2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16861 | HIGH | 7.6 | 0.9% | Dec 7, 2018 | A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create ... |
| CVE-2018-19960 | — | — | 0.3% | Dec 7, 2018 | The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_ser... |
| CVE-2018-1920 | HIGH | 7.1 | 2.4% | Dec 7, 2018 | IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processi... |
| CVE-2018-1896 | MEDIUM | 4.6 | 1.0% | Dec 7, 2018 | IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to ... |
| CVE-2018-1883 | MEDIUM | 5.3 | 2.4% | Dec 7, 2018 | A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow attackers to execute a ... |
| CVE-2018-1663 | MEDIUM | 5.9 | 2.3% | Dec 7, 2018 | IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information,... |
| CVE-2018-1424 | HIGH | 7.1 | 2.4% | Dec 7, 2018 | IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when process... |
| CVE-2018-15362 | — | — | 2.7% | Dec 7, 2018 | XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0 |
| CVE-2018-7364 | CRITICAL | 9.8 | 10.3% | Dec 7, 2018 | All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control ... |
| CVE-2018-19001 | — | — | 0.2% | Dec 7, 2018 | Philips HealthSuite Health Android App, all versions. The software uses simple encryption that is not strong enough for ... |
| CVE-2018-17924 | HIGH | 8.6 | 4.3% | Dec 7, 2018 | Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote ... |
| CVE-2018-11905 | — | — | 0.9% | Dec 7, 2018 | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buff... |
| CVE-2018-19939 | HIGH | 7.5 | 1.3% | Dec 7, 2018 | The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite... |
| CVE-2018-19935 | HIGH | 7.5 | 6.9% | Dec 7, 2018 | ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer d... |
| CVE-2018-19932 | — | — | 1.9% | Dec 7, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through... |
| CVE-2018-19931 | HIGH | 7.8 | 1.5% | Dec 7, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through... |
| CVE-2018-6757 | HIGH | 7.5 | 1.1% | Dec 6, 2018 | Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows loca... |
| CVE-2018-6756 | HIGH | 7.8 | 1.0% | Dec 6, 2018 | Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows loca... |
| CVE-2018-6755 | HIGH | 7.2 | 1.0% | Dec 6, 2018 | Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows... |
| CVE-2018-19927 | — | — | 0.6% | Dec 6, 2018 | Zenitel Norway IP-StationWeb before 4.2.3.9 allows stored XSS via the Display Name for Station Status or Account Setting... |
| CVE-2018-19926 | — | — | 0.7% | Dec 6, 2018 | Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO. |
| CVE-2018-19925 | — | — | 1.1% | Dec 6, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the mem... |
| CVE-2018-19924 | — | — | 0.7% | Dec 6, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified... |
| CVE-2018-19923 | — | — | 0.5% | Dec 6, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php... |
| CVE-2018-19665 | MEDIUM | 5.7 | 0.9% | Dec 6, 2018 | The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now