2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1999MEDIUM4.3IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the s...
CVE-2018-1997MEDIUM4.3IBM Business Automation Workflow and Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 are vulnerable to a denia...
CVE-2018-1943MEDIUM5.4IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. B...
CVE-2018-19006——OSIsoft PI Vision, versions PI Vision 2017, and PI Vision 2017 R2, The application contains a cross-site scripting vulne...
CVE-2018-1885MEDIUM5.3IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sens...
CVE-2018-1882MEDIUM4.7In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain tex...
CVE-2018-1853MEDIUM6.1IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking actio...
CVE-2018-1787MEDIUM5.1IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. I...
CVE-2018-20816——An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 ...
CVE-2018-19282——Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by cra...
CVE-2018-18068——The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 co...
CVE-2018-20229——GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory...
CVE-2018-20449——The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain s...
CVE-2018-20222——XXE issue in Airsonic before 10.1.2 during parse.
CVE-2018-10244——Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code...
CVE-2018-10243——htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer ov...
CVE-2018-19981——Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retr...
CVE-2018-13918——kernel could return a received message length higher than expected, which leads to buffer overflow in a subsequent opera...
CVE-2018-11971——Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asse...
CVE-2018-11970——TZ App dynamic allocations not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Ele...
CVE-2018-11966——Undefined behavior in UE while processing unknown IEI in OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon ...
CVE-2018-11958——Insufficient protection of keys in keypad can lead HLOS to gain access to confidential keypad input data in Snapdragon A...
CVE-2018-11830——Improper input validation in QCPE create function may lead to integer overflow in Snapdragon Auto, Snapdragon Consumer E...
CVE-2018-10242——Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing c...
CVE-2018-4470——A privacy issue in the handling of Open Directory records was addressed with improved indexing. This issue affected vers...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now