2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8654 | MEDIUM | 6.5 | 1.8% | Jan 24, 2020 | An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation o... |
| CVE-2018-16271 | MEDIUM | 6.5 | 0.8% | Jan 22, 2020 | The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged ... |
| CVE-2018-16268 | MEDIUM | 4.3 | 0.5% | Jan 22, 2020 | The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actio... |
| CVE-2018-16265 | MEDIUM | 6.5 | 0.6% | Jan 22, 2020 | The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the ... |
| CVE-2018-16264 | MEDIUM | 6.5 | 0.6% | Jan 22, 2020 | The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive inf... |
| CVE-2018-17981 | MEDIUM | 6.1 | 0.8% | Jan 22, 2020 | Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter. |
| CVE-2018-1002104 | MEDIUM | 5.3 | 1.1% | Jan 14, 2020 | Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metr... |
| CVE-2018-14476 | MEDIUM | 6.1 | 0.9% | Dec 31, 2019 | GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation. |
| CVE-2018-20507 | MEDIUM | 5.3 | 0.8% | Dec 30, 2019 | An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.... |
| CVE-2018-20501 | MEDIUM | 6.3 | 0.6% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo... |
| CVE-2018-20498 | MEDIUM | 4.3 | 0.7% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo... |
| CVE-2018-20497 | MEDIUM | 5 | 0.7% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo... |
| CVE-2018-20496 | MEDIUM | 5.4 | 0.6% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 1... |
| CVE-2018-20495 | MEDIUM | 5.3 | 0.9% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.... |
| CVE-2018-20493 | MEDIUM | 4.3 | 0.7% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo... |
| CVE-2018-20491 | MEDIUM | 5.4 | 0.6% | Dec 30, 2019 | An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x ... |
| CVE-2018-20490 | MEDIUM | 5.4 | 0.6% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 1... |
| CVE-2018-20489 | MEDIUM | 5.3 | 0.8% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo... |
| CVE-2018-20488 | MEDIUM | 4.3 | 0.8% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo... |
| CVE-2018-7859 | MEDIUM | 6.1 | 1.5% | Dec 30, 2019 | A security vulnerability in D-Link DGS-1510-series switches with firmware 1.20.011, 1.30.007, 1.31.B003 and older that m... |
| CVE-2018-1682 | MEDIUM | 5.3 | 1.1% | Dec 30, 2019 | IBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in furthe... |
| CVE-2018-20492 | MEDIUM | 5.3 | 0.9% | Dec 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo... |
| CVE-2018-18288 | MEDIUM | 6.1 | 0.6% | Dec 26, 2019 | CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection. |
| CVE-2018-11751 | MEDIUM | 5.4 | 0.6% | Dec 16, 2019 | Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue ... |
| CVE-2018-11805 | MEDIUM | 6.7 | 0.9% | Dec 12, 2019 | In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or e... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now