2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-8923MEDIUM6.5Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote ...
CVE-2018-1002100MEDIUM4.2In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles...
CVE-2018-3755MEDIUM6.1XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed wit...
CVE-2018-3743MEDIUM6.1Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
CVE-2018-8922MEDIUM6.5Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access n...
CVE-2018-8921MEDIUM6.5Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive before 1.0.2-10275 allows remote...
CVE-2018-1532MEDIUM4.3IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a us...
CVE-2018-1496MEDIUM5.4IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2018-11439MEDIUM6.5The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause informat...
CVE-2018-1495MEDIUM6.5IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitr...
CVE-2018-1376MEDIUM6.1IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allow...
CVE-2018-1375MEDIUM5.9IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentica...
CVE-2018-1370MEDIUM4.2IBM Security Guardium Big Data Intelligence (SonarG) 3.1 specifies permissions for a security-critical resource in a way...
CVE-2018-11496MEDIUM6.5In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lr...
CVE-2018-1467MEDIUM5.3The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. I...
CVE-2018-6674MEDIUM6.8Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 pri...
CVE-2018-6664MEDIUM5.8Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 1...
CVE-2018-1000039MEDIUM6.3In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to exec...
CVE-2018-1000037MEDIUM5.5In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial...
CVE-2018-1000036MEDIUM5.5In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of serv...
CVE-2018-6495MEDIUM5.4Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0,...
CVE-2018-1126MEDIUM4.8procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer...
CVE-2018-6492MEDIUM4.7Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version...
CVE-2018-6494MEDIUM5.4Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40,...
CVE-2018-11093MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inj...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now