2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-21012 | MEDIUM | 6.1 | 0.9% | Sep 9, 2019 | The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS. |
| CVE-2018-20977 | MEDIUM | 6.1 | 0.9% | Aug 21, 2019 | The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page. |
| CVE-2018-1636 | MEDIUM | 6.7 | 0.4% | Aug 20, 2019 | Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated use... |
| CVE-2018-1635 | MEDIUM | 6.7 | 0.4% | Aug 20, 2019 | Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated use... |
| CVE-2018-1634 | MEDIUM | 6.7 | 0.4% | Aug 20, 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user ... |
| CVE-2018-1633 | MEDIUM | 6.7 | 0.4% | Aug 20, 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user ... |
| CVE-2018-1632 | MEDIUM | 6.7 | 0.4% | Aug 20, 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user ... |
| CVE-2018-1631 | MEDIUM | 6.7 | 0.4% | Aug 20, 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user ... |
| CVE-2018-1630 | MEDIUM | 6.7 | 0.4% | Aug 20, 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user ... |
| CVE-2018-17790 | MEDIUM | 5.4 | 0.9% | Aug 15, 2019 | Prospecta Master Data Online (MDO) 2.0 has Stored XSS. |
| CVE-2018-20965 | MEDIUM | 6.1 | 1.0% | Aug 12, 2019 | The ultimate-member plugin before 2.0.4 for WordPress has XSS. |
| CVE-2018-20826 | MEDIUM | 4.3 | 0.8% | Aug 9, 2019 | The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter ... |
| CVE-2018-20860 | MEDIUM | 6.5 | 1.3% | Jul 30, 2019 | libopenmpt before 0.3.13 allows a crash with malformed MED files. |
| CVE-2018-20859 | MEDIUM | 6.1 | 1.2% | Jul 30, 2019 | edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem. |
| CVE-2018-2022 | MEDIUM | 5.3 | 1.3% | Jul 17, 2019 | IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount ... |
| CVE-2018-2021 | MEDIUM | 6.1 | 0.9% | Jul 17, 2019 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2018-1921 | MEDIUM | 5.4 | 0.7% | Jul 17, 2019 | IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2018-1968 | MEDIUM | 5.3 | 1.3% | Jul 11, 2019 | IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used t... |
| CVE-2018-19583 | MEDIUM | 6.5 | 1.6% | Jul 10, 2019 | GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access token... |
| CVE-2018-19574 | MEDIUM | 5.4 | 1.0% | Jul 10, 2019 | GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an X... |
| CVE-2018-19573 | MEDIUM | 5.4 | 1.0% | Jul 10, 2019 | GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an ... |
| CVE-2018-19570 | MEDIUM | 5.4 | 1.0% | Jul 10, 2019 | GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnera... |
| CVE-2018-19577 | MEDIUM | 5.3 | 2.1% | Jul 10, 2019 | Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an i... |
| CVE-2018-11563 | MEDIUM | 4.6 | 0.8% | Jul 8, 2019 | An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be... |
| CVE-2018-12715 | MEDIUM | 6.1 | 0.9% | Jul 3, 2019 | DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now