2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-15755MEDIUM6.6Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL...
CVE-2018-14664MEDIUM5.4A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly ...
CVE-2018-1770MEDIUM6.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys...
CVE-2018-1534MEDIUM5.4IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to...
CVE-2018-1533MEDIUM5.4IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to...
CVE-2018-1838MEDIUM5.3IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information ...
CVE-2018-1673MEDIUM6.1IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2018-1724MEDIUM5.9IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time d...
CVE-2018-1708MEDIUM6.5IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as p...
CVE-2018-1706MEDIUM5.4IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2018-17784MEDIUM6.1Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthentic...
CVE-2018-16758MEDIUM5.9Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle at...
CVE-2018-16737MEDIUM5.3tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.
CVE-2018-12541MEDIUM6.5In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http reques...
CVE-2018-12193MEDIUM5.5Insufficient access control in driver stack for Intel QuickAssist Technology for Linux before version 4.2 may allow an u...
CVE-2018-0063MEDIUM6.5A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP requests, sent to the mana...
CVE-2018-0062MEDIUM5.3A Denial of Service vulnerability in J-Web service may allow a remote unauthenticated user to cause Denial of Service wh...
CVE-2018-0061MEDIUM5.3A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high C...
CVE-2018-0060MEDIUM5.3An improper input validation weakness in the device control daemon process (dcd) of Juniper Networks Junos OS allows an ...
CVE-2018-0059MEDIUM5.4A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authentic...
CVE-2018-0058MEDIUM5.9Receipt of a specially crafted IPv6 exception packet may be able to trigger a kernel crash (vmcore), causing the device ...
CVE-2018-0057MEDIUM6.1On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP ...
CVE-2018-0056MEDIUM6.5If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC address learning funct...
CVE-2018-0055MEDIUM6.5Receipt of a specially crafted DHCPv6 message destined to a Junos OS device configured as a DHCP server in a Broadband E...
CVE-2018-0054MEDIUM6.5On QFX5000 Series and EX4600 switches, a high rate of Ethernet pause frames or an ARP packet storm received on the manag...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now