2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1103MEDIUM6.1Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An att...
CVE-2018-1075MEDIUM5ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engi...
CVE-2018-1070MEDIUM6.5routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which c...
CVE-2018-5165MEDIUM5.3In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by de...
CVE-2018-8916MEDIUM6.3Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allow...
CVE-2018-0355MEDIUM6.1A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remot...
CVE-2018-0329MEDIUM5.3A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area...
CVE-2018-1514MEDIUM4.3IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could all...
CVE-2018-3738MEDIUM5.5protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
CVE-2018-3735MEDIUM6.1bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
CVE-2018-3726MEDIUM6.1crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of f...
CVE-2018-3721MEDIUM6.5lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaults...
CVE-2018-3718MEDIUM5.3serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is ...
CVE-2018-3717MEDIUM5.4connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of...
CVE-2018-3716MEDIUM5.4simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
CVE-2018-3715MEDIUM6.5glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to ...
CVE-2018-3714MEDIUM6.5node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malici...
CVE-2018-3713MEDIUM6.5angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilenam...
CVE-2018-1268MEDIUM6.8Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101...
CVE-2018-1000195MEDIUM4.3A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionIns...
CVE-2018-1000193MEDIUM4.3A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in...
CVE-2018-1000192MEDIUM4.3A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, List...
CVE-2018-1454MEDIUM5.9IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, ca...
CVE-2018-1432MEDIUM6.1IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerabil...
CVE-2018-8924MEDIUM6.5Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticate...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now