2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-2025 | MEDIUM | 4.4 | 0.3% | Nov 25, 2019 | IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directo... |
| CVE-2018-10854 | MEDIUM | 5.4 | 0.6% | Nov 22, 2019 | cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in Clou... |
| CVE-2018-9195 | MEDIUM | 5.9 | 1.8% | Nov 21, 2019 | Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle wit... |
| CVE-2018-21031 | MEDIUM | 6.5 | 2.1% | Nov 18, 2019 | Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server becaus... |
| CVE-2018-13257 | MEDIUM | 6.1 | 1.2% | Nov 18, 2019 | The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spo... |
| CVE-2018-12207 | MEDIUM | 6.5 | 0.9% | Nov 14, 2019 | Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may al... |
| CVE-2018-18819 | MEDIUM | 5.3 | 1.4% | Nov 12, 2019 | A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0... |
| CVE-2018-18674 | MEDIUM | 6.1 | 1.2% | Nov 7, 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail conten... |
| CVE-2018-20853 | MEDIUM | 5.3 | 0.9% | Nov 6, 2019 | An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plug... |
| CVE-2018-21030 | MEDIUM | 5.3 | 1.4% | Oct 31, 2019 | Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, f... |
| CVE-2018-18678 | MEDIUM | 6.1 | 1.1% | Oct 30, 2019 | GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board grou... |
| CVE-2018-10727 | MEDIUM | 6.1 | 1.0% | Oct 29, 2019 | Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component ... |
| CVE-2018-3300 | MEDIUM | 5.4 | 0.8% | Oct 16, 2019 | Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Internal Operations).... |
| CVE-2018-2875 | MEDIUM | 5 | 1.0% | Oct 16, 2019 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, ... |
| CVE-2018-5745 | MEDIUM | 4.9 | 2.3% | Oct 9, 2019 | "managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which ... |
| CVE-2018-18379 | MEDIUM | 6.1 | 1.3% | Oct 7, 2019 | The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has ... |
| CVE-2018-11782 | MEDIUM | 6.5 | 2.4% | Sep 26, 2019 | In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit ... |
| CVE-2018-9090 | MEDIUM | 6.1 | 0.8% | Sep 24, 2019 | CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (a... |
| CVE-2018-17789 | MEDIUM | 6.5 | 0.7% | Sep 20, 2019 | Prospecta Master Data Online (MDO) allows CSRF. |
| CVE-2018-11200 | MEDIUM | 6.1 | 0.8% | Sep 20, 2019 | An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field. |
| CVE-2018-1847 | MEDIUM | 6.5 | 2.1% | Sep 18, 2019 | IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) v2.0.0.0 through 2.0.0.5, v2.1.0.0 through 2.1.0.4, v2.1... |
| CVE-2018-21017 | MEDIUM | 6.5 | 1.2% | Sep 16, 2019 | GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c. |
| CVE-2018-21016 | MEDIUM | 6.5 | 1.4% | Sep 16, 2019 | audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of servi... |
| CVE-2018-21015 | MEDIUM | 6.5 | 1.4% | Sep 16, 2019 | AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL poi... |
| CVE-2018-21014 | MEDIUM | 5.4 | 0.7% | Sep 9, 2019 | The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now