2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1893MEDIUM5.4IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerab...
CVE-2018-1892MEDIUM5.4IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerab...
CVE-2018-1828MEDIUM5.4IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerab...
CVE-2018-1827MEDIUM5.4IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerab...
CVE-2018-1826MEDIUM5.4IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerab...
CVE-2018-1760MEDIUM5.4IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerab...
CVE-2018-1758MEDIUM5.4IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerab...
CVE-2018-1734MEDIUM4.3IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 discloses sensitive information in error messages th...
CVE-2018-20846MEDIUM6.5Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_nex...
CVE-2018-20845MEDIUM6.5Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJP...
CVE-2018-2013MEDIUM5.3IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in...
CVE-2018-2011MEDIUM5.3IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially craft...
CVE-2018-15913MEDIUM6.1An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' ...
CVE-2018-18886MEDIUM6.1Helpy v2.1.0 has Stored XSS via the Ticket title.
CVE-2018-20472MEDIUM5.4An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.
CVE-2018-20523MEDIUM5.3Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider ...
CVE-2018-2028MEDIUM6.5IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which ...
CVE-2018-13380MEDIUM6.1A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and ...
CVE-2018-12130MEDIUM5.9Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative executi...
CVE-2018-12127MEDIUM5.6Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution m...
CVE-2018-12126MEDIUM5.6Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execu...
CVE-2018-13383MEDIUM6.5A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and e...
CVE-2018-20008MEDIUM6.8iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers...
CVE-2018-7851MEDIUM6.5CWE-119: Buffer errors vulnerability exists in Modicon M580 with firmware prior to V2.50, Modicon M340 with firmware pri...
CVE-2018-7850MEDIUM5.3A CWE-807: Reliance on Untrusted Inputs in a Security Decision vulnerability exists in all versions of the Modicon M580,...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now