2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7362 | HIGH | 7.5 | 1.2% | Nov 16, 2018 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which ma... |
| CVE-2018-7361 | MEDIUM | 6.5 | 0.8% | Nov 16, 2018 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by null pointer dereference vulnerability, which m... |
| CVE-2018-7360 | CRITICAL | 9.6 | 1.0% | Nov 16, 2018 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by information exposure vulnerability, which may a... |
| CVE-2018-7359 | CRITICAL | 9 | 1.9% | Nov 16, 2018 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which... |
| CVE-2018-1797 | MEDIUM | 6.3 | 2.0% | Nov 16, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attac... |
| CVE-2018-1639 | MEDIUM | 4.3 | 1.1% | Nov 16, 2018 | The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user t... |
| CVE-2018-9086 | — | — | 2.4% | Nov 16, 2018 | In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download comman... |
| CVE-2018-9085 | — | — | 0.7% | Nov 16, 2018 | A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potenti... |
| CVE-2018-9073 | — | — | 0.5% | Nov 16, 2018 | Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain sec... |
| CVE-2018-9071 | — | — | 1.0% | Nov 16, 2018 | Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information relat... |
| CVE-2018-19296 | HIGH | 8.8 | 2.2% | Nov 16, 2018 | PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. |
| CVE-2018-19301 | — | — | 0.7% | Nov 15, 2018 | tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later v... |
| CVE-2018-5407 | MEDIUM | 4.7 | 3.4% | Nov 15, 2018 | Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks... |
| CVE-2018-18954 | — | — | 0.5% | Nov 15, 2018 | The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV... |
| CVE-2018-16621 | HIGH | 7.2 | 1.8% | Nov 15, 2018 | Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection. |
| CVE-2018-16620 | — | — | 1.1% | Nov 15, 2018 | Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control. |
| CVE-2018-16619 | — | — | 0.7% | Nov 15, 2018 | Sonatype Nexus Repository Manager before 3.14 allows XSS. |
| CVE-2018-14935 | — | — | 0.6% | Nov 15, 2018 | The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS. |
| CVE-2018-14934 | — | — | 0.5% | Nov 15, 2018 | The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can... |
| CVE-2018-8529 | — | — | 13.5% | Nov 15, 2018 | A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on th... |
| CVE-2018-1643 | MEDIUM | 6.1 | 1.5% | Nov 15, 2018 | The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-sit... |
| CVE-2018-16163 | — | — | 0.8% | Nov 15, 2018 | OpenDolphin 2.7.0 and earlier allows authenticated attackers to bypass authentication to create and/or delete other user... |
| CVE-2018-16162 | — | — | 1.0% | Nov 15, 2018 | OpenDolphin 2.7.0 and earlier allows authenticated attackers to obtain other users credentials such as a user ID and/or ... |
| CVE-2018-16161 | — | — | 1.3% | Nov 15, 2018 | OpenDolphin 2.7.0 and earlier allows authenticated users to gain administrative privileges and perform unintended operat... |
| CVE-2018-16160 | — | — | 0.3% | Nov 15, 2018 | SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Window... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now