2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-0354A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduc...
CVE-2018-0352A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could al...
CVE-2018-0340A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an au...
CVE-2018-0339A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic...
CVE-2018-0338HIGH7.8A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allo...
CVE-2018-0336A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated...
CVE-2018-0335A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauth...
CVE-2018-0334A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConne...
CVE-2018-0333A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, r...
CVE-2018-0332A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software co...
CVE-2018-0329MEDIUM5.3A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area...
CVE-2018-0149A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and ...
CVE-2018-12043content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.
CVE-2018-12042Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.
CVE-2018-10619An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3....
CVE-2018-12039joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php ...
CVE-2018-6670HIGH7.6External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated us...
CVE-2018-12036OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds direct...
CVE-2018-12031Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrad...
CVE-2018-1547HIGH8IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on ...
CVE-2018-1514MEDIUM4.3IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could all...
CVE-2018-12016libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (applic...
CVE-2018-7689HIGH7.1Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed aut...
CVE-2018-7688HIGH7.1A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated ...
CVE-2018-12015In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mecha...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now