2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0569 | — | — | 1.5% | Jun 26, 2018 | baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attac... |
| CVE-2018-0567 | — | — | 0.8% | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass access restriction to access and write non-publi... |
| CVE-2018-0566 | — | — | 0.9% | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass authentication to obtain the schedules without a... |
| CVE-2018-0565 | — | — | 0.8% | Jun 26, 2018 | Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.0 allows remote attackers to inject arbitrary web scr... |
| CVE-2018-0563 | — | — | 1.1% | Jun 26, 2018 | Untrusted search path vulnerability in the installer of FLET'S VIRUS CLEAR Easy Setup & Application Tool ver.13.0 and ea... |
| CVE-2018-0559 | — | — | 0.8% | Jun 26, 2018 | Cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web scr... |
| CVE-2018-0558 | — | — | 0.8% | Jun 26, 2018 | Reflected cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitra... |
| CVE-2018-0557 | — | — | 0.8% | Jun 26, 2018 | Stored cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary ... |
| CVE-2018-0529 | — | — | 1.1% | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors. |
| CVE-2018-0528 | — | — | 0.9% | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are no... |
| CVE-2018-0527 | — | — | 0.8% | Jun 26, 2018 | Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to inject arbitrary web scr... |
| CVE-2018-0526 | — | — | 1.0% | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.7.0 allow remote attackers to display an image located in an external server via unspecified ... |
| CVE-2018-12889 | — | — | 1.7% | Jun 26, 2018 | An issue was discovered in CCN-lite 2.0.1. There is a heap-based buffer overflow in mkAddToRelayCacheRequest and in ccnl... |
| CVE-2018-12884 | — | — | 0.8% | Jun 26, 2018 | In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create ... |
| CVE-2018-12882 | — | — | 6.6% | Jun 26, 2018 | exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_... |
| CVE-2018-12603 | — | — | 3.6% | Jun 25, 2018 | Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authen... |
| CVE-2018-11589 | — | — | 2.1% | Jun 25, 2018 | Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU par... |
| CVE-2018-11588 | — | — | 1.1% | Jun 25, 2018 | Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the usernam... |
| CVE-2018-11587 | — | — | 4.2% | Jun 25, 2018 | There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric f... |
| CVE-2018-12735 | — | — | 1.4% | Jun 25, 2018 | SAJ Solar Inverter allows remote attackers to obtain potentially sensitive information via a direct request for the inve... |
| CVE-2018-8755 | — | — | 1.1% | Jun 25, 2018 | NuCom WR644GACV devices before STA006 allow an attacker to download the configuration file without credentials. By downl... |
| CVE-2018-12602 | — | — | 3.0% | Jun 25, 2018 | A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily. |
| CVE-2018-11046 | — | — | 0.9% | Jun 25, 2018 | Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks securit... |
| CVE-2018-11041 | — | — | 0.9% | Jun 25, 2018 | Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later ... |
| CVE-2018-11040 | HIGH | 7.5 | 3.2% | Jun 25, 2018 | Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web app... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now