2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-13398The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers...
CVE-2018-11787In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available...
CVE-2018-11786In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the runni...
CVE-2018-7991Huawei smartphones Mate10 with versions earlier before ALP-AL00B 8.0.0.110(C00) have a Factory Reset Protection (FRP) by...
CVE-2018-7929Huawei Mate RS smartphones with the versions before NEO-AL00D 8.1.0.167(C786) have a lock-screen bypass vulnerability. A...
CVE-2018-14642MEDIUM5.3An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call th...
CVE-2018-14641MEDIUM6.5A security flaw was found in the ip_frag_reasm() function in net/ipv4/ip_fragment.c in the Linux kernel from 4.19-rc1 to...
CVE-2018-16959An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecur...
CVE-2018-16958An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The ASP.NET_SessionID primary session cookie, whe...
CVE-2018-16957The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded passwor...
CVE-2018-16956The AjaxControl component of Oracle WebCenter Interaction Portal 10.3.3 does not validate the names of pages when proces...
CVE-2018-16955The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). ...
CVE-2018-16954An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to...
CVE-2018-16953The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 i...
CVE-2018-16952The Oracle WebCenter Interaction Portal 10.3.3 does not implement protection against Cross-site Request Forgery in its d...
CVE-2018-14631HIGH8.8moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently fil...
CVE-2018-14630HIGH8.8moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional re...
CVE-2018-14320This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User...
CVE-2018-1223HIGH8.8Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to applic...
CVE-2018-1198Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A m...
CVE-2018-11088Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2....
CVE-2018-11086Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior...
CVE-2018-8041Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
CVE-2018-17143HIGH7.5The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a ...
CVE-2018-17142HIGH7.5The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "pani...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now