2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-8654MEDIUM6.5An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation o...
CVE-2018-16271MEDIUM6.5The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged ...
CVE-2018-16268MEDIUM4.3The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actio...
CVE-2018-16265MEDIUM6.5The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the ...
CVE-2018-16264MEDIUM6.5The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive inf...
CVE-2018-17981MEDIUM6.1Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.
CVE-2018-1002104MEDIUM5.3Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metr...
CVE-2018-14476MEDIUM6.1GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.
CVE-2018-20507MEDIUM5.3An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11....
CVE-2018-20501MEDIUM6.3An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo...
CVE-2018-20498MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo...
CVE-2018-20497MEDIUM5An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo...
CVE-2018-20496MEDIUM5.4An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 1...
CVE-2018-20495MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5....
CVE-2018-20493MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo...
CVE-2018-20491MEDIUM5.4An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x ...
CVE-2018-20490MEDIUM5.4An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 1...
CVE-2018-20489MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo...
CVE-2018-20488MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo...
CVE-2018-7859MEDIUM6.1A security vulnerability in D-Link DGS-1510-series switches with firmware 1.20.011, 1.30.007, 1.31.B003 and older that m...
CVE-2018-1682MEDIUM5.3IBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in furthe...
CVE-2018-20492MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo...
CVE-2018-18288MEDIUM6.1CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
CVE-2018-11751MEDIUM5.4Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue ...
CVE-2018-11805MEDIUM6.7In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or e...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now