2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1771 | HIGH | 8.4 | 0.5% | Dec 20, 2018 | IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in th... |
| CVE-2018-1677 | MEDIUM | 5.1 | 0.4% | Dec 20, 2018 | IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of serv... |
| CVE-2018-1661 | MEDIUM | 6.5 | 0.9% | Dec 20, 2018 | IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attac... |
| CVE-2018-8653 | HIGH | 7.5 | 29.1% | Dec 20, 2018 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ... |
| CVE-2018-6669 | MEDIUM | 6.3 | 0.5% | Dec 20, 2018 | A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or loca... |
| CVE-2018-20307 | MEDIUM | 4.3 | 0.8% | Dec 20, 2018 | Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain ... |
| CVE-2018-20306 | — | — | 0.5% | Dec 20, 2018 | A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traff... |
| CVE-2018-20301 | — | — | 0.9% | Dec 20, 2018 | An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In pa... |
| CVE-2018-20305 | — | — | 4.1% | Dec 20, 2018 | D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass paramete... |
| CVE-2018-20304 | — | — | 0.9% | Dec 20, 2018 | wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via... |
| CVE-2018-20303 | — | — | 3.2% | Dec 20, 2018 | In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an att... |
| CVE-2018-20302 | — | — | 0.9% | Dec 20, 2018 | An XSS issue was discovered in Steve Pallen Xain before 0.6.2 via the order parameter. |
| CVE-2018-20300 | — | — | 1.6% | Dec 20, 2018 | Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm ... |
| CVE-2018-20299 | CRITICAL | 9.8 | 1.9% | Dec 19, 2018 | An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firm... |
| CVE-2018-15801 | HIGH | 7.4 | 0.7% | Dec 19, 2018 | Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation... |
| CVE-2018-15798 | HIGH | 7.6 | 1.1% | Dec 19, 2018 | Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unau... |
| CVE-2018-11799 | — | — | 1.5% | Dec 19, 2018 | Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can... |
| CVE-2018-19598 | — | — | 0.6% | Dec 19, 2018 | Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request. |
| CVE-2018-19597 | — | — | 0.7% | Dec 19, 2018 | CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798. |
| CVE-2018-19596 | — | — | 0.6% | Dec 19, 2018 | Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506. |
| CVE-2018-19508 | — | — | 0.6% | Dec 19, 2018 | CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI. |
| CVE-2018-19507 | — | — | 0.6% | Dec 19, 2018 | CMSimple 4.7.5 has XSS via an admin's use of a ?file=config&action=array URI. |
| CVE-2018-19506 | — | — | 0.6% | Dec 19, 2018 | Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/defau... |
| CVE-2018-18999 | HIGH | 7.3 | 2.3% | Dec 19, 2018 | WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user suppl... |
| CVE-2018-20298 | — | — | 1.4% | Dec 19, 2018 | S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now