2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8926 | HIGH | 8.8 | 1.7% | Jun 8, 2018 | Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before... |
| CVE-2018-8925 | HIGH | 8.8 | 0.7% | Jun 8, 2018 | Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before... |
| CVE-2018-1453 | HIGH | 8.8 | 2.1% | Jun 8, 2018 | IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dang... |
| CVE-2018-3758 | HIGH | 8.8 | 27.5% | Jun 7, 2018 | Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hostin... |
| CVE-2018-0338 | HIGH | 7.8 | 0.4% | Jun 7, 2018 | A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allo... |
| CVE-2018-6670 | HIGH | 7.6 | 1.3% | Jun 7, 2018 | External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated us... |
| CVE-2018-1547 | HIGH | 8 | 2.2% | Jun 7, 2018 | IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on ... |
| CVE-2018-7689 | HIGH | 7.1 | 1.2% | Jun 7, 2018 | Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed aut... |
| CVE-2018-7688 | HIGH | 7.1 | 1.1% | Jun 7, 2018 | A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated ... |
| CVE-2018-0296 | HIGH | 7.5 | 99.9% | Jun 7, 2018 | A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo... |
| CVE-2018-0274 | HIGH | 8.8 | 4.0% | Jun 7, 2018 | A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote atta... |
| CVE-2018-0263 | HIGH | 7.4 | 0.7% | Jun 7, 2018 | A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services runni... |
| CVE-2018-3737 | HIGH | 7.5 | 1.7% | Jun 7, 2018 | sshpk is vulnerable to ReDoS when parsing crafted invalid public keys. |
| CVE-2018-3732 | HIGH | 7.5 | 2.4% | Jun 7, 2018 | resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths wit... |
| CVE-2018-3731 | HIGH | 7.5 | 2.0% | Jun 7, 2018 | public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a mal... |
| CVE-2018-3730 | HIGH | 7.5 | 2.0% | Jun 7, 2018 | mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a m... |
| CVE-2018-3729 | HIGH | 7.5 | 2.0% | Jun 7, 2018 | localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a ... |
| CVE-2018-3727 | HIGH | 7.5 | 2.0% | Jun 7, 2018 | 626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious ... |
| CVE-2018-3725 | HIGH | 7.5 | 2.0% | Jun 7, 2018 | hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a maliciou... |
| CVE-2018-3720 | HIGH | 8.8 | 2.0% | Jun 7, 2018 | assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which a... |
| CVE-2018-3719 | HIGH | 8.8 | 2.1% | Jun 7, 2018 | mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which al... |
| CVE-2018-3711 | HIGH | 7.5 | 1.8% | Jun 7, 2018 | Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: a... |
| CVE-2018-3852 | HIGH | 7.5 | 1.9% | Jun 6, 2018 | An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A sp... |
| CVE-2018-1000194 | HIGH | 8.1 | 2.6% | Jun 5, 2018 | A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFi... |
| CVE-2018-10601 | HIGH | 8.2 | 0.4% | Jun 5, 2018 | IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monit... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now