2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3755 | MEDIUM | 6.1 | 0.9% | Jun 1, 2018 | XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed wit... |
| CVE-2018-3743 | MEDIUM | 6.1 | 0.9% | Jun 1, 2018 | Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server. |
| CVE-2018-8922 | MEDIUM | 6.5 | 1.3% | Jun 1, 2018 | Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access n... |
| CVE-2018-8921 | MEDIUM | 6.5 | 0.8% | Jun 1, 2018 | Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive before 1.0.2-10275 allows remote... |
| CVE-2018-1532 | MEDIUM | 4.3 | 1.0% | May 31, 2018 | IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a us... |
| CVE-2018-1496 | MEDIUM | 5.4 | 1.0% | May 31, 2018 | IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability al... |
| CVE-2018-11439 | MEDIUM | 6.5 | 2.8% | May 30, 2018 | The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause informat... |
| CVE-2018-1495 | MEDIUM | 6.5 | 1.6% | May 29, 2018 | IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitr... |
| CVE-2018-1376 | MEDIUM | 6.1 | 0.9% | May 29, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allow... |
| CVE-2018-1375 | MEDIUM | 5.9 | 2.0% | May 29, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentica... |
| CVE-2018-1370 | MEDIUM | 4.2 | 0.6% | May 29, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 specifies permissions for a security-critical resource in a way... |
| CVE-2018-11496 | MEDIUM | 6.5 | 1.3% | May 26, 2018 | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lr... |
| CVE-2018-1467 | MEDIUM | 5.3 | 2.0% | May 25, 2018 | The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. I... |
| CVE-2018-6674 | MEDIUM | 6.8 | 0.2% | May 25, 2018 | Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 pri... |
| CVE-2018-6664 | MEDIUM | 5.8 | 0.7% | May 25, 2018 | Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 1... |
| CVE-2018-1000039 | MEDIUM | 6.3 | 1.8% | May 24, 2018 | In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to exec... |
| CVE-2018-1000037 | MEDIUM | 5.5 | 1.6% | May 24, 2018 | In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial... |
| CVE-2018-1000036 | MEDIUM | 5.5 | 1.0% | May 24, 2018 | In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of serv... |
| CVE-2018-6495 | MEDIUM | 5.4 | 0.7% | May 23, 2018 | Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0,... |
| CVE-2018-1126 | MEDIUM | 4.8 | 2.0% | May 23, 2018 | procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer... |
| CVE-2018-6492 | MEDIUM | 4.7 | 1.6% | May 22, 2018 | Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version... |
| CVE-2018-6494 | MEDIUM | 5.4 | 1.2% | May 22, 2018 | Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40,... |
| CVE-2018-11093 | MEDIUM | 6.1 | 1.0% | May 22, 2018 | Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inj... |
| CVE-2018-3639 | MEDIUM | 5.5 | 60.6% | May 22, 2018 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres... |
| CVE-2018-1108 | MEDIUM | 5.9 | 1.8% | May 21, 2018 | kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now