2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7824 | MEDIUM | 4.9 | 0.9% | May 22, 2019 | An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driv... |
| CVE-2018-7823 | MEDIUM | 5.3 | 1.3% | May 22, 2019 | A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versio... |
| CVE-2018-7822 | MEDIUM | 5.5 | 0.3% | May 22, 2019 | An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all r... |
| CVE-2018-7788 | MEDIUM | 6.5 | 1.1% | May 22, 2019 | A CWE-255 Credentials Management vulnerability exists in Modicon Quantum with firmware versions prior to V2.40. which co... |
| CVE-2018-20839 | MEDIUM | 4.3 | 2.5% | May 17, 2019 | systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstan... |
| CVE-2018-1975 | MEDIUM | 5.4 | 0.7% | May 16, 2019 | IBM Rational DOORS Web Access 9.5.1 through 9.5.2.9, and 9.6 through 9.6.1.9 is vulnerable to cross-site scripting. This... |
| CVE-2018-1990 | MEDIUM | 5.3 | 2.3% | May 10, 2019 | IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration i... |
| CVE-2018-1790 | MEDIUM | 4.3 | 0.5% | May 10, 2019 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forg... |
| CVE-2018-2008 | MEDIUM | 4.3 | 1.3% | May 7, 2019 | IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 could disclose sensitive information to an authenticated user that coul... |
| CVE-2018-2001 | MEDIUM | 4.3 | 0.5% | May 7, 2019 | IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which coul... |
| CVE-2018-13991 | MEDIUM | 5.3 | 1.6% | May 7, 2019 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware image... |
| CVE-2018-2015 | MEDIUM | 6.4 | 1.6% | May 2, 2019 | IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By pers... |
| CVE-2018-1933 | MEDIUM | 5.4 | 1.0% | May 1, 2019 | IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2018-1608 | MEDIUM | 5.9 | 1.3% | May 1, 2019 | IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected cryptographic algorithms that cou... |
| CVE-2018-20239 | MEDIUM | 5.4 | 3.4% | Apr 30, 2019 | Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version... |
| CVE-2018-2007 | MEDIUM | 5.9 | 1.0% | Apr 29, 2019 | IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to... |
| CVE-2018-2004 | MEDIUM | 5.4 | 1.0% | Apr 29, 2019 | IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2018-1961 | MEDIUM | 5.3 | 1.3% | Apr 29, 2019 | IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from... |
| CVE-2018-1720 | MEDIUM | 5.9 | 1.0% | Apr 25, 2019 | IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker than expected cryptogr... |
| CVE-2018-20822 | MEDIUM | 6.5 | 2.1% | Apr 23, 2019 | LibSass 3.5.4 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Complex_Selector::perform i... |
| CVE-2018-20821 | MEDIUM | 6.5 | 2.2% | Apr 23, 2019 | The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in ... |
| CVE-2018-1729 | MEDIUM | 5.3 | 1.8% | Apr 19, 2019 | IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further ... |
| CVE-2018-16878 | MEDIUM | 5.5 | 0.4% | Apr 18, 2019 | A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of un... |
| CVE-2018-0382 | MEDIUM | 5.3 | 2.0% | Apr 17, 2019 | A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN ... |
| CVE-2018-0248 | MEDIUM | 6.8 | 2.0% | Apr 17, 2019 | A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could al... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now