2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-0053MEDIUM6.8An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allo...
CVE-2018-8006MEDIUM6.1An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console...
CVE-2018-12479MEDIUM6.5A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying craft...
CVE-2018-12478MEDIUM4.8A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system...
CVE-2018-12474MEDIUM5.4Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extra...
CVE-2018-18070MEDIUM5.9An issue was discovered in Daimler Mercedes-Benz COMAND 17/13.0 50.12 on Mercedes-Benz C-Class 2018 vehicles. Defining o...
CVE-2018-18064MEDIUM6.5cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ beca...
CVE-2018-17060MEDIUM5.3Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to acce...
CVE-2018-1753MEDIUM4.3IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about ...
CVE-2018-1750MEDIUM4.2IBM Security Key Lifecycle Manager 3.0 specifies permissions for a security-critical resource in a way that allows that ...
CVE-2018-1749MEDIUM4.3IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation which allows attack...
CVE-2018-1743MEDIUM5.3IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 discloses sensitive information to unauthorized users. The informatio...
CVE-2018-1742MEDIUM5.9IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic ...
CVE-2018-1741MEDIUM6.5IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 does not properly limit the number or frequency of interaction which ...
CVE-2018-11082MEDIUM6.6Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute ...
CVE-2018-11797MEDIUM5.5In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long runn...
CVE-2018-15429MEDIUM5.3A vulnerability in the web-based UI of Cisco HyperFlex HX Data Platform Software could allow an unauthenticated, remote ...
CVE-2018-15425MEDIUM4.7A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2018-15424MEDIUM4.7A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2018-15423MEDIUM4.7A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the ...
CVE-2018-15407MEDIUM5.5A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to ...
CVE-2018-15406MEDIUM6.1A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attac...
CVE-2018-15405MEDIUM6.5A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Superviso...
CVE-2018-15399MEDIUM6.8A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat ...
CVE-2018-15398MEDIUM4A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now