2018 | An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbi... |
| CVE-2018-6219 | — | — | 4.1% | Mar 15, 2018 | An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdr... |
| CVE-2018-8729 | — | — | 5.6% | Mar 15, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a... |
| CVE-2018-8728 | — | — | 1.1% | Mar 15, 2018 | server/app/views/static/code.html in Kontena before 1.5.0 allows XSS in "kontena master login --remote" code display, as... |
| CVE-2018-8720 | — | — | 0.7% | Mar 15, 2018 | ServiceNow ITSM 2016-06-02 has XSS via the First Name or Last Name field of My Profile (aka navpage.do), or the Search b... |
| CVE-2018-8722 | — | — | 1.6% | Mar 15, 2018 | Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026. |
| CVE-2018-8721 | — | — | 2.0% | Mar 15, 2018 | Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&t... |
| CVE-2018-8076 | — | — | 1.1% | Mar 15, 2018 | ZenMate 1.5.4 for macOS suffers from a type confusion vulnerability within the com.zenmate.chron-xpc LaunchDaemon compon... |
| CVE-2018-7886 | — | — | 2.1% | Mar 15, 2018 | An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" clie... |
| CVE-2018-8717 | — | — | 0.7% | Mar 15, 2018 | joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&... |
| CVE-2018-8715 | — | — | 19.9% | Mar 15, 2018 | The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in... |
| CVE-2018-8045 | — | — | 29.2% | Mar 15, 2018 | In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulne... |
| CVE-2018-7756 | — | — | 62.5% | Mar 15, 2018 | RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP... |
| CVE-2018-7707 | — | — | 2.7% | Mar 15, 2018 | Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitr... |
| CVE-2018-7706 | — | — | 7.1% | Mar 15, 2018 | Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbit... |
| CVE-2018-7705 | — | — | 6.3% | Mar 15, 2018 | Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mai... |
| CVE-2018-7704 | — | — | 4.9% | Mar 15, 2018 | SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1 ... |
| CVE-2018-7703 | — | — | 4.2% | Mar 15, 2018 | Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitr... |
| CVE-2018-7702 | — | — | 14.7% | Mar 15, 2018 | SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e... |
| CVE-2018-7701 | — | — | 3.1% | Mar 15, 2018 | Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers... |
| CVE-2018-8712 | — | — | 1.8% | Mar 14, 2018 | An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is e... |
| CVE-2018-8711 | — | — | 2.0% | Mar 14, 2018 | A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPr... |
| CVE-2018-8710 | — | — | 4.3% | Mar 14, 2018 | A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordP... |
| CVE-2018-6329 | — | — | 62.5% | Mar 14, 2018 | It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i... |
| CVE-2018-6328 | — | — | 65.5% | Mar 14, 2018 | It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, w... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now