2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1253 | MEDIUM | 6.1 | 1.5% | Jun 21, 2018 | RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulner... |
| CVE-2018-0331 | MEDIUM | 6.5 | 0.6% | Jun 21, 2018 | A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco... |
| CVE-2018-1117 | MEDIUM | 5 | 1.4% | Jun 20, 2018 | ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oV... |
| CVE-2018-11728 | MEDIUM | 5.5 | 1.2% | Jun 19, 2018 | The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-2... |
| CVE-2018-11727 | MEDIUM | 5.5 | 1.2% | Jun 19, 2018 | The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote at... |
| CVE-2018-1073 | MEDIUM | 5.3 | 1.9% | Jun 19, 2018 | The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and inv... |
| CVE-2018-1061 | MEDIUM | 6.5 | 5.0% | Jun 19, 2018 | python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the dif... |
| CVE-2018-1090 | MEDIUM | 5.5 | 1.3% | Jun 18, 2018 | In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable t... |
| CVE-2018-12458 | MEDIUM | 6.5 | 1.5% | Jun 15, 2018 | An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may... |
| CVE-2018-6672 | MEDIUM | 5.7 | 1.2% | Jun 15, 2018 | Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 al... |
| CVE-2018-6671 | MEDIUM | 4.7 | 4.7% | Jun 15, 2018 | Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5... |
| CVE-2018-12438 | MEDIUM | 4.9 | 0.5% | Jun 15, 2018 | The Elliptic Curve Cryptography library (aka sunec or libsunec) allows a memory-cache side-channel attack on ECDSA signa... |
| CVE-2018-12437 | MEDIUM | 4.9 | 0.5% | Jun 15, 2018 | LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden N... |
| CVE-2018-12433 | MEDIUM | 4.9 | 0.3% | Jun 15, 2018 | cryptlib through 3.4.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidd... |
| CVE-2018-11689 | MEDIUM | 6.1 | 1.6% | Jun 14, 2018 | Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi... |
| CVE-2018-10821 | MEDIUM | 4.8 | 1.0% | Jun 14, 2018 | Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated user... |
| CVE-2018-8927 | MEDIUM | 5.4 | 0.9% | Jun 14, 2018 | Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users t... |
| CVE-2018-12355 | MEDIUM | 6.1 | 0.8% | Jun 13, 2018 | Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue... |
| CVE-2018-10850 | MEDIUM | 5.9 | 1.6% | Jun 13, 2018 | 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persisten... |
| CVE-2018-5434 | MEDIUM | 5.8 | 1.2% | Jun 13, 2018 | The TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent, and TIBCO Runtime Agent for z/Linux contains ... |
| CVE-2018-5433 | MEDIUM | 6.5 | 1.4% | Jun 13, 2018 | The TIBCO Administrator server component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Ad... |
| CVE-2018-10470 | MEDIUM | 5.3 | 0.6% | Jun 12, 2018 | Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllAr... |
| CVE-2018-2428 | MEDIUM | 5.3 | 1.8% | Jun 12, 2018 | Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. S... |
| CVE-2018-1103 | MEDIUM | 6.1 | 1.3% | Jun 12, 2018 | Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An att... |
| CVE-2018-1075 | MEDIUM | 5 | 0.4% | Jun 12, 2018 | ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now