2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-4055 | MEDIUM | 5.5 | 0.5% | Mar 8, 2019 | A local privilege escalation vulnerability exists in the install helper tool of the Mac OS X version of Pixar Renderman,... |
| CVE-2018-18809 | MEDIUM | 6.5 | 79.8% | Mar 7, 2019 | The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Comm... |
| CVE-2018-1912 | MEDIUM | 5.4 | 0.7% | Mar 6, 2019 | IBM DOORS Next Generation (DNG/RRC) 6.0.2 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2018-1911 | MEDIUM | 5.4 | 0.7% | Mar 6, 2019 | IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This ... |
| CVE-2018-1939 | MEDIUM | 6.8 | 1.3% | Mar 5, 2019 | IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By per... |
| CVE-2018-1938 | MEDIUM | 4.4 | 0.3% | Mar 5, 2019 | IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypte... |
| CVE-2018-1937 | MEDIUM | 4.4 | 0.3% | Mar 5, 2019 | IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypte... |
| CVE-2018-1899 | MEDIUM | 4.3 | 0.5% | Mar 5, 2019 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to ... |
| CVE-2018-19640 | MEDIUM | 4.4 | 0.3% | Mar 5, 2019 | If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.... |
| CVE-2018-19639 | MEDIUM | 6.7 | 0.5% | Mar 5, 2019 | If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipula... |
| CVE-2018-1775 | MEDIUM | 6.5 | 1.9% | Feb 27, 2019 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 c... |
| CVE-2018-2006 | MEDIUM | 4.9 | 2.5% | Feb 21, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the ... |
| CVE-2018-1950 | MEDIUM | 4.3 | 1.0% | Feb 21, 2019 | IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance generates an error message that ... |
| CVE-2018-1949 | MEDIUM | 4.3 | 1.0% | Feb 21, 2019 | IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance discloses sensitive information ... |
| CVE-2018-1948 | MEDIUM | 4.3 | 1.1% | Feb 21, 2019 | IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribut... |
| CVE-2018-1947 | MEDIUM | 6.1 | 0.9% | Feb 21, 2019 | IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance is vulnerable to cross-site scri... |
| CVE-2018-1946 | MEDIUM | 5.9 | 0.7% | Feb 21, 2019 | IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between mul... |
| CVE-2018-1945 | MEDIUM | 6.1 | 1.2% | Feb 21, 2019 | IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance could allow a remote attacker to... |
| CVE-2018-1944 | MEDIUM | 5.1 | 0.8% | Feb 21, 2019 | IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials,... |
| CVE-2018-6687 | MEDIUM | 5.5 | 0.8% | Feb 21, 2019 | Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attacker... |
| CVE-2018-9867 | MEDIUM | 5.5 | 0.2% | Feb 19, 2019 | In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administra... |
| CVE-2018-1996 | MEDIUM | 5.3 | 1.1% | Feb 19, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the impro... |
| CVE-2018-1895 | MEDIUM | 5.4 | 0.7% | Feb 15, 2019 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2018-20237 | MEDIUM | 6.5 | 1.7% | Feb 13, 2019 | Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted pag... |
| CVE-2018-17542 | MEDIUM | 4.3 | 1.2% | Feb 11, 2019 | SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now