2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-0146A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker...
CVE-2018-0145A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could all...
CVE-2018-0130A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Softw...
CVE-2018-0124A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass...
CVE-2018-0121A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller...
CVE-2018-7281CactusVPN 5.3.6 for macOS contains a root privilege escalation vulnerability through a setuid root binary called runme. ...
CVE-2018-6936Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.
CVE-2018-7308A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users...
CVE-2018-7305MyBB 1.8.14 is not checking for a valid CSRF token, leading to arbitrary deletion of user accounts.
CVE-2018-7304Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE o...
CVE-2018-7303The Calendar component in Tiki 17.1 allows HTML injection.
CVE-2018-7302Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
CVE-2018-7289An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames cont...
CVE-2018-7280The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
CVE-2018-7261There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Usern...
CVE-2018-7260Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticate...
CVE-2018-1168This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with ...
CVE-2018-1166This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-2...
CVE-2018-1164This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P...
CVE-2018-7278An issue was discovered on RLE Protocol Converter FDS-PC / FDS-PC-DP 2.1 devices. Persistent XSS exists in the web serve...
CVE-2018-7277An issue was discovered on RLE Wi-MGR/FDS-Wi 6.2 devices. Persistent XSS exists in the web server. Remote attackers can ...
CVE-2018-7276An issue was discovered on Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) devices. Remote attackers can obtain...
CVE-2018-7273In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi...
CVE-2018-7272The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sen...
CVE-2018-7271An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php c...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now