2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7445 | CRITICAL | 9.8 | 61.0% | Mar 19, 2018 | A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remot... |
| CVE-2018-7262 | — | — | 3.0% | Mar 19, 2018 | In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't han... |
| CVE-2018-5233 | — | — | 3.4% | Mar 19, 2018 | Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote ... |
| CVE-2018-8732 | — | — | 1.7% | Mar 19, 2018 | Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or H... |
| CVE-2018-1226 | — | — | — | Mar 19, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-1225 | — | — | — | Mar 19, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-1224 | — | — | — | Mar 19, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-1221 | HIGH | 8.1 | 1.2% | Mar 19, 2018 | In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket reque... |
| CVE-2018-1218 | — | — | 14.0% | Mar 19, 2018 | In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the '... |
| CVE-2018-1197 | — | — | 0.6% | Mar 19, 2018 | In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are a... |
| CVE-2018-1196 | — | — | 1.2% | Mar 19, 2018 | Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d lin... |
| CVE-2018-1195 | HIGH | 8.8 | 1.0% | Mar 19, 2018 | In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 28... |
| CVE-2018-1171 | HIGH | 7 | 0.4% | Mar 19, 2018 | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-2... |
| CVE-2018-5552 | LOW | 2.9 | 0.2% | Mar 19, 2018 | Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contains a ... |
| CVE-2018-5551 | CRITICAL | 9 | 1.7% | Mar 19, 2018 | Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain thr... |
| CVE-2018-8761 | — | — | 0.9% | Mar 19, 2018 | protected\apps\member\controller\shopcarController.php in Yxcms building system (compatible cell phone) v1.4.7 has a log... |
| CVE-2018-7422 | — | — | 63.1% | Mar 19, 2018 | A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re... |
| CVE-2018-6843 | — | — | 1.2% | Mar 19, 2018 | Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface. |
| CVE-2018-6842 | — | — | 0.6% | Mar 19, 2018 | Kentico 10 before 10.0.50 and 11 before 11.0.3 has XSS in which a crafted URL results in improper construction of a syst... |
| CVE-2018-8770 | MEDIUM | 5.3 | 60.6% | Mar 18, 2018 | Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, contro... |
| CVE-2018-8769 | — | — | 0.9% | Mar 18, 2018 | elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_... |
| CVE-2018-8768 | — | — | 1.1% | Mar 18, 2018 | In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in th... |
| CVE-2018-8767 | — | — | 0.6% | Mar 18, 2018 | joyplus-cms 1.6.0 has XSS in manager/admin_ajax.php?action=save&tab={pre}vod_type via the t_name parameter. |
| CVE-2018-8766 | — | — | 3.4% | Mar 18, 2018 | joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, r... |
| CVE-2018-8765 | — | — | 0.4% | Mar 18, 2018 | In 2345 Security Guard 3.6, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now