2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-0514MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via u...
CVE-2018-0513Cross-site scripting vulnerability in MTS Simple Booking C, MTS Simple Booking Business version 1.28.0 and earlier allow...
CVE-2018-0512Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to ...
CVE-2018-6844MyBB 1.8.14 has XSS via the Title or Description field on the Edit Forum screen.
CVE-2018-6836The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an un...
CVE-2018-6835node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass ...
CVE-2018-6834static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
CVE-2018-0140MEDIUM6.5A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance...
CVE-2018-0138MEDIUM5.3A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack...
CVE-2018-0137A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to ...
CVE-2018-0135A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitiv...
CVE-2018-0134MEDIUM5.3A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacke...
CVE-2018-0132A vulnerability in the forwarding information base (FIB) code of Cisco IOS XR Software could allow an unauthenticated, r...
CVE-2018-0129A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenti...
CVE-2018-0128A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenti...
CVE-2018-0127CRITICAL9.8A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VP...
CVE-2018-0125CRITICAL9.8A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers ...
CVE-2018-0123A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow an authenticated, l...
CVE-2018-0122MEDIUM4.4A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c...
CVE-2018-0120A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attack...
CVE-2018-0119A vulnerability in certain authentication controls in the account services of Cisco Spark could allow an authenticated, ...
CVE-2018-0117A vulnerability in the ingress packet processing functionality of the Cisco Virtualized Packet Core-Distributed Instance...
CVE-2018-0116A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacke...
CVE-2018-0113A vulnerability in an operations script of Cisco UCS Central could allow an authenticated, remote attacker to execute ar...
CVE-2018-6829cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, whic...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now