2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-12467MEDIUM6Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against project...
CVE-2018-12466MEDIUM4.4openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project ...
CVE-2018-10916MEDIUM5.3It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading...
CVE-2018-1999033MEDIUM6.5An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and ea...
CVE-2018-14289MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader...
CVE-2018-1718MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 5.2.0.1 - 5.2.6.3 is vulnerable to cross-site scripting. This vulnerability...
CVE-2018-1638MEDIUM5.9IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user...
CVE-2018-3773MEDIUM6.1There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <...
CVE-2018-10847MEDIUM4.2prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtua...
CVE-2018-10883MEDIUM4.8A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_di...
CVE-2018-10882MEDIUM4.8A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/trans...
CVE-2018-6686MEDIUM6.6Authentication Bypass vulnerability in TPM autoboot in McAfee Drive Encryption (MDE) 7.1.0 and above allows physically p...
CVE-2018-10881MEDIUM4.2A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_...
CVE-2018-10879MEDIUM4.2A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in ext4_xattr_set_entry ...
CVE-2018-10876MEDIUM5A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_ext_remove_space() fu...
CVE-2018-1288MEDIUM5.4In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may...
CVE-2018-1002208MEDIUM5.5SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a .....
CVE-2018-1002205MEDIUM5.5DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files vi...
CVE-2018-1002204MEDIUM5.5adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files vi...
CVE-2018-1002201MEDIUM5.5zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot d...
CVE-2018-6972MEDIUM6.5VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 b...
CVE-2018-10880MEDIUM5.5Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a cra...
CVE-2018-10906MEDIUM5.3In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is act...
CVE-2018-14335MEDIUM6.5An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read ...
CVE-2018-10912MEDIUM4.9keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with mul...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now