2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9038 | — | — | 9.8% | Apr 10, 2018 | Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uplo... |
| CVE-2018-9037 | — | — | 2.9% | Apr 10, 2018 | Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extrac... |
| CVE-2018-8772 | — | — | 1.8% | Apr 10, 2018 | Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen. |
| CVE-2018-2413 | MEDIUM | 5.4 | 1.5% | Apr 10, 2018 | SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in e... |
| CVE-2018-2412 | LOW | 3.8 | 1.4% | Apr 10, 2018 | SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in e... |
| CVE-2018-2410 | MEDIUM | 5.4 | 1.0% | Apr 10, 2018 | SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross... |
| CVE-2018-2409 | MEDIUM | 6.3 | 1.3% | Apr 10, 2018 | Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain ... |
| CVE-2018-2408 | HIGH | 7.3 | 1.6% | Apr 10, 2018 | Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Laun... |
| CVE-2018-2406 | MEDIUM | 5.3 | 0.4% | Apr 10, 2018 | Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0... |
| CVE-2018-2405 | MEDIUM | 5.4 | 1.0% | Apr 10, 2018 | SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an ... |
| CVE-2018-2404 | MEDIUM | 4.3 | 2.0% | Apr 10, 2018 | SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation. |
| CVE-2018-2403 | MEDIUM | 5.4 | 1.2% | Apr 10, 2018 | Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise ... |
| CVE-2018-5227 | — | — | 0.6% | Apr 10, 2018 | Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attac... |
| CVE-2018-9934 | — | — | 1.4% | Apr 10, 2018 | The reset-password feature in MetInfo 6.0 allows remote attackers to change arbitrary passwords via vectors involving a ... |
| CVE-2018-9928 | — | — | 0.8% | Apr 10, 2018 | Cross-site scripting (XSS) vulnerability in save.php in MetInfo 6.0 allows remote attackers to inject arbitrary web scri... |
| CVE-2018-9927 | — | — | 0.7% | Apr 10, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=me... |
| CVE-2018-9926 | — | — | 3.1% | Apr 10, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=... |
| CVE-2018-9925 | — | — | 0.6% | Apr 10, 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&d... |
| CVE-2018-9924 | — | — | 1.5% | Apr 10, 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp... |
| CVE-2018-9923 | — | — | 0.6% | Apr 10, 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an artic... |
| CVE-2018-9922 | — | — | 1.2% | Apr 10, 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field tha... |
| CVE-2018-9840 | — | — | 0.4% | Apr 10, 2018 | The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feat... |
| CVE-2018-5463 | — | — | 0.4% | Apr 9, 2018 | A structured exception handler overflow vulnerability in Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME L... |
| CVE-2018-6182 | — | — | 0.7% | Apr 9, 2018 | Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE i... |
| CVE-2018-1217 | — | — | 46.6% | Apr 9, 2018 | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection A... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now