2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-4004MEDIUM5.5An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectServic...
CVE-2018-1925MEDIUM5.9IBM WebShere MQ 9.1.0.0, 9.1.0.1, 9.1.1 uses weaker than expected cryptographic algorithms that could allow an attacker ...
CVE-2018-1994MEDIUM6.3IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-c...
CVE-2018-1903MEDIUM6.7IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, and 6.0.0 could allow a user with restricted sudo access on a system ...
CVE-2018-15635MEDIUM5.9Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and e...
CVE-2018-15631MEDIUM6.5Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allo...
CVE-2018-2000MEDIUM4.3IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an ...
CVE-2018-1999MEDIUM4.3IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the s...
CVE-2018-1997MEDIUM4.3IBM Business Automation Workflow and Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 are vulnerable to a denia...
CVE-2018-1943MEDIUM5.4IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. B...
CVE-2018-1885MEDIUM5.3IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sens...
CVE-2018-1882MEDIUM4.7In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain tex...
CVE-2018-1853MEDIUM6.1IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking actio...
CVE-2018-1787MEDIUM5.1IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. I...
CVE-2018-1913MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This ...
CVE-2018-1731MEDIUM4.8IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This ...
CVE-2018-4053MEDIUM5.5An exploitable local denial-of-service vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version...
CVE-2018-4052MEDIUM5.5An exploitable local information leak vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version ...
CVE-2018-4051MEDIUM5.5An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, vers...
CVE-2018-1906MEDIUM4.3IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download code using a special...
CVE-2018-1874MEDIUM4.6IBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker with physical access t...
CVE-2018-1680MEDIUM5.9IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong password...
CVE-2018-1625MEDIUM4.3IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 generates an error message that includes sensitive info...
CVE-2018-1623MEDIUM4IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read...
CVE-2018-1622MEDIUM4.3IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now