2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-4055MEDIUM5.5A local privilege escalation vulnerability exists in the install helper tool of the Mac OS X version of Pixar Renderman,...
CVE-2018-18809MEDIUM6.5The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Comm...
CVE-2018-1912MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 6.0.2 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows...
CVE-2018-1911MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This ...
CVE-2018-1939MEDIUM6.8IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By per...
CVE-2018-1938MEDIUM4.4IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypte...
CVE-2018-1937MEDIUM4.4IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypte...
CVE-2018-1899MEDIUM4.3IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to ...
CVE-2018-19640MEDIUM4.4If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5....
CVE-2018-19639MEDIUM6.7If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipula...
CVE-2018-1775MEDIUM6.5IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 c...
CVE-2018-2006MEDIUM4.9IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the ...
CVE-2018-1950MEDIUM4.3IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance generates an error message that ...
CVE-2018-1949MEDIUM4.3IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance discloses sensitive information ...
CVE-2018-1948MEDIUM4.3IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribut...
CVE-2018-1947MEDIUM6.1IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance is vulnerable to cross-site scri...
CVE-2018-1946MEDIUM5.9IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between mul...
CVE-2018-1945MEDIUM6.1IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance could allow a remote attacker to...
CVE-2018-1944MEDIUM5.1IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials,...
CVE-2018-6687MEDIUM5.5Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attacker...
CVE-2018-9867MEDIUM5.5In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administra...
CVE-2018-1996MEDIUM5.3IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the impro...
CVE-2018-1895MEDIUM5.4IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2018-20237MEDIUM6.5Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted pag...
CVE-2018-17542MEDIUM4.3SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now