2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-3755MEDIUM6.1XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed wit...
CVE-2018-3743MEDIUM6.1Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
CVE-2018-8922MEDIUM6.5Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access n...
CVE-2018-8921MEDIUM6.5Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive before 1.0.2-10275 allows remote...
CVE-2018-1532MEDIUM4.3IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a us...
CVE-2018-1496MEDIUM5.4IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2018-11439MEDIUM6.5The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause informat...
CVE-2018-1495MEDIUM6.5IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitr...
CVE-2018-1376MEDIUM6.1IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allow...
CVE-2018-1375MEDIUM5.9IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentica...
CVE-2018-1370MEDIUM4.2IBM Security Guardium Big Data Intelligence (SonarG) 3.1 specifies permissions for a security-critical resource in a way...
CVE-2018-11496MEDIUM6.5In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lr...
CVE-2018-1467MEDIUM5.3The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. I...
CVE-2018-6674MEDIUM6.8Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 pri...
CVE-2018-6664MEDIUM5.8Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 1...
CVE-2018-1000039MEDIUM6.3In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to exec...
CVE-2018-1000037MEDIUM5.5In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial...
CVE-2018-1000036MEDIUM5.5In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of serv...
CVE-2018-6495MEDIUM5.4Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0,...
CVE-2018-1126MEDIUM4.8procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer...
CVE-2018-6492MEDIUM4.7Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version...
CVE-2018-6494MEDIUM5.4Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40,...
CVE-2018-11093MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inj...
CVE-2018-3639MEDIUM5.5Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres...
CVE-2018-1108MEDIUM5.9kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now