2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0137 | — | — | 1.6% | Feb 8, 2018 | A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to ... |
| CVE-2018-0135 | — | — | 1.3% | Feb 8, 2018 | A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitiv... |
| CVE-2018-0132 | — | — | 2.3% | Feb 8, 2018 | A vulnerability in the forwarding information base (FIB) code of Cisco IOS XR Software could allow an unauthenticated, r... |
| CVE-2018-0129 | — | — | 0.9% | Feb 8, 2018 | A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenti... |
| CVE-2018-0128 | — | — | 0.9% | Feb 8, 2018 | A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenti... |
| CVE-2018-0123 | — | — | 0.4% | Feb 8, 2018 | A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow an authenticated, l... |
| CVE-2018-0120 | — | — | 1.4% | Feb 8, 2018 | A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attack... |
| CVE-2018-0119 | — | — | 1.0% | Feb 8, 2018 | A vulnerability in certain authentication controls in the account services of Cisco Spark could allow an authenticated, ... |
| CVE-2018-0117 | — | — | 1.8% | Feb 8, 2018 | A vulnerability in the ingress packet processing functionality of the Cisco Virtualized Packet Core-Distributed Instance... |
| CVE-2018-0116 | — | — | 1.1% | Feb 8, 2018 | A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacke... |
| CVE-2018-0113 | — | — | 2.3% | Feb 8, 2018 | A vulnerability in an operations script of Cisco UCS Central could allow an authenticated, remote attacker to execute ar... |
| CVE-2018-6829 | — | — | 1.8% | Feb 7, 2018 | cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, whic... |
| CVE-2018-6796 | — | — | 0.6% | Feb 7, 2018 | PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field. |
| CVE-2018-6795 | — | — | 0.6% | Feb 7, 2018 | PHP Scripts Mall Naukri Clone Script 3.0.3 has Stored XSS via every profile input field. |
| CVE-2018-6655 | — | — | 0.6% | Feb 7, 2018 | PHP Scripts Mall Doctor Search Script 1.0.2 has Stored XSS via an arbitrary profile field. |
| CVE-2018-6574 | — | — | 7.7% | Feb 7, 2018 | Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command executi... |
| CVE-2018-6824 | — | — | 0.8% | Feb 7, 2018 | Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url paramete... |
| CVE-2018-1388 | — | — | 2.2% | Feb 7, 2018 | GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force I... |
| CVE-2018-1382 | — | — | 0.6% | Feb 7, 2018 | IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc... |
| CVE-2018-1366 | — | — | 0.9% | Feb 7, 2018 | IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this... |
| CVE-2018-6823 | — | — | 1.5% | Feb 7, 2018 | In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implemen... |
| CVE-2018-6822 | — | — | 1.5% | Feb 7, 2018 | In PureVPN 6.0.1 on macOS, HelperTool LaunchDaemon implements an unprotected XPC service that can be abused to execute s... |
| CVE-2018-6799 | — | — | 2.6% | Feb 7, 2018 | The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause ... |
| CVE-2018-6794 | — | — | 29.5% | Feb 7, 2018 | Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious se... |
| CVE-2018-6603 | — | — | 0.8% | Feb 7, 2018 | Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injecti... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now