2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-16869MEDIUM5.7A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of ...
CVE-2018-16868MEDIUM5.6A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA d...
CVE-2018-19787MEDIUM6.1An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascrip...
CVE-2018-1928MEDIUM6.7IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileg...
CVE-2018-1927MEDIUM6.5IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2018-14637MEDIUM6.1The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertion...
CVE-2018-19497MEDIUM6.5In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is...
CVE-2018-16859MEDIUM4.2Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can a...
CVE-2018-14626MEDIUM5.3PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerab...
CVE-2018-10851MEDIUM5.3PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excludi...
CVE-2018-1762MEDIUM5.4IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scr...
CVE-2018-12123MEDIUM4.3Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascrip...
CVE-2018-1584MEDIUM5.4IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2018-16852MEDIUM6.5Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of...
CVE-2018-16851MEDIUM6.5Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the proce...
CVE-2018-16841MEDIUM6.5Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configu...
CVE-2018-14629MEDIUM6.5A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAM...
CVE-2018-0719MEDIUM5.5Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. ...
CVE-2018-14663MEDIUM5.9An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing d...
CVE-2018-16862MEDIUM5.3A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final fil...
CVE-2018-14646MEDIUM5.5The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capabl...
CVE-2018-16854MEDIUM6.5A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form ...
CVE-2018-19535MEDIUM6.5In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (applica...
CVE-2018-19464MEDIUM4.8Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and template\default\common\footer.htm mishand...
CVE-2018-1843MEDIUM4.1The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now