2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-6693MEDIUM5.3An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 12467...
CVE-2018-11084MEDIUM6.8Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file at...
CVE-2018-16668MEDIUM5.3An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the l...
CVE-2018-17178MEDIUM5.3An issue was discovered on Neato Botvac Connected 2.2.0 devices. They execute unauthenticated manual drive commands (sen...
CVE-2018-14642MEDIUM5.3An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call th...
CVE-2018-14641MEDIUM6.5A security flaw was found in the ip_frag_reasm() function in net/ipv4/ip_fragment.c in the Linux kernel from 4.19-rc1 to...
CVE-2018-11087MEDIUM5.9Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerabil...
CVE-2018-1791MEDIUM4.9IBM Connections 5.0, 5.5, and 6.0 is vulnerable to an External Service Interaction attack, caused by improper validation...
CVE-2018-1719MEDIUM5.9IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This ...
CVE-2018-1698MEDIUM5.3IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information fr...
CVE-2018-3658MEDIUM5.3Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with ...
CVE-2018-3657MEDIUM6.7Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user...
CVE-2018-3616MEDIUM5.9Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0....
CVE-2018-16605MEDIUM5.4D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.
CVE-2018-1773MEDIUM4.3IBM Datacap Fastdoc Capture 9.1.1, 9.1.3, and 9.1.4 could allow an authenticated user to bypass future authentication me...
CVE-2018-11078MEDIUM4Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authen...
CVE-2018-11070MEDIUM5.9RSA BSAFE Crypto-J versions prior to 6.2.4 and RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel v...
CVE-2018-11069MEDIUM5.9RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during RSA decryption, also known ...
CVE-2018-11068MEDIUM4.6RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physic...
CVE-2018-10937MEDIUM4.6A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker wi...
CVE-2018-2452MEDIUM6.1The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode u...
CVE-2018-1127MEDIUM4.2Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Ses...
CVE-2018-1114MEDIUM6.5It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized whi...
CVE-2018-10935MEDIUM6.5A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with...
CVE-2018-6976MEDIUM5.3The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vu...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now