2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-0137A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to ...
CVE-2018-0135A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitiv...
CVE-2018-0132A vulnerability in the forwarding information base (FIB) code of Cisco IOS XR Software could allow an unauthenticated, r...
CVE-2018-0129A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenti...
CVE-2018-0128A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenti...
CVE-2018-0123A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow an authenticated, l...
CVE-2018-0120A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attack...
CVE-2018-0119A vulnerability in certain authentication controls in the account services of Cisco Spark could allow an authenticated, ...
CVE-2018-0117A vulnerability in the ingress packet processing functionality of the Cisco Virtualized Packet Core-Distributed Instance...
CVE-2018-0116A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacke...
CVE-2018-0113A vulnerability in an operations script of Cisco UCS Central could allow an authenticated, remote attacker to execute ar...
CVE-2018-6829cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, whic...
CVE-2018-6796PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field.
CVE-2018-6795PHP Scripts Mall Naukri Clone Script 3.0.3 has Stored XSS via every profile input field.
CVE-2018-6655PHP Scripts Mall Doctor Search Script 1.0.2 has Stored XSS via an arbitrary profile field.
CVE-2018-6574Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command executi...
CVE-2018-6824Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url paramete...
CVE-2018-1388GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force I...
CVE-2018-1382IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc...
CVE-2018-1366IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this...
CVE-2018-6823In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implemen...
CVE-2018-6822In PureVPN 6.0.1 on macOS, HelperTool LaunchDaemon implements an unprotected XPC service that can be abused to execute s...
CVE-2018-6799The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause ...
CVE-2018-6794Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious se...
CVE-2018-6603Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injecti...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now