2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000160 | — | — | 1.3% | Apr 18, 2018 | RisingStack protect version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in isXss() function in... |
| CVE-2018-1000159 | — | — | 0.8% | Apr 18, 2018 | tlslite-ng version 0.7.3 and earlier, since commit d7b288316bca7bcdd082e6ccff5491e241305233 contains a CWE-354: Improper... |
| CVE-2018-1000158 | — | — | 1.1% | Apr 18, 2018 | cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in ... |
| CVE-2018-8831 | — | — | 53.9% | Apr 18, 2018 | A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/s... |
| CVE-2018-1274 | HIGH | 7.5 | 2.0% | Apr 18, 2018 | Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path par... |
| CVE-2018-1240 | — | — | 0.5% | Apr 18, 2018 | Dell EMC ViPR Controller, versions after 3.0.0.38, contain an information exposure vulnerability in the VRRP. VRRP defau... |
| CVE-2018-1088 | HIGH | 8.1 | 5.4% | Apr 18, 2018 | A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster vol... |
| CVE-2018-6413 | — | — | 1.7% | Apr 18, 2018 | There is a buffer overflow in the Hikvision Camera DS-2CD9111-S of V4.1.2 build 160203 and before, and this vulnerabilit... |
| CVE-2018-10199 | — | — | 2.3% | Apr 18, 2018 | In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_cop... |
| CVE-2018-9999 | — | — | 0.7% | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR stor... |
| CVE-2018-9990 | — | — | 0.8% | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead. |
| CVE-2018-9987 | — | — | 0.8% | Apr 18, 2018 | In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications. |
| CVE-2018-9986 | — | — | 0.8% | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor. |
| CVE-2018-8092 | — | — | 1.7% | Apr 18, 2018 | Mautic before 2.13.0 allows CSV injection. |
| CVE-2018-8071 | — | — | 0.8% | Apr 18, 2018 | Mautic before v2.13.0 has stored XSS via a theme config file. |
| CVE-2018-5342 | — | — | 3.8% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central an... |
| CVE-2018-5341 | — | — | 8.2% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the f... |
| CVE-2018-5340 | — | — | 5.2% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser ac... |
| CVE-2018-5339 | — | — | 7.6% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database... |
| CVE-2018-5338 | — | — | 9.0% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization... |
| CVE-2018-5337 | — | — | 9.5% | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NA... |
| CVE-2018-8736 | — | — | 46.9% | Apr 18, 2018 | A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC... |
| CVE-2018-8735 | — | — | 64.2% | Apr 18, 2018 | Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut... |
| CVE-2018-8734 | — | — | 53.2% | Apr 18, 2018 | SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker... |
| CVE-2018-8733 | — | — | 27.5% | Apr 18, 2018 | Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now