2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1751MEDIUM5.9IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could all...
CVE-2018-14666MEDIUM6.8An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configu...
CVE-2018-13374MEDIUM4.3A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 al...
CVE-2018-16042MEDIUM6.5Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 20...
CVE-2018-18812MEDIUM6.5The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO...
CVE-2018-5741MEDIUM6.5To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides...
CVE-2018-5739MEDIUM6.5An extension to hooks capabilities which debuted in Kea 1.4.0 introduced a memory leak for operators who are using certa...
CVE-2018-5738MEDIUM5.3Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, ...
CVE-2018-5737MEDIUM5.9A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb....
CVE-2018-14662MEDIUM5.7It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt e...
CVE-2018-15463MEDIUM6.1A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic...
CVE-2018-15440MEDIUM6.1A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic...
CVE-2018-16846MEDIUM6.5It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAP...
CVE-2018-16888MEDIUM4.7It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When ...
CVE-2018-1967MEDIUM6.1IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2018-1956MEDIUM5.9IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it ...
CVE-2018-16887MEDIUM5.4A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/...
CVE-2018-15467MEDIUM6.1A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an unauth...
CVE-2018-15466MEDIUM5.3A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CP...
CVE-2018-15464MEDIUM5.8A vulnerability in Cisco 900 Series Aggregation Services Router (ASR) software could allow an unauthenticated, remote at...
CVE-2018-15461MEDIUM6.1A vulnerability in the MyWebex component of Cisco Webex Business Suite could allow an unauthenticated, remote attacker t...
CVE-2018-20685MEDIUM5.3In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filenam...
CVE-2018-15458MEDIUM5.3A vulnerability in the Shell Access Filter feature of Cisco Firepower Management Center (FMC), when used in conjunction ...
CVE-2018-15457MEDIUM6.1A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remo...
CVE-2018-15456MEDIUM4.3A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacke...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now