2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7538 | — | — | 4.5% | Mar 12, 2018 | A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 a... |
| CVE-2018-6623 | — | — | 0.9% | Mar 12, 2018 | An issue was discovered in Hola 1.79.859. An unprivileged user could modify or overwrite the executable with arbitrary c... |
| CVE-2018-6400 | — | — | 0.3% | Mar 12, 2018 | Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating... |
| CVE-2018-6322 | — | — | 0.3% | Mar 12, 2018 | Panda Global Protection 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all t... |
| CVE-2018-6321 | — | — | 0.3% | Mar 12, 2018 | Unquoted Windows search path vulnerability in the panda_url_filtering service in Panda Global Protection 17.0.1 allows l... |
| CVE-2018-6183 | — | — | 0.3% | Mar 12, 2018 | BitDefender Total Security 2018 allows local users to gain privileges or cause a denial of service by impersonating all ... |
| CVE-2018-6016 | — | — | 0.3% | Mar 12, 2018 | Unquoted Windows search path vulnerability in the srvInventoryWebServer service in 10-Strike Network Monitor 5.4 allows ... |
| CVE-2018-5758 | — | — | 3.1% | Mar 12, 2018 | The Upload File functionality in upload.jspa in Aurea Jive Jive-n 9.0.2.1 On-Premises allows for an XML External Entity ... |
| CVE-2018-7749 | — | — | 1.8% | Mar 12, 2018 | The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed befo... |
| CVE-2018-1206 | — | — | 0.4% | Mar 12, 2018 | Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to ... |
| CVE-2018-1323 | — | — | 44.2% | Mar 12, 2018 | The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path b... |
| CVE-2018-8070 | — | — | 0.5% | Mar 12, 2018 | QCMS version 3.0 has XSS via the title parameter to the /guest/index.html URI. |
| CVE-2018-8069 | — | — | 0.5% | Mar 12, 2018 | QCMS version 3.0 has XSS via the webname parameter to the /backend/system.html URI. |
| CVE-2018-8065 | — | — | 76.5% | Mar 12, 2018 | An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v... |
| CVE-2018-8058 | — | — | 0.6% | Mar 12, 2018 | CMS Made Simple (CMSMS) 2.2.6 has XSS in admin/moduleinterface.php via the pagedata parameter. |
| CVE-2018-7893 | — | — | 0.6% | Mar 12, 2018 | CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter. |
| CVE-2018-8059 | — | — | 0.5% | Mar 11, 2018 | The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involv... |
| CVE-2018-8057 | — | — | 23.0% | Mar 11, 2018 | A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a... |
| CVE-2018-8056 | — | — | 13.4% | Mar 11, 2018 | Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/ma... |
| CVE-2018-8050 | — | — | 1.6% | Mar 11, 2018 | The af_get_page() function in lib/afflib_pages.cpp in AFFLIB (aka AFFLIBv3) through 3.7.16 allows remote attackers to ca... |
| CVE-2018-7213 | — | — | 1.7% | Mar 11, 2018 | The Password Manager Extension in Abine Blur 7.8.242* before 7.8.2428 allows attackers to bypass the Multi-Factor Authen... |
| CVE-2018-8043 | — | — | 0.4% | Mar 10, 2018 | The unimac_mdio_probe function in drivers/net/phy/mdio-bcm-unimac.c in the Linux kernel through 4.15.8 does not validate... |
| CVE-2018-7239 | — | — | 2.9% | Mar 9, 2018 | A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in a... |
| CVE-2018-7582 | — | — | 37.6% | Mar 9, 2018 | WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to ... |
| CVE-2018-7581 | — | — | 1.1% | Mar 9, 2018 | \ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUIL... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now