2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-7311HIGH8.8PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability. The software installs a privileged h...
CVE-2018-7281CactusVPN 5.3.6 for macOS contains a root privilege escalation vulnerability through a setuid root binary called runme. ...
CVE-2018-6936Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.
CVE-2018-7308A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users...
CVE-2018-7305MyBB 1.8.14 is not checking for a valid CSRF token, leading to arbitrary deletion of user accounts.
CVE-2018-7304Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE o...
CVE-2018-7303The Calendar component in Tiki 17.1 allows HTML injection.
CVE-2018-7302Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
CVE-2018-7289An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames cont...
CVE-2018-7280The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
CVE-2018-7261There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Usern...
CVE-2018-7260Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticate...
CVE-2018-5716HIGH8.1An issue was discovered in Reprise License Manager 11.0. This vulnerability is a Path Traversal where the attacker, by c...
CVE-2018-1168This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with ...
CVE-2018-1166This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-2...
CVE-2018-1165HIGH7This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-2...
CVE-2018-1164This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P...
CVE-2018-7278An issue was discovered on RLE Protocol Converter FDS-PC / FDS-PC-DP 2.1 devices. Persistent XSS exists in the web serve...
CVE-2018-7277An issue was discovered on RLE Wi-MGR/FDS-Wi 6.2 devices. Persistent XSS exists in the web server. Remote attackers can ...
CVE-2018-7276An issue was discovered on Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) devices. Remote attackers can obtain...
CVE-2018-7274MEDIUM6.1Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Questio...
CVE-2018-7273In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi...
CVE-2018-7272The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sen...
CVE-2018-7271An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php c...
CVE-2018-7265Shimmie 2 2.6.0 allows an attacker to upload a crafted SVG file that enables stored XSS.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now