2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-7824MEDIUM4.9An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driv...
CVE-2018-7823MEDIUM5.3A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versio...
CVE-2018-7822MEDIUM5.5An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all r...
CVE-2018-7788MEDIUM6.5A CWE-255 Credentials Management vulnerability exists in Modicon Quantum with firmware versions prior to V2.40. which co...
CVE-2018-20839MEDIUM4.3systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstan...
CVE-2018-1975MEDIUM5.4IBM Rational DOORS Web Access 9.5.1 through 9.5.2.9, and 9.6 through 9.6.1.9 is vulnerable to cross-site scripting. This...
CVE-2018-1990MEDIUM5.3IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration i...
CVE-2018-1790MEDIUM4.3IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forg...
CVE-2018-2008MEDIUM4.3IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 could disclose sensitive information to an authenticated user that coul...
CVE-2018-2001MEDIUM4.3IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which coul...
CVE-2018-13991MEDIUM5.3The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware image...
CVE-2018-2015MEDIUM6.4IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By pers...
CVE-2018-1933MEDIUM5.4IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2018-1608MEDIUM5.9IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected cryptographic algorithms that cou...
CVE-2018-20239MEDIUM5.4Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version...
CVE-2018-2007MEDIUM5.9IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to...
CVE-2018-2004MEDIUM5.4IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2018-1961MEDIUM5.3IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from...
CVE-2018-1720MEDIUM5.9IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker than expected cryptogr...
CVE-2018-20822MEDIUM6.5LibSass 3.5.4 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Complex_Selector::perform i...
CVE-2018-20821MEDIUM6.5The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in ...
CVE-2018-1729MEDIUM5.3IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further ...
CVE-2018-16878MEDIUM5.5A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of un...
CVE-2018-0382MEDIUM5.3A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN ...
CVE-2018-0248MEDIUM6.8A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could al...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now