2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-10255HIGH8.8A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level pri...
CVE-2018-9336openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a do...
CVE-2018-9232Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can cr...
CVE-2018-6589HIGH7.5CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of ...
CVE-2018-8939An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit speci...
CVE-2018-8938A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious act...
CVE-2018-10583An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p...
CVE-2018-10365An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the opt...
CVE-2018-1502IBM Content Manager Enterprise Edition Resource Manager 8.4.3 and 9.5 is vulnerable to cross-site scripting. This vulner...
CVE-2018-10581In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Te...
CVE-2018-10371An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin...
CVE-2018-1000166Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-3848 and CVE-2018-3849. Reason: This candidate ...
CVE-2018-10576An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentica...
CVE-2018-10575An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentia...
CVE-2018-1000172Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Ti...
CVE-2018-1194Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-10364BigTree before 4.2.22 has XSS in the Users management page via the name or company field.
CVE-2018-1277Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A r...
CVE-2018-1183In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance...
CVE-2018-10574site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PH...
CVE-2018-1102A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of ta...
CVE-2018-5234The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic...
CVE-2018-9310An issue was discovered in MagniComp SysInfo before 10-H82 if setuid root (the default). This vulnerability allows any l...
CVE-2018-10573interface/fax/fax_dispatch.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restr...
CVE-2018-10572interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access re...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now