2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11487 | — | — | 0.7% | May 26, 2018 | PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php. |
| CVE-2018-9091 | — | — | 3.3% | May 25, 2018 | A critical vulnerability in the KEMP LoadMaster Operating System (LMOS) 6.0.44 through 7.2.41.2 and Long Term Support (L... |
| CVE-2018-11479 | — | — | 9.9% | May 25, 2018 | The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s... |
| CVE-2018-11475 | — | — | 1.1% | May 25, 2018 | Monstra CMS 3.0.4 has a Session Management Issue in the Users tab. A password change at users/1/edit does not invalidate... |
| CVE-2018-11474 | — | — | 1.1% | May 25, 2018 | Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=use... |
| CVE-2018-11473 | — | — | 2.3% | May 25, 2018 | Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration). |
| CVE-2018-11472 | — | — | 0.9% | May 25, 2018 | Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php). |
| CVE-2018-11471 | — | — | 0.6% | May 25, 2018 | Cockpit 0.5.5 has XSS via a collection, form, or region. |
| CVE-2018-8871 | CRITICAL | 9.8 | 3.9% | May 25, 2018 | In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based bu... |
| CVE-2018-8864 | — | — | 0.2% | May 25, 2018 | In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, a missing encryption ... |
| CVE-2018-8862 | — | — | 0.6% | May 25, 2018 | In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentic... |
| CVE-2018-6237 | — | — | 6.4% | May 25, 2018 | A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker t... |
| CVE-2018-6236 | — | — | 0.3% | May 25, 2018 | A Time-of-Check Time-of-Use privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could all... |
| CVE-2018-6235 | — | — | 0.5% | May 25, 2018 | An Out-of-Bounds write privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a ... |
| CVE-2018-6234 | — | — | 0.7% | May 25, 2018 | An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a... |
| CVE-2018-6233 | — | — | 0.5% | May 25, 2018 | A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local... |
| CVE-2018-6232 | — | — | 0.5% | May 25, 2018 | A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local... |
| CVE-2018-10350 | — | — | 15.2% | May 25, 2018 | A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow ... |
| CVE-2018-1565 | HIGH | 8.4 | 0.4% | May 25, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ... |
| CVE-2018-1544 | HIGH | 8.4 | 0.4% | May 25, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ... |
| CVE-2018-1515 | HIGH | 7.4 | 0.4% | May 25, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1, under specific or unusual conditions, c... |
| CVE-2018-1488 | HIGH | 8.4 | 0.5% | May 25, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, whic... |
| CVE-2018-1467 | MEDIUM | 5.3 | 2.0% | May 25, 2018 | The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. I... |
| CVE-2018-1459 | — | — | 0.5% | May 25, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to stack based... |
| CVE-2018-1452 | — | — | 0.4% | May 25, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now