2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10048 | — | — | 0.5% | Apr 11, 2018 | iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel. |
| CVE-2018-1100 | HIGH | 7.8 | 0.5% | Apr 11, 2018 | zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local ... |
| CVE-2018-10033 | — | — | 0.6% | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter. |
| CVE-2018-10032 | — | — | 0.5% | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter. |
| CVE-2018-10031 | — | — | 0.5% | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php. |
| CVE-2018-10030 | — | — | 0.5% | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php. |
| CVE-2018-10029 | — | — | 0.5% | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to m... |
| CVE-2018-0023 | MEDIUM | 5.5 | 0.3% | Apr 11, 2018 | JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github. T... |
| CVE-2018-0022 | HIGH | 7.5 | 2.3% | Apr 11, 2018 | A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when ... |
| CVE-2018-0021 | HIGH | 8.8 | 0.6% | Apr 11, 2018 | If all 64 digits of the connectivity association name (CKN) key or all 32 digits of the connectivity association key (CA... |
| CVE-2018-0020 | HIGH | 7.5 | 1.4% | Apr 11, 2018 | Junos OS may be impacted by the receipt of a malformed BGP UPDATE which can lead to a routing process daemon (rpd) crash... |
| CVE-2018-0019 | MEDIUM | 5.3 | 1.6% | Apr 11, 2018 | A vulnerability in Junos OS SNMP MIB-II subagent daemon (mib2d) may allow a remote network based attacker to cause the m... |
| CVE-2018-0018 | HIGH | 7.5 | 1.5% | Apr 11, 2018 | On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted packets may be able to b... |
| CVE-2018-0017 | HIGH | 7.5 | 1.9% | Apr 11, 2018 | A vulnerability in the Network Address Translation - Protocol Translation (NAT-PT) feature of Junos OS on SRX series dev... |
| CVE-2018-0016 | CRITICAL | 9.8 | 4.2% | Apr 11, 2018 | Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS de... |
| CVE-2018-10028 | — | — | 1.5% | Apr 11, 2018 | joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ U... |
| CVE-2018-10026 | — | — | 0.5% | Apr 11, 2018 | The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the val... |
| CVE-2018-8954 | — | — | 7.3% | Apr 11, 2018 | CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request... |
| CVE-2018-8953 | — | — | 2.8% | Apr 11, 2018 | CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP reque... |
| CVE-2018-7930 | — | — | 0.4% | Apr 11, 2018 | The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C56... |
| CVE-2018-10024 | — | — | 1.4% | Apr 11, 2018 | ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed lo... |
| CVE-2018-10023 | — | — | 0.7% | Apr 11, 2018 | Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment). |
| CVE-2018-10021 | — | — | 0.5% | Apr 11, 2018 | drivers/scsi/libsas/sas_scsi_host.c in the Linux kernel before 4.16 allows local users to cause a denial of service (ata... |
| CVE-2018-1483 | MEDIUM | 6.1 | 1.3% | Apr 11, 2018 | IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2018-3594 | — | — | 1.3% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon W... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now