2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1070 | MEDIUM | 6.5 | 0.8% | Jun 12, 2018 | routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which c... |
| CVE-2018-5165 | MEDIUM | 5.3 | 1.7% | Jun 11, 2018 | In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by de... |
| CVE-2018-8916 | MEDIUM | 6.3 | 1.0% | Jun 8, 2018 | Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allow... |
| CVE-2018-0355 | MEDIUM | 6.1 | 1.8% | Jun 7, 2018 | A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remot... |
| CVE-2018-0329 | MEDIUM | 5.3 | 2.4% | Jun 7, 2018 | A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area... |
| CVE-2018-1514 | MEDIUM | 4.3 | 0.5% | Jun 7, 2018 | IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could all... |
| CVE-2018-3738 | MEDIUM | 5.5 | 1.0% | Jun 7, 2018 | protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files. |
| CVE-2018-3735 | MEDIUM | 6.1 | 0.8% | Jun 7, 2018 | bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template |
| CVE-2018-3726 | MEDIUM | 6.1 | 1.0% | Jun 7, 2018 | crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of f... |
| CVE-2018-3721 | MEDIUM | 6.5 | 2.4% | Jun 7, 2018 | lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaults... |
| CVE-2018-3718 | MEDIUM | 5.3 | 1.3% | Jun 7, 2018 | serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is ... |
| CVE-2018-3717 | MEDIUM | 5.4 | 1.3% | Jun 7, 2018 | connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of... |
| CVE-2018-3716 | MEDIUM | 5.4 | 0.6% | Jun 7, 2018 | simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names. |
| CVE-2018-3715 | MEDIUM | 6.5 | 1.4% | Jun 7, 2018 | glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to ... |
| CVE-2018-3714 | MEDIUM | 6.5 | 8.6% | Jun 7, 2018 | node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malici... |
| CVE-2018-3713 | MEDIUM | 6.5 | 1.5% | Jun 7, 2018 | angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilenam... |
| CVE-2018-1268 | MEDIUM | 6.8 | 1.0% | Jun 6, 2018 | Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101... |
| CVE-2018-1000195 | MEDIUM | 4.3 | 2.1% | Jun 5, 2018 | A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionIns... |
| CVE-2018-1000193 | MEDIUM | 4.3 | 1.0% | Jun 5, 2018 | A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in... |
| CVE-2018-1000192 | MEDIUM | 4.3 | 1.1% | Jun 5, 2018 | A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, List... |
| CVE-2018-1454 | MEDIUM | 5.9 | 1.5% | Jun 5, 2018 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, ca... |
| CVE-2018-1432 | MEDIUM | 6.1 | 0.7% | Jun 5, 2018 | IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerabil... |
| CVE-2018-8924 | MEDIUM | 6.5 | 0.8% | Jun 5, 2018 | Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticate... |
| CVE-2018-8923 | MEDIUM | 6.5 | 0.8% | Jun 5, 2018 | Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote ... |
| CVE-2018-1002100 | MEDIUM | 4.2 | 1.6% | Jun 2, 2018 | In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now