2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16869 | MEDIUM | 5.7 | 1.5% | Dec 3, 2018 | A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of ... |
| CVE-2018-16868 | MEDIUM | 5.6 | 0.6% | Dec 3, 2018 | A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA d... |
| CVE-2018-19787 | MEDIUM | 6.1 | 2.4% | Dec 2, 2018 | An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascrip... |
| CVE-2018-1928 | MEDIUM | 6.7 | 0.3% | Nov 30, 2018 | IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileg... |
| CVE-2018-1927 | MEDIUM | 6.5 | 0.7% | Nov 30, 2018 | IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau... |
| CVE-2018-14637 | MEDIUM | 6.1 | 0.8% | Nov 30, 2018 | The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertion... |
| CVE-2018-19497 | MEDIUM | 6.5 | 1.5% | Nov 29, 2018 | In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is... |
| CVE-2018-16859 | MEDIUM | 4.2 | 0.5% | Nov 29, 2018 | Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can a... |
| CVE-2018-14626 | MEDIUM | 5.3 | 2.7% | Nov 29, 2018 | PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerab... |
| CVE-2018-10851 | MEDIUM | 5.3 | 6.0% | Nov 29, 2018 | PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excludi... |
| CVE-2018-1762 | MEDIUM | 5.4 | 1.0% | Nov 29, 2018 | IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scr... |
| CVE-2018-12123 | MEDIUM | 4.3 | 4.0% | Nov 28, 2018 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascrip... |
| CVE-2018-1584 | MEDIUM | 5.4 | 1.0% | Nov 28, 2018 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2018-16852 | MEDIUM | 6.5 | 2.2% | Nov 28, 2018 | Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of... |
| CVE-2018-16851 | MEDIUM | 6.5 | 3.3% | Nov 28, 2018 | Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the proce... |
| CVE-2018-16841 | MEDIUM | 6.5 | 4.6% | Nov 28, 2018 | Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configu... |
| CVE-2018-14629 | MEDIUM | 6.5 | 5.2% | Nov 28, 2018 | A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAM... |
| CVE-2018-0719 | MEDIUM | 5.5 | 0.8% | Nov 27, 2018 | Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. ... |
| CVE-2018-14663 | MEDIUM | 5.9 | 2.5% | Nov 26, 2018 | An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing d... |
| CVE-2018-16862 | MEDIUM | 5.3 | 0.5% | Nov 26, 2018 | A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final fil... |
| CVE-2018-14646 | MEDIUM | 5.5 | 0.4% | Nov 26, 2018 | The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capabl... |
| CVE-2018-16854 | MEDIUM | 6.5 | 2.3% | Nov 26, 2018 | A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form ... |
| CVE-2018-19535 | MEDIUM | 6.5 | 2.1% | Nov 26, 2018 | In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (applica... |
| CVE-2018-19464 | MEDIUM | 4.8 | 0.5% | Nov 22, 2018 | Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and template\default\common\footer.htm mishand... |
| CVE-2018-1843 | MEDIUM | 4.1 | 0.3% | Nov 21, 2018 | The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now