2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1453HIGH8.8IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dang...
CVE-2018-12065A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to...
CVE-2018-12064tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.
CVE-2018-11409Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json ...
CVE-2018-10088Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE...
CVE-2018-12055Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.ph...
CVE-2018-12054Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol...
CVE-2018-12053Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p...
CVE-2018-12052SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
CVE-2018-12051Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in ...
CVE-2018-9246The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes...
CVE-2018-9182Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
CVE-2018-9177Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
CVE-2018-12049A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.c...
CVE-2018-12048A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi ...
CVE-2018-12047xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by ...
CVE-2018-12046DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=...
CVE-2018-12045DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmd...
CVE-2018-12041An issue was discovered on the MediaTek AWUS036NH wireless USB adapter through 5.1.25.0. Attackers can remotely deny ser...
CVE-2018-11229Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthe...
CVE-2018-11228Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthe...
CVE-2018-3758HIGH8.8Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hostin...
CVE-2018-0357A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-s...
CVE-2018-0356A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-s...
CVE-2018-0355MEDIUM6.1A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remot...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now