2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-19856GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API...
CVE-2018-15583MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject...
CVE-2018-12653A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious Jav...
CVE-2018-12652A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied in...
CVE-2018-16858HIGH7.8It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could...
CVE-2018-16838MEDIUM5.4A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict p...
CVE-2018-20165Cross-site scripting (XSS) vulnerability in OpenText Portal 7.4.4 allows remote attackers to inject arbitrary web script...
CVE-2018-18913HIGH7.8Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive...
CVE-2018-20034HIGH7.5A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet P...
CVE-2018-20032HIGH7.5A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher...
CVE-2018-20031HIGH7.5A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet P...
CVE-2018-13798A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V14), SICAM A8000 CP-802X (All versions < V14...
CVE-2018-3968HIGH7An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.0...
CVE-2018-4030HIGH7.5An exploitable vulnerability exists the safe browsing function of the CUJO Smart Firewall, version 7003. The bug lies in...
CVE-2018-4011HIGH7.5An exploitable integer underflow vulnerability exists in the mdnscap binary of the CUJO Smart Firewall, version 7003. Wh...
CVE-2018-4003CRITICAL9.8An exploitable heap overflow vulnerability exists in the mdnscap binary of the CUJO Smart Firewall running firmware 7003...
CVE-2018-3985CRITICAL9.8An exploitable double free vulnerability exists in the mdnscap binary of the CUJO Smart Firewall. When parsing mDNS pack...
CVE-2018-3969HIGH7.8An exploitable vulnerability exists in the verified boot protection of the CUJO Smart Firewall. It is possible to add ar...
CVE-2018-3963HIGH8An exploitable command injection vulnerability exists in the DHCP daemon configuration of the CUJO Smart Firewall. When ...
CVE-2018-6517Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting add...
CVE-2018-4059CRITICAL9.8An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version ...
CVE-2018-4058HIGH7.7An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5...
CVE-2018-20737An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.
CVE-2018-20736An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.
CVE-2018-20669HIGH7.8An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in driver...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now