2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19856 | — | — | 2.3% | Mar 26, 2019 | GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API... |
| CVE-2018-15583 | MEDIUM | 6.1 | 1.1% | Mar 25, 2019 | Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject... |
| CVE-2018-12653 | — | — | 2.6% | Mar 25, 2019 | A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious Jav... |
| CVE-2018-12652 | — | — | 0.9% | Mar 25, 2019 | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied in... |
| CVE-2018-16858 | HIGH | 7.8 | 67.5% | Mar 25, 2019 | It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could... |
| CVE-2018-16838 | MEDIUM | 5.4 | 1.1% | Mar 25, 2019 | A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict p... |
| CVE-2018-20165 | — | — | 1.5% | Mar 22, 2019 | Cross-site scripting (XSS) vulnerability in OpenText Portal 7.4.4 allows remote attackers to inject arbitrary web script... |
| CVE-2018-18913 | HIGH | 7.8 | 0.4% | Mar 21, 2019 | Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive... |
| CVE-2018-20034 | HIGH | 7.5 | 2.8% | Mar 21, 2019 | A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet P... |
| CVE-2018-20032 | HIGH | 7.5 | 2.2% | Mar 21, 2019 | A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher... |
| CVE-2018-20031 | HIGH | 7.5 | 2.2% | Mar 21, 2019 | A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet P... |
| CVE-2018-13798 | — | — | 2.0% | Mar 21, 2019 | A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V14), SICAM A8000 CP-802X (All versions < V14... |
| CVE-2018-3968 | HIGH | 7 | 0.3% | Mar 21, 2019 | An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.0... |
| CVE-2018-4030 | HIGH | 7.5 | 1.2% | Mar 21, 2019 | An exploitable vulnerability exists the safe browsing function of the CUJO Smart Firewall, version 7003. The bug lies in... |
| CVE-2018-4011 | HIGH | 7.5 | 1.3% | Mar 21, 2019 | An exploitable integer underflow vulnerability exists in the mdnscap binary of the CUJO Smart Firewall, version 7003. Wh... |
| CVE-2018-4003 | CRITICAL | 9.8 | 1.8% | Mar 21, 2019 | An exploitable heap overflow vulnerability exists in the mdnscap binary of the CUJO Smart Firewall running firmware 7003... |
| CVE-2018-3985 | CRITICAL | 9.8 | 1.9% | Mar 21, 2019 | An exploitable double free vulnerability exists in the mdnscap binary of the CUJO Smart Firewall. When parsing mDNS pack... |
| CVE-2018-3969 | HIGH | 7.8 | 0.5% | Mar 21, 2019 | An exploitable vulnerability exists in the verified boot protection of the CUJO Smart Firewall. It is possible to add ar... |
| CVE-2018-3963 | HIGH | 8 | 2.6% | Mar 21, 2019 | An exploitable command injection vulnerability exists in the DHCP daemon configuration of the CUJO Smart Firewall. When ... |
| CVE-2018-6517 | — | — | 0.9% | Mar 21, 2019 | Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting add... |
| CVE-2018-4059 | CRITICAL | 9.8 | 1.9% | Mar 21, 2019 | An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version ... |
| CVE-2018-4058 | HIGH | 7.7 | 0.9% | Mar 21, 2019 | An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5... |
| CVE-2018-20737 | — | — | 1.0% | Mar 21, 2019 | An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product. |
| CVE-2018-20736 | — | — | 1.0% | Mar 21, 2019 | An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product. |
| CVE-2018-20669 | HIGH | 7.8 | 0.6% | Mar 21, 2019 | An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in driver... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now