2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16988 | CRITICAL | 9.8 | 1.6% | May 2, 2019 | An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak pa... |
| CVE-2018-16961 | — | — | 2.5% | May 2, 2019 | An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal via the f... |
| CVE-2018-16960 | — | — | 0.8% | May 2, 2019 | An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal... |
| CVE-2018-16718 | — | — | 0.8% | May 2, 2019 | An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted ... |
| CVE-2018-16717 | — | — | 1.6% | May 2, 2019 | A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox. |
| CVE-2018-16716 | — | — | 8.6% | May 2, 2019 | A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, whic... |
| CVE-2018-10383 | — | — | 1.9% | May 2, 2019 | Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page. |
| CVE-2018-12404 | — | — | 44.4% | May 2, 2019 | A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content.... |
| CVE-2018-2015 | MEDIUM | 6.4 | 1.6% | May 2, 2019 | IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By pers... |
| CVE-2018-8035 | — | — | 4.9% | May 1, 2019 | This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache ... |
| CVE-2018-17606 | — | — | — | May 1, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-16620. Reason: This candidate is a reservation d... |
| CVE-2018-1933 | MEDIUM | 5.4 | 1.0% | May 1, 2019 | IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2018-1608 | MEDIUM | 5.9 | 1.3% | May 1, 2019 | IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected cryptographic algorithms that cou... |
| CVE-2018-20835 | — | — | 2.1% | Apr 30, 2019 | A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball co... |
| CVE-2018-20834 | — | — | 3.1% | Apr 30, 2019 | A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue ... |
| CVE-2018-15208 | — | — | 1.1% | Apr 30, 2019 | BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter. |
| CVE-2018-15207 | — | — | 1.4% | Apr 30, 2019 | BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a norm... |
| CVE-2018-15206 | — | — | 0.6% | Apr 30, 2019 | BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf. |
| CVE-2018-14931 | — | — | 2.4% | Apr 30, 2019 | An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exis... |
| CVE-2018-14930 | — | — | 0.6% | Apr 30, 2019 | An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebA... |
| CVE-2018-14875 | — | — | 0.7% | Apr 30, 2019 | An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists ... |
| CVE-2018-14874 | — | — | 1.4% | Apr 30, 2019 | An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code pa... |
| CVE-2018-20510 | — | — | 0.4% | Apr 30, 2019 | The print_binder_transaction_ilocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users... |
| CVE-2018-20509 | — | — | 0.4% | Apr 30, 2019 | The print_binder_ref_olocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obta... |
| CVE-2018-19374 | — | — | 1.1% | Apr 30, 2019 | Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Troj... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now