2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-10856MEDIUM5.3It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-r...
CVE-2018-10855MEDIUM5.9Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log ...
CVE-2018-1249MEDIUM6.5Dell EMC iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to iDRAC web server for...
CVE-2018-7475MEDIUM6.1Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers t...
CVE-2018-10860MEDIUM5.4perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did n...
CVE-2018-12998MEDIUM6.1A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network ...
CVE-2018-12992MEDIUM4.8An issue was discovered CMS MaeloStore V.1.5.0. There is stored XSS in the Telephone field of the admin interface.
CVE-2018-1553MEDIUM5.3IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information...
CVE-2018-1543MEDIUM5.9IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to pro...
CVE-2018-1507MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2018-12536MEDIUM5.3In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad q...
CVE-2018-5437MEDIUM6.8The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analys...
CVE-2018-5436MEDIUM6.5The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO ...
CVE-2018-11053MEDIUM6.5Dell EMC iDRAC Service Module for all supported Linux and XenServer versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, when starte...
CVE-2018-1614MEDIUM5.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider c...
CVE-2018-1374MEDIUM5.3An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and ...
CVE-2018-1072MEDIUM5ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup w...
CVE-2018-1000547MEDIUM5.3coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in...
CVE-2018-1000519MEDIUM6.5aio-libs aiohttp-session contains a Session Fixation vulnerability in load_session function for RedisStorage (see: https...
CVE-2018-1000205MEDIUM5.5U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result ...
CVE-2018-0612MEDIUM6.1Cross-site scripting vulnerability in 5000 trillion yen converter v1.0.6 allows remote attackers to inject arbitrary web...
CVE-2018-11039MEDIUM5.9Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow w...
CVE-2018-12658MEDIUM6.1Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_...
CVE-2018-1655MEDIUM4IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. ...
CVE-2018-3665MEDIUM5.6System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentia...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now