2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9159 | — | — | 4.6% | Mar 31, 2018 | In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or rel... |
| CVE-2018-7566 | — | — | 0.5% | Mar 30, 2018 | The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq... |
| CVE-2018-7203 | — | — | 2.4% | Mar 30, 2018 | Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary... |
| CVE-2018-7171 | — | — | 28.2% | Mar 30, 2018 | Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of a... |
| CVE-2018-5708 | — | — | 6.3% | Mar 30, 2018 | An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticat... |
| CVE-2018-1234 | — | — | 0.5% | Mar 30, 2018 | RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (A... |
| CVE-2018-1233 | — | — | 1.1% | Mar 30, 2018 | RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-si... |
| CVE-2018-1232 | — | — | 2.8% | Mar 30, 2018 | RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-ba... |
| CVE-2018-3822 | CRITICAL | 9.8 | 1.6% | Mar 30, 2018 | X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonic... |
| CVE-2018-3821 | MEDIUM | 6.1 | 0.7% | Mar 30, 2018 | Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud v... |
| CVE-2018-3820 | MEDIUM | 6.1 | 0.7% | Mar 30, 2018 | Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that ... |
| CVE-2018-3819 | — | — | 0.9% | Mar 30, 2018 | The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 h... |
| CVE-2018-3818 | — | — | 0.9% | Mar 30, 2018 | Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter... |
| CVE-2018-3817 | — | — | 1.0% | Mar 30, 2018 | When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log ... |
| CVE-2018-9151 | — | — | 0.3% | Mar 30, 2018 | A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel dri... |
| CVE-2018-9148 | — | — | 3.8% | Mar 30, 2018 | Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it e... |
| CVE-2018-3741 | MEDIUM | 6.1 | 1.2% | Mar 30, 2018 | There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-... |
| CVE-2018-3740 | — | — | 1.5% | Mar 30, 2018 | A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a wh... |
| CVE-2018-3728 | — | — | 4.2% | Mar 30, 2018 | hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulner... |
| CVE-2018-9147 | — | — | 0.8% | Mar 30, 2018 | Cross-site scripting (XSS) vulnerabilities in version 7.5.7 of Gespage software allow remote attackers to inject arbitra... |
| CVE-2018-9134 | — | — | 0.7% | Mar 30, 2018 | file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file ... |
| CVE-2018-1390 | MEDIUM | 5.4 | 1.0% | Mar 30, 2018 | IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is vulnerable to cross-s... |
| CVE-2018-1384 | MEDIUM | 5.4 | 1.1% | Mar 30, 2018 | IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2018-5799 | — | — | 2.0% | Mar 30, 2018 | In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /ap... |
| CVE-2018-9146 | — | — | — | Mar 30, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17724. Reason: This candidate is a reservation... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now