2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12941 | — | — | 3.6% | Jul 31, 2018 | This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.... |
| CVE-2018-12940 | — | — | 2.5% | Jul 31, 2018 | Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 ... |
| CVE-2018-12939 | — | — | 2.0% | Jul 31, 2018 | A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to writ... |
| CVE-2018-11338 | — | — | 0.9% | Jul 31, 2018 | Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB,... |
| CVE-2018-8027 | — | — | 5.5% | Jul 31, 2018 | Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor. |
| CVE-2018-8020 | — | — | 4.2% | Jul 31, 2018 | Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced resp... |
| CVE-2018-8019 | — | — | 4.1% | Jul 31, 2018 | When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid ... |
| CVE-2018-1718 | MEDIUM | 5.4 | 1.2% | Jul 31, 2018 | IBM Sterling B2B Integrator Standard Edition 5.2.0.1 - 5.2.6.3 is vulnerable to cross-site scripting. This vulnerability... |
| CVE-2018-1638 | MEDIUM | 5.9 | 1.8% | Jul 31, 2018 | IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user... |
| CVE-2018-14767 | — | — | 29.3% | Jul 31, 2018 | In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag c... |
| CVE-2018-3773 | MEDIUM | 6.1 | 0.9% | Jul 30, 2018 | There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <... |
| CVE-2018-3772 | — | — | 2.8% | Jul 30, 2018 | Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary comman... |
| CVE-2018-10898 | HIGH | 8.8 | 0.9% | Jul 30, 2018 | A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director usin... |
| CVE-2018-10847 | MEDIUM | 4.2 | 1.7% | Jul 30, 2018 | prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtua... |
| CVE-2018-9066 | — | — | 2.2% | Jul 30, 2018 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstanc... |
| CVE-2018-9065 | — | — | 0.5% | Jul 30, 2018 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file ... |
| CVE-2018-9064 | — | — | 1.0% | Jul 30, 2018 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call ... |
| CVE-2018-10903 | HIGH | 7.5 | 2.6% | Jul 30, 2018 | A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a m... |
| CVE-2018-10883 | MEDIUM | 4.8 | 0.5% | Jul 30, 2018 | A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_di... |
| CVE-2018-13280 | HIGH | 7.4 | 0.6% | Jul 30, 2018 | Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) ... |
| CVE-2018-14744 | — | — | 1.6% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A use-after-free can occur in _pbcM_sp_query in m... |
| CVE-2018-14743 | — | — | 1.4% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in wiretype_decode in context.c. |
| CVE-2018-14742 | — | — | 1.3% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c ... |
| CVE-2018-14741 | — | — | 1.3% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in pbc_pattern_pack in pattern.c... |
| CVE-2018-14740 | — | — | 1.3% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now