2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20491MEDIUM5.4An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x ...
CVE-2018-20490MEDIUM5.4An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 1...
CVE-2018-20489MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo...
CVE-2018-20488MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo...
CVE-2018-7859MEDIUM6.1A security vulnerability in D-Link DGS-1510-series switches with firmware 1.20.011, 1.30.007, 1.31.B003 and older that m...
CVE-2018-1682MEDIUM5.3IBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in furthe...
CVE-2018-20492MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo...
CVE-2018-18288MEDIUM6.1CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
CVE-2018-10389CRITICAL9.8Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perfor...
CVE-2018-10388CRITICAL9.8Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perfor...
CVE-2018-10387CRITICAL9.8Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of serv...
CVE-2018-1934HIGH8.8IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to exe...
CVE-2018-1311HIGH8.1The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external ...
CVE-2018-11980HIGH7.8When a fake broadcast/multicast 11w rmf without mmie received, since no proper length check in wma_process_bip, buffer o...
CVE-2018-11751MEDIUM5.4Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue ...
CVE-2018-11805MEDIUM6.7In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or e...
CVE-2018-17185Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2018-7282CRITICAL9.8The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based b...
CVE-2018-1002102LOW2.6Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-cont...
CVE-2018-0730CRITICAL9.8This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix...
CVE-2018-0729CRITICAL9.8This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fi...
CVE-2018-0728HIGH7.5This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerabil...
CVE-2018-20090HIGH8.3An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass pr...
CVE-2018-17860HIGH7.2Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0....
CVE-2018-2025MEDIUM4.4IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directo...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now