2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1453 | HIGH | 8.8 | 2.1% | Jun 8, 2018 | IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dang... |
| CVE-2018-12065 | — | — | 2.6% | Jun 8, 2018 | A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to... |
| CVE-2018-12064 | — | — | 1.3% | Jun 8, 2018 | tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h. |
| CVE-2018-11409 | — | — | 98.2% | Jun 8, 2018 | Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json ... |
| CVE-2018-10088 | — | — | 40.4% | Jun 8, 2018 | Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE... |
| CVE-2018-12055 | — | — | 3.3% | Jun 8, 2018 | Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.ph... |
| CVE-2018-12054 | — | — | 39.4% | Jun 8, 2018 | Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol... |
| CVE-2018-12053 | — | — | 11.0% | Jun 8, 2018 | Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p... |
| CVE-2018-12052 | — | — | 4.7% | Jun 8, 2018 | SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php. |
| CVE-2018-12051 | — | — | 2.9% | Jun 8, 2018 | Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in ... |
| CVE-2018-9246 | — | — | 2.6% | Jun 8, 2018 | The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes... |
| CVE-2018-9182 | — | — | 1.4% | Jun 8, 2018 | Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section. |
| CVE-2018-9177 | — | — | 0.7% | Jun 8, 2018 | Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen. |
| CVE-2018-12049 | — | — | 5.2% | Jun 8, 2018 | A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.c... |
| CVE-2018-12048 | — | — | 5.2% | Jun 8, 2018 | A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi ... |
| CVE-2018-12047 | — | — | 0.9% | Jun 8, 2018 | xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by ... |
| CVE-2018-12046 | — | — | 1.0% | Jun 8, 2018 | DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=... |
| CVE-2018-12045 | — | — | 1.4% | Jun 8, 2018 | DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmd... |
| CVE-2018-12041 | — | — | 1.1% | Jun 8, 2018 | An issue was discovered on the MediaTek AWUS036NH wireless USB adapter through 5.1.25.0. Attackers can remotely deny ser... |
| CVE-2018-11229 | — | — | 5.7% | Jun 8, 2018 | Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthe... |
| CVE-2018-11228 | — | — | 7.6% | Jun 8, 2018 | Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthe... |
| CVE-2018-3758 | HIGH | 8.8 | 27.5% | Jun 7, 2018 | Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hostin... |
| CVE-2018-0357 | — | — | 2.0% | Jun 7, 2018 | A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-s... |
| CVE-2018-0356 | — | — | 1.8% | Jun 7, 2018 | A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-s... |
| CVE-2018-0355 | MEDIUM | 6.1 | 1.8% | Jun 7, 2018 | A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remot... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now