2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0053 | MEDIUM | 6.8 | 0.5% | Oct 10, 2018 | An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allo... |
| CVE-2018-8006 | MEDIUM | 6.1 | 56.2% | Oct 10, 2018 | An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console... |
| CVE-2018-12479 | MEDIUM | 6.5 | 1.7% | Oct 9, 2018 | A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying craft... |
| CVE-2018-12478 | MEDIUM | 4.8 | 1.5% | Oct 9, 2018 | A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system... |
| CVE-2018-12474 | MEDIUM | 5.4 | 1.4% | Oct 9, 2018 | Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extra... |
| CVE-2018-18070 | MEDIUM | 5.9 | 1.1% | Oct 9, 2018 | An issue was discovered in Daimler Mercedes-Benz COMAND 17/13.0 50.12 on Mercedes-Benz C-Class 2018 vehicles. Defining o... |
| CVE-2018-18064 | MEDIUM | 6.5 | 1.5% | Oct 8, 2018 | cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ beca... |
| CVE-2018-17060 | MEDIUM | 5.3 | 1.0% | Oct 8, 2018 | Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to acce... |
| CVE-2018-1753 | MEDIUM | 4.3 | 1.0% | Oct 8, 2018 | IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about ... |
| CVE-2018-1750 | MEDIUM | 4.2 | 0.7% | Oct 8, 2018 | IBM Security Key Lifecycle Manager 3.0 specifies permissions for a security-critical resource in a way that allows that ... |
| CVE-2018-1749 | MEDIUM | 4.3 | 0.9% | Oct 8, 2018 | IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation which allows attack... |
| CVE-2018-1743 | MEDIUM | 5.3 | 1.3% | Oct 8, 2018 | IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 discloses sensitive information to unauthorized users. The informatio... |
| CVE-2018-1742 | MEDIUM | 5.9 | 0.3% | Oct 8, 2018 | IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic ... |
| CVE-2018-1741 | MEDIUM | 6.5 | 1.3% | Oct 8, 2018 | IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 does not properly limit the number or frequency of interaction which ... |
| CVE-2018-11082 | MEDIUM | 6.6 | 1.1% | Oct 5, 2018 | Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute ... |
| CVE-2018-11797 | MEDIUM | 5.5 | 4.0% | Oct 5, 2018 | In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long runn... |
| CVE-2018-15429 | MEDIUM | 5.3 | 1.1% | Oct 5, 2018 | A vulnerability in the web-based UI of Cisco HyperFlex HX Data Platform Software could allow an unauthenticated, remote ... |
| CVE-2018-15425 | MEDIUM | 4.7 | 1.6% | Oct 5, 2018 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2018-15424 | MEDIUM | 4.7 | 1.4% | Oct 5, 2018 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2018-15423 | MEDIUM | 4.7 | 0.9% | Oct 5, 2018 | A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the ... |
| CVE-2018-15407 | MEDIUM | 5.5 | 0.3% | Oct 5, 2018 | A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to ... |
| CVE-2018-15406 | MEDIUM | 6.1 | 1.2% | Oct 5, 2018 | A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attac... |
| CVE-2018-15405 | MEDIUM | 6.5 | 1.8% | Oct 5, 2018 | A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Superviso... |
| CVE-2018-15399 | MEDIUM | 6.8 | 1.8% | Oct 5, 2018 | A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat ... |
| CVE-2018-15398 | MEDIUM | 4 | 1.9% | Oct 5, 2018 | A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now