2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18923 | — | — | 3.2% | Dec 13, 2018 | AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and ... |
| CVE-2018-18922 | — | — | 2.4% | Dec 13, 2018 | add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POS... |
| CVE-2018-12076 | — | — | 0.3% | Dec 13, 2018 | A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to a... |
| CVE-2018-20138 | MEDIUM | 5.4 | 0.6% | Dec 13, 2018 | PHP Scripts Mall Entrepreneur B2B Script 3.0.6 allows Stored XSS via Account Settings fields such as FirstName and LastN... |
| CVE-2018-20137 | — | — | 0.6% | Dec 13, 2018 | XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demo... |
| CVE-2018-20136 | — | — | 0.6% | Dec 13, 2018 | XSS exists in FUEL CMS 1.4.3 via the Header or Body in the Layout Variables during new-page creation, as demonstrated by... |
| CVE-2018-1887 | MEDIUM | 5.9 | 0.2% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, s... |
| CVE-2018-1886 | MEDIUM | 5.3 | 1.3% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to... |
| CVE-2018-1821 | HIGH | 7.1 | 15.8% | Dec 13, 2018 | IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) a... |
| CVE-2018-1818 | MEDIUM | 5.9 | 0.8% | Dec 13, 2018 | IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it use... |
| CVE-2018-1817 | MEDIUM | 6.1 | 0.9% | Dec 13, 2018 | IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2018-1815 | MEDIUM | 6.1 | 0.9% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is v... |
| CVE-2018-1814 | MEDIUM | 5.9 | 1.0% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses weaker than expected cryptogr... |
| CVE-2018-1813 | MEDIUM | 4.3 | 0.9% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for i... |
| CVE-2018-1805 | MEDIUM | 4.3 | 1.0% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an error message that in... |
| CVE-2018-1804 | LOW | 3.7 | 0.9% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set the secure attribute ... |
| CVE-2018-1803 | MEDIUM | 6.1 | 1.2% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to h... |
| CVE-2018-1740 | MEDIUM | 5.4 | 0.7% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site script... |
| CVE-2018-1667 | MEDIUM | 5.4 | 0.7% | Dec 13, 2018 | IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.... |
| CVE-2018-1665 | MEDIUM | 5.9 | 1.0% | Dec 13, 2018 | IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.... |
| CVE-2018-16557 | HIGH | 8.2 | 0.8% | Dec 13, 2018 | A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (... |
| CVE-2018-16556 | HIGH | 7.5 | 1.5% | Dec 13, 2018 | A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (... |
| CVE-2018-16555 | — | — | 0.7% | Dec 13, 2018 | A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1),... |
| CVE-2018-1653 | MEDIUM | 5.4 | 1.0% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site script... |
| CVE-2018-13815 | — | — | 1.8% | Dec 13, 2018 | A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacke... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now