2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20491 | MEDIUM | 5.4 | 0.6% | Dec 30, 2019 | An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x ... |
| CVE-2018-20490 | MEDIUM | 5.4 | 0.6% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 1... |
| CVE-2018-20489 | MEDIUM | 5.3 | 0.8% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo... |
| CVE-2018-20488 | MEDIUM | 4.3 | 0.8% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo... |
| CVE-2018-7859 | MEDIUM | 6.1 | 1.5% | Dec 30, 2019 | A security vulnerability in D-Link DGS-1510-series switches with firmware 1.20.011, 1.30.007, 1.31.B003 and older that m... |
| CVE-2018-1682 | MEDIUM | 5.3 | 1.1% | Dec 30, 2019 | IBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in furthe... |
| CVE-2018-20492 | MEDIUM | 5.3 | 0.9% | Dec 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo... |
| CVE-2018-18288 | MEDIUM | 6.1 | 0.6% | Dec 26, 2019 | CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection. |
| CVE-2018-10389 | CRITICAL | 9.8 | 2.3% | Dec 23, 2019 | Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perfor... |
| CVE-2018-10388 | CRITICAL | 9.8 | 4.4% | Dec 23, 2019 | Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perfor... |
| CVE-2018-10387 | CRITICAL | 9.8 | 2.9% | Dec 23, 2019 | Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of serv... |
| CVE-2018-1934 | HIGH | 8.8 | 0.4% | Dec 20, 2019 | IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to exe... |
| CVE-2018-1311 | HIGH | 8.1 | 9.5% | Dec 18, 2019 | The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external ... |
| CVE-2018-11980 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | When a fake broadcast/multicast 11w rmf without mmie received, since no proper length check in wma_process_bip, buffer o... |
| CVE-2018-11751 | MEDIUM | 5.4 | 0.6% | Dec 16, 2019 | Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue ... |
| CVE-2018-11805 | MEDIUM | 6.7 | 0.9% | Dec 12, 2019 | In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or e... |
| CVE-2018-17185 | — | — | — | Dec 9, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-7282 | CRITICAL | 9.8 | 10.1% | Dec 6, 2019 | The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based b... |
| CVE-2018-1002102 | LOW | 2.6 | 0.6% | Dec 5, 2019 | Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-cont... |
| CVE-2018-0730 | CRITICAL | 9.8 | 2.0% | Dec 4, 2019 | This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix... |
| CVE-2018-0729 | CRITICAL | 9.8 | 2.3% | Dec 4, 2019 | This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fi... |
| CVE-2018-0728 | HIGH | 7.5 | 1.3% | Dec 4, 2019 | This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerabil... |
| CVE-2018-20090 | HIGH | 8.3 | 0.8% | Nov 26, 2019 | An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass pr... |
| CVE-2018-17860 | HIGH | 7.2 | 1.0% | Nov 26, 2019 | Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.... |
| CVE-2018-2025 | MEDIUM | 4.4 | 0.3% | Nov 25, 2019 | IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directo... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now