2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10856 | MEDIUM | 5.3 | 0.9% | Jul 3, 2018 | It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-r... |
| CVE-2018-10855 | MEDIUM | 5.9 | 3.1% | Jul 3, 2018 | Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log ... |
| CVE-2018-1249 | MEDIUM | 6.5 | 0.9% | Jul 2, 2018 | Dell EMC iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to iDRAC web server for... |
| CVE-2018-7475 | MEDIUM | 6.1 | 1.0% | Jun 30, 2018 | Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers t... |
| CVE-2018-10860 | MEDIUM | 5.4 | 48.7% | Jun 29, 2018 | perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did n... |
| CVE-2018-12998 | MEDIUM | 6.1 | 98.5% | Jun 29, 2018 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network ... |
| CVE-2018-12992 | MEDIUM | 4.8 | 0.5% | Jun 29, 2018 | An issue was discovered CMS MaeloStore V.1.5.0. There is stored XSS in the Telephone field of the admin interface. |
| CVE-2018-1553 | MEDIUM | 5.3 | 2.9% | Jun 27, 2018 | IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information... |
| CVE-2018-1543 | MEDIUM | 5.9 | 1.1% | Jun 27, 2018 | IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to pro... |
| CVE-2018-1507 | MEDIUM | 5.4 | 1.0% | Jun 27, 2018 | IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2018-12536 | MEDIUM | 5.3 | 4.3% | Jun 27, 2018 | In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad q... |
| CVE-2018-5437 | MEDIUM | 6.8 | 0.9% | Jun 27, 2018 | The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analys... |
| CVE-2018-5436 | MEDIUM | 6.5 | 1.0% | Jun 27, 2018 | The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO ... |
| CVE-2018-11053 | MEDIUM | 6.5 | 0.5% | Jun 26, 2018 | Dell EMC iDRAC Service Module for all supported Linux and XenServer versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, when starte... |
| CVE-2018-1614 | MEDIUM | 5.8 | 2.9% | Jun 26, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider c... |
| CVE-2018-1374 | MEDIUM | 5.3 | 1.4% | Jun 26, 2018 | An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and ... |
| CVE-2018-1072 | MEDIUM | 5 | 1.0% | Jun 26, 2018 | ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup w... |
| CVE-2018-1000547 | MEDIUM | 5.3 | 0.8% | Jun 26, 2018 | coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in... |
| CVE-2018-1000519 | MEDIUM | 6.5 | 1.2% | Jun 26, 2018 | aio-libs aiohttp-session contains a Session Fixation vulnerability in load_session function for RedisStorage (see: https... |
| CVE-2018-1000205 | MEDIUM | 5.5 | 0.7% | Jun 26, 2018 | U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result ... |
| CVE-2018-0612 | MEDIUM | 6.1 | 0.8% | Jun 26, 2018 | Cross-site scripting vulnerability in 5000 trillion yen converter v1.0.6 allows remote attackers to inject arbitrary web... |
| CVE-2018-11039 | MEDIUM | 5.9 | 2.8% | Jun 25, 2018 | Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow w... |
| CVE-2018-12658 | MEDIUM | 6.1 | 0.9% | Jun 22, 2018 | Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_... |
| CVE-2018-1655 | MEDIUM | 4 | 0.4% | Jun 22, 2018 | IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. ... |
| CVE-2018-3665 | MEDIUM | 5.6 | 0.6% | Jun 21, 2018 | System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentia... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now