2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-10048iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.
CVE-2018-1100HIGH7.8zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local ...
CVE-2018-10033CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.
CVE-2018-10032CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.
CVE-2018-10031CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.
CVE-2018-10030CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.
CVE-2018-10029CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to m...
CVE-2018-0023MEDIUM5.5JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github. T...
CVE-2018-0022HIGH7.5A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when ...
CVE-2018-0021HIGH8.8If all 64 digits of the connectivity association name (CKN) key or all 32 digits of the connectivity association key (CA...
CVE-2018-0020HIGH7.5Junos OS may be impacted by the receipt of a malformed BGP UPDATE which can lead to a routing process daemon (rpd) crash...
CVE-2018-0019MEDIUM5.3A vulnerability in Junos OS SNMP MIB-II subagent daemon (mib2d) may allow a remote network based attacker to cause the m...
CVE-2018-0018HIGH7.5On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted packets may be able to b...
CVE-2018-0017HIGH7.5A vulnerability in the Network Address Translation - Protocol Translation (NAT-PT) feature of Junos OS on SRX series dev...
CVE-2018-0016CRITICAL9.8Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS de...
CVE-2018-10028joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ U...
CVE-2018-10026The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the val...
CVE-2018-8954CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request...
CVE-2018-8953CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP reque...
CVE-2018-7930The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C56...
CVE-2018-10024ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed lo...
CVE-2018-10023Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).
CVE-2018-10021drivers/scsi/libsas/sas_scsi_host.c in the Linux kernel before 4.16 allows local users to cause a denial of service (ata...
CVE-2018-1483MEDIUM6.1IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2018-3594In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon W...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now