2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0354 | — | — | 1.8% | Jun 7, 2018 | A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduc... |
| CVE-2018-0352 | — | — | 0.4% | Jun 7, 2018 | A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could al... |
| CVE-2018-0340 | — | — | 1.3% | Jun 7, 2018 | A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an au... |
| CVE-2018-0339 | — | — | 1.8% | Jun 7, 2018 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic... |
| CVE-2018-0338 | HIGH | 7.8 | 0.4% | Jun 7, 2018 | A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allo... |
| CVE-2018-0336 | — | — | 2.4% | Jun 7, 2018 | A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated... |
| CVE-2018-0335 | — | — | 0.4% | Jun 7, 2018 | A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauth... |
| CVE-2018-0334 | — | — | 1.0% | Jun 7, 2018 | A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConne... |
| CVE-2018-0333 | — | — | 1.9% | Jun 7, 2018 | A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, r... |
| CVE-2018-0332 | — | — | 3.5% | Jun 7, 2018 | A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software co... |
| CVE-2018-0329 | MEDIUM | 5.3 | 2.4% | Jun 7, 2018 | A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area... |
| CVE-2018-0149 | — | — | 1.3% | Jun 7, 2018 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and ... |
| CVE-2018-12043 | — | — | 0.8% | Jun 7, 2018 | content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page. |
| CVE-2018-12042 | — | — | 1.8% | Jun 7, 2018 | Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter. |
| CVE-2018-10619 | — | — | 2.8% | Jun 7, 2018 | An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.... |
| CVE-2018-12039 | — | — | 4.7% | Jun 7, 2018 | joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php ... |
| CVE-2018-6670 | HIGH | 7.6 | 1.3% | Jun 7, 2018 | External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated us... |
| CVE-2018-12036 | — | — | 1.7% | Jun 7, 2018 | OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds direct... |
| CVE-2018-12031 | — | — | 17.3% | Jun 7, 2018 | Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrad... |
| CVE-2018-1547 | HIGH | 8 | 2.2% | Jun 7, 2018 | IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on ... |
| CVE-2018-1514 | MEDIUM | 4.3 | 0.5% | Jun 7, 2018 | IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could all... |
| CVE-2018-12016 | — | — | 1.9% | Jun 7, 2018 | libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (applic... |
| CVE-2018-7689 | HIGH | 7.1 | 1.2% | Jun 7, 2018 | Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed aut... |
| CVE-2018-7688 | HIGH | 7.1 | 1.1% | Jun 7, 2018 | A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated ... |
| CVE-2018-12015 | — | — | 8.2% | Jun 7, 2018 | In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mecha... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now