2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7301 | — | — | 1.5% | Feb 22, 2018 | eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sendin... |
| CVE-2018-7299 | — | — | 1.2% | Feb 22, 2018 | Remote Code Execution in the addon installation process in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows authenticate... |
| CVE-2018-7298 | — | — | 0.8% | Feb 22, 2018 | In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are do... |
| CVE-2018-7297 | — | — | 65.3% | Feb 22, 2018 | Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers... |
| CVE-2018-7296 | — | — | 1.9% | Feb 22, 2018 | Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows... |
| CVE-2018-6890 | — | — | 0.7% | Feb 22, 2018 | Cross-site scripting (XSS) vulnerability in Wolf CMS 0.8.3.1 via the page editing feature, as demonstrated by /?/admin/p... |
| CVE-2018-1415 | — | — | 0.8% | Feb 22, 2018 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2018-1414 | — | — | 1.6% | Feb 22, 2018 | IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted S... |
| CVE-2018-1392 | — | — | 0.6% | Feb 22, 2018 | IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user ... |
| CVE-2018-1391 | — | — | 1.5% | Feb 22, 2018 | IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user ... |
| CVE-2018-7409 | — | — | 2.7% | Feb 22, 2018 | In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c. |
| CVE-2018-7408 | — | — | 0.3% | Feb 22, 2018 | An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically inst... |
| CVE-2018-7313 | — | — | 20.2% | Feb 22, 2018 | SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter. |
| CVE-2018-7287 | — | — | 11.9% | Feb 22, 2018 | An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default ... |
| CVE-2018-7286 | — | — | 39.5% | Feb 22, 2018 | An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asteris... |
| CVE-2018-7285 | — | — | 5.2% | Feb 22, 2018 | A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Asterisk maintains its ow... |
| CVE-2018-7284 | — | — | 58.9% | Feb 22, 2018 | A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Ce... |
| CVE-2018-0206 | — | — | 1.3% | Feb 22, 2018 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthentic... |
| CVE-2018-0205 | — | — | 1.3% | Feb 22, 2018 | A vulnerability in the User Provisioning tab in the Cisco Prime Collaboration Provisioning Tool could allow an unauthent... |
| CVE-2018-0204 | — | — | 2.5% | Feb 22, 2018 | A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, rem... |
| CVE-2018-0203 | — | — | 1.7% | Feb 22, 2018 | A vulnerability in the SMTP relay of Cisco Unity Connection could allow an unauthenticated, remote attacker to send unso... |
| CVE-2018-0201 | — | — | 0.9% | Feb 22, 2018 | A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-... |
| CVE-2018-0200 | — | — | 1.3% | Feb 22, 2018 | A vulnerability in the web-based interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacke... |
| CVE-2018-0199 | — | — | 2.1% | Feb 22, 2018 | A vulnerability in Cisco Jabber Client Framework (JCF) could allow an unauthenticated, remote attacker to conduct a cros... |
| CVE-2018-0148 | — | — | 0.9% | Feb 22, 2018 | A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Con... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now