2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000190 | — | — | 1.0% | Jun 5, 2018 | A exposure of sensitive information vulnerability exists in Jenkins Black Duck Hub Plugin 4.0.0 and older in PostBuildSc... |
| CVE-2018-1000189 | — | — | 2.0% | Jun 5, 2018 | A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allo... |
| CVE-2018-1000188 | — | — | 0.6% | Jun 5, 2018 | A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that a... |
| CVE-2018-1000187 | — | — | 1.3% | Jun 5, 2018 | A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDe... |
| CVE-2018-1000186 | — | — | 1.0% | Jun 5, 2018 | A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older ... |
| CVE-2018-1000185 | — | — | 0.6% | Jun 5, 2018 | A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.ja... |
| CVE-2018-1000184 | — | — | 0.6% | Jun 5, 2018 | A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java ... |
| CVE-2018-1000183 | — | — | 1.0% | Jun 5, 2018 | A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig... |
| CVE-2018-1000182 | — | — | 0.8% | Jun 5, 2018 | A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRep... |
| CVE-2018-8008 | — | — | 2.4% | Jun 5, 2018 | Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write ... |
| CVE-2018-1332 | — | — | 1.5% | Jun 5, 2018 | Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that cou... |
| CVE-2018-7943 | — | — | 1.2% | Jun 5, 2018 | There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass ... |
| CVE-2018-1454 | MEDIUM | 5.9 | 1.5% | Jun 5, 2018 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, ca... |
| CVE-2018-1432 | MEDIUM | 6.1 | 0.7% | Jun 5, 2018 | IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerabil... |
| CVE-2018-10966 | — | — | 1.6% | Jun 5, 2018 | An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.j... |
| CVE-2018-10813 | — | — | 1.1% | Jun 5, 2018 | In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visib... |
| CVE-2018-8924 | MEDIUM | 6.5 | 0.8% | Jun 5, 2018 | Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticate... |
| CVE-2018-8923 | MEDIUM | 6.5 | 0.8% | Jun 5, 2018 | Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote ... |
| CVE-2018-6662 | HIGH | 7.8 | 0.2% | Jun 5, 2018 | Privilege Escalation vulnerability in McAfee Management of Native Encryption (MNE) before 4.1.4 allows local users to ga... |
| CVE-2018-11743 | CRITICAL | 9.8 | 2.2% | Jun 5, 2018 | The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attack... |
| CVE-2018-1000200 | — | — | 0.5% | Jun 5, 2018 | The Linux Kernel versions 4.14, 4.15, and 4.16 has a null pointer dereference which can result in an out of memory (OOM)... |
| CVE-2018-1000181 | — | — | 1.5% | Jun 5, 2018 | Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a cra... |
| CVE-2018-1000180 | — | — | 3.6% | Jun 5, 2018 | Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key p... |
| CVE-2018-1252 | — | — | 2.0% | Jun 5, 2018 | RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensi... |
| CVE-2018-11722 | — | — | 1.5% | Jun 5, 2018 | WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now