2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0194 | — | — | 0.6% | Apr 2, 2018 | Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inje... |
| CVE-2018-6661 | HIGH | 7.8 | 0.8% | Apr 2, 2018 | DLL Side-Loading vulnerability in Microsoft Windows Client in McAfee True Key before 4.20.110 allows local users to gain... |
| CVE-2018-6660 | MEDIUM | 6.2 | 1.7% | Apr 2, 2018 | Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrato... |
| CVE-2018-1038 | — | — | 8.9% | Apr 2, 2018 | The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to... |
| CVE-2018-9163 | — | — | 5.0% | Apr 2, 2018 | A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) all... |
| CVE-2018-9175 | — | — | 1.9% | Apr 2, 2018 | DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_ma... |
| CVE-2018-9174 | — | — | 1.5% | Apr 2, 2018 | sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, b... |
| CVE-2018-9173 | — | — | 2.5% | Apr 2, 2018 | Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows rem... |
| CVE-2018-1095 | — | — | 1.5% | Apr 2, 2018 | The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate ... |
| CVE-2018-1094 | MEDIUM | 5.5 | 2.1% | Apr 2, 2018 | The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32... |
| CVE-2018-1093 | — | — | 2.0% | Apr 2, 2018 | The ext4_valid_block_bitmap function in fs/ext4/balloc.c in the Linux kernel through 4.15.15 allows attackers to cause a... |
| CVE-2018-1092 | — | — | 2.0% | Apr 2, 2018 | The ext4_iget function in fs/ext4/inode.c in the Linux kernel through 4.15.15 mishandles the case of a root directory wi... |
| CVE-2018-9172 | — | — | 3.2% | Apr 1, 2018 | The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. |
| CVE-2018-9165 | — | — | 1.1% | Apr 1, 2018 | The pushdup function in util/decompile.c in libming through 0.4.8 does not recognize the need for ActionPushDuplicate to... |
| CVE-2018-9158 | — | — | 1.3% | Apr 1, 2018 | An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mech... |
| CVE-2018-9157 | — | — | 3.2% | Apr 1, 2018 | An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verif... |
| CVE-2018-9156 | — | — | 3.9% | Apr 1, 2018 | An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify ... |
| CVE-2018-9149 | — | — | 0.5% | Apr 1, 2018 | The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an at... |
| CVE-2018-6849 | — | — | 30.1% | Apr 1, 2018 | In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client informati... |
| CVE-2018-9128 | — | — | 4.9% | Apr 1, 2018 | DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068. |
| CVE-2018-9162 | — | — | 2.4% | Mar 31, 2018 | Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.... |
| CVE-2018-9161 | — | — | 58.5% | Mar 31, 2018 | Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the... |
| CVE-2018-8908 | — | — | 2.4% | Mar 31, 2018 | An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CS... |
| CVE-2018-8893 | — | — | 0.5% | Mar 31, 2018 | Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code. |
| CVE-2018-9160 | — | — | 76.5% | Mar 31, 2018 | SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now