2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9126 | — | — | 50.2% | Apr 4, 2018 | The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and conseque... |
| CVE-2018-9115 | — | — | 6.0% | Apr 4, 2018 | Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG... |
| CVE-2018-9035 | — | — | 7.7% | Apr 4, 2018 | CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr... |
| CVE-2018-9034 | — | — | 2.0% | Apr 4, 2018 | Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote... |
| CVE-2018-8719 | — | — | 15.8% | Apr 4, 2018 | An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-securit... |
| CVE-2018-9275 | — | — | 1.5% | Apr 4, 2018 | In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak fi... |
| CVE-2018-9119 | — | — | 0.4% | Apr 4, 2018 | An attacker with physical access to a BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4) can unlock the car... |
| CVE-2018-1469 | CRITICAL | 9.8 | 2.8% | Apr 4, 2018 | IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system comma... |
| CVE-2018-1447 | MEDIUM | 5.1 | 0.9% | Apr 4, 2018 | The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic f... |
| CVE-2018-1421 | HIGH | 7.1 | 1.4% | Apr 4, 2018 | IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection... |
| CVE-2018-6874 | — | — | 0.8% | Apr 4, 2018 | CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled. |
| CVE-2018-6873 | — | — | 2.3% | Apr 4, 2018 | The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated... |
| CVE-2018-0986 | HIGH | 8.8 | 61.5% | Apr 4, 2018 | A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a speci... |
| CVE-2018-9249 | — | — | 6.3% | Apr 4, 2018 | FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScr... |
| CVE-2018-9248 | — | — | 15.3% | Apr 4, 2018 | FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header. |
| CVE-2018-9205 | — | — | 56.9% | Apr 4, 2018 | Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. |
| CVE-2018-8814 | — | — | 3.2% | Apr 4, 2018 | Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication ... |
| CVE-2018-8813 | — | — | 3.4% | Apr 4, 2018 | Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attack... |
| CVE-2018-6919 | — | — | 1.4% | Apr 4, 2018 | In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, due to insufficient i... |
| CVE-2018-6918 | — | — | 4.4% | Apr 4, 2018 | In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of t... |
| CVE-2018-6917 | — | — | 2.0% | Apr 4, 2018 | In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, insufficient validati... |
| CVE-2018-9274 | — | — | 2.2% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, ui/failure_message.c has a memory leak. |
| CVE-2018-9273 | — | — | 2.2% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-pcp.c has a memory leak. |
| CVE-2018-9272 | — | — | 2.1% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-h223.c has a memory leak. |
| CVE-2018-9271 | — | — | 2.1% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-multipart.c has a memory leak. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now