2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1951MEDIUM5.4IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to ...
CVE-2018-1888MEDIUM5.3An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitra...
CVE-2018-1859MEDIUM4.3IBM API Connect 5.0.0.0 through 5.0.8.4 could allow a user authenticated as an administrator with limited rights to esca...
CVE-2018-1657MEDIUM5.4IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to ...
CVE-2018-3986MEDIUM5.5An exploitable information disclosure vulnerability exists in the "Secret Chats" functionality of the Telegram Android m...
CVE-2018-15780MEDIUM4.3RSA Archer versions prior to 6.5.0.1 contain an improper access control vulnerability. A remote malicious user could pot...
CVE-2018-16885MEDIUM4.7A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with ...
CVE-2018-16876MEDIUM5.3ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on...
CVE-2018-20662MEDIUM6.5In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by...
CVE-2018-20650MEDIUM6.5A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack...
CVE-2018-6341MEDIUM6.1React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names a...
CVE-2018-20623MEDIUM5.5In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archiv...
CVE-2018-20622MEDIUM6.5JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
CVE-2018-6668MEDIUM6.1A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows execution bypass...
CVE-2018-19937MEDIUM6.6A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by ope...
CVE-2018-19918MEDIUM5.4CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.
CVE-2018-19906MEDIUM5.4Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter.
CVE-2018-19905MEDIUM5.4HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter.
CVE-2018-19904MEDIUM6.1Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field.
CVE-2018-18593MEDIUM6.5Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, ve...
CVE-2018-20590MEDIUM4.8Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/users.php user ID.
CVE-2018-20584MEDIUM6.5JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the...
CVE-2018-7366MEDIUM4.3ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the...
CVE-2018-20217MEDIUM5.3A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtai...
CVE-2018-19615MEDIUM6.1Rockwell Automation Allen-Bradley PowerMonitor 1000 all versions. A remote attacker could inject arbitrary code into a t...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now