2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-10250iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Manageme...
CVE-2018-10248An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=co...
CVE-2018-10245A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is all...
CVE-2018-6960VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypa...
CVE-2018-0564Session fixation vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3..4, EC-...
CVE-2018-10201An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible t...
CVE-2018-10238bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of pack...
CVE-2018-0276A vulnerability in Cisco WebEx Connect IM could allow an unauthenticated, remote attacker to conduct a cross-site script...
CVE-2018-0275A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, loca...
CVE-2018-0273A vulnerability in the IPsec Manager of Cisco StarOS for Cisco Aggregation Services Router (ASR) 5000 Series Routers and...
CVE-2018-0272A vulnerability in the Secure Sockets Layer (SSL) Engine of Cisco Firepower System Software could allow an unauthenticat...
CVE-2018-0269MEDIUM4.3A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauth...
CVE-2018-0267MEDIUM6.5A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacke...
CVE-2018-0266MEDIUM4.3A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attack...
CVE-2018-0260A vulnerability in the web interface of Cisco MATE Live could allow an unauthenticated, remote attacker to view and down...
CVE-2018-0259A vulnerability in the web-based management interface of Cisco MATE Collector could allow an unauthenticated, remote att...
CVE-2018-0257A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthen...
CVE-2018-0256A vulnerability in the peer-to-peer message processing functionality of Cisco Packet Data Network Gateway could allow an...
CVE-2018-0255A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated...
CVE-2018-0254MEDIUM5.3A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack...
CVE-2018-0251A vulnerability in the Web Server Authentication Required screen of the Clientless Secure Sockets Layer (SSL) VPN portal...
CVE-2018-0244MEDIUM5.8A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack...
CVE-2018-0243MEDIUM5.8A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack...
CVE-2018-0242A vulnerability in the WebVPN web-based management interface of Cisco Adaptive Security Appliance could allow an unauthe...
CVE-2018-0241A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjace...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now