2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3734 | HIGH | 7.5 | 1.9% | May 29, 2018 | stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malici... |
| CVE-2018-3733 | HIGH | 7.5 | 2.2% | May 29, 2018 | crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url... |
| CVE-2018-11392 | — | — | 4.6% | May 29, 2018 | An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.... |
| CVE-2018-11027 | — | — | 0.8% | May 29, 2018 | A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTM... |
| CVE-2018-10751 | — | — | 8.7% | May 29, 2018 | A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex... |
| CVE-2018-10466 | — | — | 8.3% | May 29, 2018 | Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection. |
| CVE-2018-1495 | MEDIUM | 6.5 | 1.6% | May 29, 2018 | IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitr... |
| CVE-2018-1242 | — | — | 2.8% | May 29, 2018 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command inj... |
| CVE-2018-1241 | — | — | 1.6% | May 29, 2018 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditio... |
| CVE-2018-1235 | — | — | 43.3% | May 29, 2018 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje... |
| CVE-2018-5241 | — | — | 4.8% | May 29, 2018 | Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authenticati... |
| CVE-2018-1376 | MEDIUM | 6.1 | 0.9% | May 29, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allow... |
| CVE-2018-1375 | MEDIUM | 5.9 | 2.0% | May 29, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentica... |
| CVE-2018-1370 | MEDIUM | 4.2 | 0.6% | May 29, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 specifies permissions for a security-critical resource in a way... |
| CVE-2018-1369 | LOW | 3.7 | 1.1% | May 29, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead t... |
| CVE-2018-11536 | — | — | 1.7% | May 29, 2018 | md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits. |
| CVE-2018-11535 | — | — | 3.3% | May 29, 2018 | An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.... |
| CVE-2018-11532 | — | — | 2.4% | May 29, 2018 | An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonst... |
| CVE-2018-11531 | — | — | 3.0% | May 29, 2018 | Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp. |
| CVE-2018-11528 | — | — | 1.6% | May 29, 2018 | WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI. |
| CVE-2018-11527 | — | — | 0.6% | May 29, 2018 | An issue was discovered in CScms v4.1. A Cross-site request forgery (CSRF) vulnerability in plugins/sys/admin/Sys.php al... |
| CVE-2018-11523 | — | — | 9.9% | May 29, 2018 | upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files. |
| CVE-2018-11488 | — | — | 4.9% | May 29, 2018 | A stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cau... |
| CVE-2018-10732 | — | — | 1.6% | May 28, 2018 | The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a u... |
| CVE-2018-11517 | — | — | 2.1% | May 28, 2018 | mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter valu... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now