2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1284 | — | — | 2.3% | Apr 5, 2018 | In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xp... |
| CVE-2018-1282 | — | — | 5.5% | Apr 5, 2018 | This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the... |
| CVE-2018-1000154 | — | — | 1.6% | Apr 5, 2018 | Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Pag... |
| CVE-2018-1000153 | — | — | 0.7% | Apr 5, 2018 | A cross-site request forgery vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorP... |
| CVE-2018-1000152 | — | — | 0.7% | Apr 5, 2018 | An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorPara... |
| CVE-2018-1000151 | — | — | 0.4% | Apr 5, 2018 | A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS ... |
| CVE-2018-1000150 | — | — | 0.3% | Apr 5, 2018 | An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseP... |
| CVE-2018-1000149 | — | — | 0.7% | Apr 5, 2018 | A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, Ansi... |
| CVE-2018-1000148 | — | — | 1.0% | Apr 5, 2018 | An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in Cop... |
| CVE-2018-1000147 | — | — | 0.9% | Apr 5, 2018 | An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in Perforc... |
| CVE-2018-1000146 | — | — | 1.6% | Apr 5, 2018 | An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attac... |
| CVE-2018-1000145 | — | — | 1.1% | Apr 5, 2018 | An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in Perforc... |
| CVE-2018-1000144 | — | — | 0.9% | Apr 5, 2018 | A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in Cukedoct... |
| CVE-2018-1000143 | — | — | 0.4% | Apr 5, 2018 | An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 a... |
| CVE-2018-1000142 | — | — | 0.4% | Apr 5, 2018 | An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 a... |
| CVE-2018-9307 | — | — | 0.7% | Apr 4, 2018 | dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html. |
| CVE-2018-9306 | — | — | — | Apr 4, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17724. Reason: This candidate is a reservation... |
| CVE-2018-9305 | — | — | 2.0% | Apr 4, 2018 | In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, ... |
| CVE-2018-9304 | — | — | 1.7% | Apr 4, 2018 | In Exiv2 0.26, a divide by zero in BigTiffImage::printIFD in bigtiffimage.cpp could result in denial of service. |
| CVE-2018-9303 | — | — | 1.4% | Apr 4, 2018 | In Exiv2 0.26, an assertion failure in BigTiffImage::readData in bigtiffimage.cpp results in an abort. |
| CVE-2018-1097 | — | — | 1.8% | Apr 4, 2018 | A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts ... |
| CVE-2018-1082 | — | — | 2.1% | Apr 4, 2018 | A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once... |
| CVE-2018-1002150 | — | — | 1.7% | Apr 4, 2018 | Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesyst... |
| CVE-2018-9285 | — | — | 3.6% | Apr 4, 2018 | Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3... |
| CVE-2018-9126 | — | — | 50.2% | Apr 4, 2018 | The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and conseque... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now