2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1480 | MEDIUM | 4 | 1.1% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization to... |
| CVE-2018-1478 | MEDIUM | 6.1 | 1.1% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 could allow a remote attacker to hijack the clicking acti... |
| CVE-2018-1476 | MEDIUM | 5.3 | 1.4% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users. Th... |
| CVE-2018-1474 | MEDIUM | 6.1 | 1.2% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused ... |
| CVE-2018-13816 | — | — | 2.8% | Dec 12, 2018 | A vulnerability has been identified in TIM 1531 IRC (All version < V2.0). The devices was missing proper authentication ... |
| CVE-2018-11466 | — | — | 4.0% | Dec 12, 2018 | A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK... |
| CVE-2018-11465 | — | — | 0.4% | Dec 12, 2018 | A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK... |
| CVE-2018-11464 | — | — | 1.9% | Dec 12, 2018 | A vulnerability has been identified in SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All ve... |
| CVE-2018-11463 | — | — | 0.5% | Dec 12, 2018 | A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK... |
| CVE-2018-11462 | — | — | 3.7% | Dec 12, 2018 | A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK... |
| CVE-2018-11461 | — | — | 0.4% | Dec 12, 2018 | A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK... |
| CVE-2018-11460 | — | — | 0.4% | Dec 12, 2018 | A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK... |
| CVE-2018-11459 | — | — | 0.4% | Dec 12, 2018 | A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK... |
| CVE-2018-11458 | — | — | 4.6% | Dec 12, 2018 | A vulnerability has been identified in SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All ve... |
| CVE-2018-11457 | — | — | 4.6% | Dec 12, 2018 | A vulnerability has been identified in SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All ve... |
| CVE-2018-8650 | MEDIUM | 5.4 | 1.6% | Dec 12, 2018 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2018-17952 | — | — | 0.6% | Dec 12, 2018 | Cross site scripting vulnerability in eDirectory prior to 9.1 SP2 |
| CVE-2018-17950 | — | — | 0.8% | Dec 12, 2018 | Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2 |
| CVE-2018-17949 | — | — | 0.6% | Dec 12, 2018 | Cross site scripting vulnerability in iManager prior to 3.1 SP2. |
| CVE-2018-15328 | — | — | 2.3% | Dec 12, 2018 | On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passp... |
| CVE-2018-16867 | HIGH | 7.8 | 0.4% | Dec 12, 2018 | A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_da... |
| CVE-2018-20099 | — | — | 2.3% | Dec 12, 2018 | There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will le... |
| CVE-2018-20098 | — | — | 2.6% | Dec 12, 2018 | There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted ... |
| CVE-2018-20097 | MEDIUM | 6.5 | 2.3% | Dec 12, 2018 | There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafte... |
| CVE-2018-20096 | — | — | 2.8% | Dec 12, 2018 | There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now