2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16861HIGH7.6A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create ...
CVE-2018-19960The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_ser...
CVE-2018-1920HIGH7.1IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processi...
CVE-2018-1896MEDIUM4.6IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to ...
CVE-2018-1883MEDIUM5.3A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow attackers to execute a ...
CVE-2018-1663MEDIUM5.9IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information,...
CVE-2018-1424HIGH7.1IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when process...
CVE-2018-15362XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0
CVE-2018-7364CRITICAL9.8All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control ...
CVE-2018-19001Philips HealthSuite Health Android App, all versions. The software uses simple encryption that is not strong enough for ...
CVE-2018-17924HIGH8.6Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote ...
CVE-2018-11905In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buff...
CVE-2018-19939HIGH7.5The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite...
CVE-2018-19935HIGH7.5ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer d...
CVE-2018-19932An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through...
CVE-2018-19931HIGH7.8An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through...
CVE-2018-6757HIGH7.5Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows loca...
CVE-2018-6756HIGH7.8Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows loca...
CVE-2018-6755HIGH7.2Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows...
CVE-2018-19927Zenitel Norway IP-StationWeb before 4.2.3.9 allows stored XSS via the Display Name for Station Status or Account Setting...
CVE-2018-19926Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO.
CVE-2018-19925An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the mem...
CVE-2018-19924An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified...
CVE-2018-19923An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php...
CVE-2018-19665MEDIUM5.7The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now