2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-7362HIGH7.5All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which ma...
CVE-2018-7361MEDIUM6.5All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by null pointer dereference vulnerability, which m...
CVE-2018-7360CRITICAL9.6All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by information exposure vulnerability, which may a...
CVE-2018-7359CRITICAL9All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which...
CVE-2018-1797MEDIUM6.3IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attac...
CVE-2018-1639MEDIUM4.3The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user t...
CVE-2018-9086In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download comman...
CVE-2018-9085A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potenti...
CVE-2018-9073Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain sec...
CVE-2018-9071Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information relat...
CVE-2018-19296HIGH8.8PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
CVE-2018-19301tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later v...
CVE-2018-5407MEDIUM4.7Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks...
CVE-2018-18954The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV...
CVE-2018-16621HIGH7.2Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
CVE-2018-16620Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.
CVE-2018-16619Sonatype Nexus Repository Manager before 3.14 allows XSS.
CVE-2018-14935The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.
CVE-2018-14934The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can...
CVE-2018-8529A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on th...
CVE-2018-1643MEDIUM6.1The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-sit...
CVE-2018-16163OpenDolphin 2.7.0 and earlier allows authenticated attackers to bypass authentication to create and/or delete other user...
CVE-2018-16162OpenDolphin 2.7.0 and earlier allows authenticated attackers to obtain other users credentials such as a user ID and/or ...
CVE-2018-16161OpenDolphin 2.7.0 and earlier allows authenticated users to gain administrative privileges and perform unintended operat...
CVE-2018-16160SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Window...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now