2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1408MEDIUM5.4IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerabi...
CVE-2018-1407MEDIUM5.4IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerabi...
CVE-2018-10888MEDIUM6.5A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead...
CVE-2018-1548MEDIUM4.3IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an auth...
CVE-2018-13785MEDIUM6.5In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an i...
CVE-2018-13256MEDIUM6.1PHP Scripts Mall Auditor Website 2.0.1 has XSS via the lastname or firstname parameter.
CVE-2018-10892MEDIUM5.3The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi path...
CVE-2018-1676MEDIUM6.1IBM Planning Analytics 2.0.0 through 2.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to emb...
CVE-2018-1621MEDIUM4.4IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a ...
CVE-2018-1556MEDIUM5.4IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2018-1555MEDIUM5.4IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2018-1546MEDIUM5.9IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the fai...
CVE-2018-1494MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This ...
CVE-2018-3769MEDIUM6.1ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter.
CVE-2018-3764MEDIUM4.8In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a s...
CVE-2018-3763MEDIUM4.8In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could l...
CVE-2018-3762MEDIUM4.3Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowi...
CVE-2018-8928MEDIUM6.5Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remo...
CVE-2018-10885MEDIUM6.5In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash ...
CVE-2018-13122MEDIUM6.5onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) s...
CVE-2018-13099MEDIUM5.5An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory a...
CVE-2018-13096MEDIUM5.5An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A denial of service (out-of-bounds memory a...
CVE-2018-8870MEDIUM6.4Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An atta...
CVE-2018-8868MEDIUM6.2Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of t...
CVE-2018-1113MEDIUM4.8setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now