2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-10892MEDIUM5.3The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi path...
CVE-2018-1676MEDIUM6.1IBM Planning Analytics 2.0.0 through 2.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to emb...
CVE-2018-1621MEDIUM4.4IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a ...
CVE-2018-1556MEDIUM5.4IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2018-1555MEDIUM5.4IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2018-1546MEDIUM5.9IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the fai...
CVE-2018-1542HIGH7.1IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform...
CVE-2018-1494MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This ...
CVE-2018-13406HIGH7.8An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux kernel before 4.17.4 c...
CVE-2018-13405HIGH7.8The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an ...
CVE-2018-13110All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerabilit...
CVE-2018-13109All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerabili...
CVE-2018-13108All ADB broadband gateways / routers based on the Epicentro platform are affected by a local root jailbreak vulnerabilit...
CVE-2018-11124Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows...
CVE-2018-8929HIGH7.3Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Cli...
CVE-2018-13348The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at ...
CVE-2018-13347mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.
CVE-2018-13346The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start i...
CVE-2018-13340Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request.
CVE-2018-13339Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an ...
CVE-2018-9998Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4...
CVE-2018-9997Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7...
CVE-2018-8738Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
CVE-2018-8046The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passe...
CVE-2018-13052In CyberArk Endpoint Privilege Manager (formerly Viewfinity), Privilege Escalation is possible if the attacker has one p...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now