2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6345 | CRITICAL | 9.8 | 1.7% | Jan 15, 2019 | The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively ... |
| CVE-2018-14662 | MEDIUM | 5.7 | 0.4% | Jan 15, 2019 | It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt e... |
| CVE-2018-15463 | MEDIUM | 6.1 | 1.2% | Jan 15, 2019 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic... |
| CVE-2018-1772 | — | — | 1.0% | Jan 15, 2019 | IBM SPSS Analytic Server 3.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2018-15440 | MEDIUM | 6.1 | 1.3% | Jan 15, 2019 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic... |
| CVE-2018-16846 | MEDIUM | 6.5 | 2.1% | Jan 15, 2019 | It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAP... |
| CVE-2018-20719 | — | — | 1.0% | Jan 15, 2019 | In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history p... |
| CVE-2018-20718 | — | — | 3.7% | Jan 15, 2019 | In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:... |
| CVE-2018-20717 | — | — | 2.7% | Jan 15, 2019 | In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a ... |
| CVE-2018-20716 | — | — | 1.2% | Jan 15, 2019 | CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature. |
| CVE-2018-20715 | — | — | 1.1% | Jan 15, 2019 | The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the... |
| CVE-2018-20714 | — | — | 1.8% | Jan 15, 2019 | The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vuln... |
| CVE-2018-20713 | — | — | 1.1% | Jan 15, 2019 | Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404. |
| CVE-2018-20712 | — | — | 2.7% | Jan 15, 2019 | A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in... |
| CVE-2018-16888 | MEDIUM | 4.7 | 0.3% | Jan 14, 2019 | It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When ... |
| CVE-2018-16886 | HIGH | 8.1 | 4.0% | Jan 14, 2019 | etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-b... |
| CVE-2018-1969 | CRITICAL | 9 | 1.7% | Jan 14, 2019 | IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be autom... |
| CVE-2018-1967 | MEDIUM | 6.1 | 1.3% | Jan 14, 2019 | IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2018-1956 | MEDIUM | 5.9 | 2.0% | Jan 14, 2019 | IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it ... |
| CVE-2018-20703 | — | — | 0.6% | Jan 13, 2019 | CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string. |
| CVE-2018-16887 | MEDIUM | 5.4 | 1.0% | Jan 13, 2019 | A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/... |
| CVE-2018-16206 | — | — | 1.0% | Jan 13, 2019 | Cross-site scripting vulnerability in WordPress plugin spam-byebye 2.2.1 and earlier allows remote attackers to inject a... |
| CVE-2018-20699 | — | — | 2.2% | Jan 12, 2019 | Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large intege... |
| CVE-2018-16865 | HIGH | 7.8 | 3.0% | Jan 11, 2019 | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discover... |
| CVE-2018-16864 | HIGH | 7.8 | 0.7% | Jan 11, 2019 | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discover... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now