2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5521 | — | — | 0.9% | Jun 1, 2018 | On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect a... |
| CVE-2018-5513 | — | — | 1.8% | Jun 1, 2018 | On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handsh... |
| CVE-2018-11651 | — | — | 0.8% | Jun 1, 2018 | Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/... |
| CVE-2018-11650 | — | — | 0.8% | Jun 1, 2018 | Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNot... |
| CVE-2018-11649 | — | — | 0.7% | Jun 1, 2018 | Hue 3.12 has XSS via the /pig/save/ name and script parameters. |
| CVE-2018-8922 | MEDIUM | 6.5 | 1.3% | Jun 1, 2018 | Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access n... |
| CVE-2018-8921 | MEDIUM | 6.5 | 0.8% | Jun 1, 2018 | Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive before 1.0.2-10275 allows remote... |
| CVE-2018-11646 | — | — | 69.0% | Jun 1, 2018 | webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon... |
| CVE-2018-11645 | — | — | 2.6% | Jun 1, 2018 | psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow ... |
| CVE-2018-9186 | — | — | 0.8% | May 31, 2018 | A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF valida... |
| CVE-2018-6552 | — | — | 0.4% | May 31, 2018 | Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as... |
| CVE-2018-1532 | MEDIUM | 4.3 | 1.0% | May 31, 2018 | IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a us... |
| CVE-2018-1496 | MEDIUM | 5.4 | 1.0% | May 31, 2018 | IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability al... |
| CVE-2018-10379 | — | — | 0.9% | May 31, 2018 | An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5... |
| CVE-2018-11633 | — | — | 0.5% | May 31, 2018 | An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can b... |
| CVE-2018-11632 | — | — | 0.5% | May 31, 2018 | An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPres... |
| CVE-2018-11631 | — | — | 1.2% | May 31, 2018 | Rondaful M1 Wristband Smart Band 1 devices allow remote attackers to send an arbitrary number of call or SMS notificatio... |
| CVE-2018-11627 | — | — | 2.2% | May 31, 2018 | Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. |
| CVE-2018-11626 | — | — | 1.4% | May 31, 2018 | SELA (aka SimplE Lossless Audio) v0.1.2-alpha has a stack-based buffer overflow in the core/apev2.c init_apev2_keys func... |
| CVE-2018-11142 | — | — | 0.4% | May 31, 2018 | The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management App... |
| CVE-2018-11141 | — | — | 2.0% | May 31, 2018 | The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE Syste... |
| CVE-2018-11140 | — | — | 1.4% | May 31, 2018 | The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8... |
| CVE-2018-11139 | — | — | 42.9% | May 31, 2018 | The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible ... |
| CVE-2018-11138 | CRITICAL | 9.8 | 91.8% | May 31, 2018 | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by... |
| CVE-2018-11137 | — | — | 6.5% | May 31, 2018 | The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now