2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1070MEDIUM6.5routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which c...
CVE-2018-5165MEDIUM5.3In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by de...
CVE-2018-8916MEDIUM6.3Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allow...
CVE-2018-0355MEDIUM6.1A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remot...
CVE-2018-0329MEDIUM5.3A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area...
CVE-2018-1514MEDIUM4.3IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could all...
CVE-2018-3738MEDIUM5.5protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
CVE-2018-3735MEDIUM6.1bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
CVE-2018-3726MEDIUM6.1crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of f...
CVE-2018-3721MEDIUM6.5lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaults...
CVE-2018-3718MEDIUM5.3serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is ...
CVE-2018-3717MEDIUM5.4connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of...
CVE-2018-3716MEDIUM5.4simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
CVE-2018-3715MEDIUM6.5glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to ...
CVE-2018-3714MEDIUM6.5node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malici...
CVE-2018-3713MEDIUM6.5angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilenam...
CVE-2018-1268MEDIUM6.8Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101...
CVE-2018-1000195MEDIUM4.3A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionIns...
CVE-2018-1000193MEDIUM4.3A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in...
CVE-2018-1000192MEDIUM4.3A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, List...
CVE-2018-1454MEDIUM5.9IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, ca...
CVE-2018-1432MEDIUM6.1IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerabil...
CVE-2018-8924MEDIUM6.5Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticate...
CVE-2018-8923MEDIUM6.5Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote ...
CVE-2018-1002100MEDIUM4.2In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now