2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12467 | MEDIUM | 6 | 0.6% | Aug 1, 2018 | Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against project... |
| CVE-2018-12466 | MEDIUM | 4.4 | 0.8% | Aug 1, 2018 | openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project ... |
| CVE-2018-10916 | MEDIUM | 5.3 | 4.8% | Aug 1, 2018 | It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading... |
| CVE-2018-1999033 | MEDIUM | 6.5 | 0.9% | Aug 1, 2018 | An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and ea... |
| CVE-2018-14289 | MEDIUM | 6.5 | 2.5% | Jul 31, 2018 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader... |
| CVE-2018-1718 | MEDIUM | 5.4 | 1.2% | Jul 31, 2018 | IBM Sterling B2B Integrator Standard Edition 5.2.0.1 - 5.2.6.3 is vulnerable to cross-site scripting. This vulnerability... |
| CVE-2018-1638 | MEDIUM | 5.9 | 1.8% | Jul 31, 2018 | IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user... |
| CVE-2018-3773 | MEDIUM | 6.1 | 0.9% | Jul 30, 2018 | There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <... |
| CVE-2018-10847 | MEDIUM | 4.2 | 1.7% | Jul 30, 2018 | prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtua... |
| CVE-2018-10883 | MEDIUM | 4.8 | 0.5% | Jul 30, 2018 | A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_di... |
| CVE-2018-10882 | MEDIUM | 4.8 | 0.7% | Jul 27, 2018 | A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/trans... |
| CVE-2018-6686 | MEDIUM | 6.6 | 0.2% | Jul 27, 2018 | Authentication Bypass vulnerability in TPM autoboot in McAfee Drive Encryption (MDE) 7.1.0 and above allows physically p... |
| CVE-2018-10881 | MEDIUM | 4.2 | 0.8% | Jul 26, 2018 | A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_... |
| CVE-2018-10879 | MEDIUM | 4.2 | 0.9% | Jul 26, 2018 | A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in ext4_xattr_set_entry ... |
| CVE-2018-10876 | MEDIUM | 5 | 0.8% | Jul 26, 2018 | A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_ext_remove_space() fu... |
| CVE-2018-1288 | MEDIUM | 5.4 | 4.8% | Jul 26, 2018 | In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may... |
| CVE-2018-1002208 | MEDIUM | 5.5 | 8.9% | Jul 25, 2018 | SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ..... |
| CVE-2018-1002205 | MEDIUM | 5.5 | 12.2% | Jul 25, 2018 | DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files vi... |
| CVE-2018-1002204 | MEDIUM | 5.5 | 15.4% | Jul 25, 2018 | adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files vi... |
| CVE-2018-1002201 | MEDIUM | 5.5 | 10.3% | Jul 25, 2018 | zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot d... |
| CVE-2018-6972 | MEDIUM | 6.5 | 3.0% | Jul 25, 2018 | VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 b... |
| CVE-2018-10880 | MEDIUM | 5.5 | 2.9% | Jul 25, 2018 | Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a cra... |
| CVE-2018-10906 | MEDIUM | 5.3 | 1.4% | Jul 24, 2018 | In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is act... |
| CVE-2018-14335 | MEDIUM | 6.5 | 13.4% | Jul 24, 2018 | An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read ... |
| CVE-2018-10912 | MEDIUM | 4.9 | 1.3% | Jul 23, 2018 | keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with mul... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now