2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1666 | MEDIUM | 4.3 | 0.8% | Feb 7, 2019 | IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 ... |
| CVE-2018-20758 | MEDIUM | 5.4 | 0.6% | Feb 6, 2019 | MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description. |
| CVE-2018-3989 | MEDIUM | 4.3 | 0.6% | Feb 5, 2019 | An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTE... |
| CVE-2018-18506 | MEDIUM | 5.9 | 2.2% | Feb 5, 2019 | When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is l... |
| CVE-2018-1962 | MEDIUM | 4 | 0.4% | Feb 4, 2019 | IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is press... |
| CVE-2018-1801 | MEDIUM | 5.3 | 2.5% | Feb 4, 2019 | IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.... |
| CVE-2018-1675 | MEDIUM | 6.8 | 1.6% | Feb 4, 2019 | IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memor... |
| CVE-2018-16487 | MEDIUM | 5.6 | 1.6% | Feb 1, 2019 | A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep ... |
| CVE-2018-15617 | MEDIUM | 6.5 | 2.2% | Feb 1, 2019 | A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remo... |
| CVE-2018-17189 | MEDIUM | 5.3 | 19.4% | Jan 30, 2019 | In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h... |
| CVE-2018-19440 | MEDIUM | 5.3 | 1.4% | Jan 30, 2019 | ARM Trusted Firmware-A allows information disclosure. |
| CVE-2018-1976 | MEDIUM | 4.9 | 1.7% | Jan 29, 2019 | IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow ... |
| CVE-2018-1733 | MEDIUM | 5.3 | 1.7% | Jan 29, 2019 | IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane impl... |
| CVE-2018-1668 | MEDIUM | 5.3 | 1.4% | Jan 29, 2019 | IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through ... |
| CVE-2018-10910 | MEDIUM | 4.5 | 0.5% | Jan 28, 2019 | A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with... |
| CVE-2018-16889 | MEDIUM | 5.5 | 0.5% | Jan 28, 2019 | Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption ... |
| CVE-2018-19021 | MEDIUM | 6.5 | 0.7% | Jan 25, 2019 | A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, ... |
| CVE-2018-1959 | MEDIUM | 5.1 | 0.2% | Jan 24, 2019 | IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptograph... |
| CVE-2018-17699 | MEDIUM | 6.5 | 4.1% | Jan 24, 2019 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader... |
| CVE-2018-17686 | MEDIUM | 6.5 | 24.4% | Jan 24, 2019 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader... |
| CVE-2018-15459 | MEDIUM | 6.5 | 1.7% | Jan 23, 2019 | A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated... |
| CVE-2018-15455 | MEDIUM | 6.1 | 1.1% | Jan 23, 2019 | A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated, remote attack... |
| CVE-2018-0187 | MEDIUM | 6.5 | 1.5% | Jan 23, 2019 | A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacke... |
| CVE-2018-15614 | MEDIUM | 6.8 | 0.6% | Jan 23, 2019 | A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross sit... |
| CVE-2018-2026 | MEDIUM | 4.3 | 1.4% | Jan 23, 2019 | IBM Financial Transaction Manager 3.2.1 for Digital Payments could allow an authenticated user to obtain a directory lis... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now