2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1751 | MEDIUM | 5.9 | 1.3% | Jan 23, 2019 | IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could all... |
| CVE-2018-14666 | MEDIUM | 6.8 | 1.0% | Jan 22, 2019 | An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configu... |
| CVE-2018-13374 | MEDIUM | 4.3 | 38.1% | Jan 22, 2019 | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 al... |
| CVE-2018-16042 | MEDIUM | 6.5 | 82.4% | Jan 18, 2019 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 20... |
| CVE-2018-18812 | MEDIUM | 6.5 | 1.2% | Jan 16, 2019 | The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO... |
| CVE-2018-5741 | MEDIUM | 6.5 | 3.5% | Jan 16, 2019 | To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides... |
| CVE-2018-5739 | MEDIUM | 6.5 | 1.9% | Jan 16, 2019 | An extension to hooks capabilities which debuted in Kea 1.4.0 introduced a memory leak for operators who are using certa... |
| CVE-2018-5738 | MEDIUM | 5.3 | 11.1% | Jan 16, 2019 | Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, ... |
| CVE-2018-5737 | MEDIUM | 5.9 | 10.4% | Jan 16, 2019 | A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.... |
| CVE-2018-14662 | MEDIUM | 5.7 | 0.4% | Jan 15, 2019 | It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt e... |
| CVE-2018-15463 | MEDIUM | 6.1 | 1.2% | Jan 15, 2019 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic... |
| CVE-2018-15440 | MEDIUM | 6.1 | 1.3% | Jan 15, 2019 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic... |
| CVE-2018-16846 | MEDIUM | 6.5 | 2.1% | Jan 15, 2019 | It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAP... |
| CVE-2018-16888 | MEDIUM | 4.7 | 0.3% | Jan 14, 2019 | It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When ... |
| CVE-2018-1967 | MEDIUM | 6.1 | 1.3% | Jan 14, 2019 | IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2018-1956 | MEDIUM | 5.9 | 2.0% | Jan 14, 2019 | IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it ... |
| CVE-2018-16887 | MEDIUM | 5.4 | 1.0% | Jan 13, 2019 | A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/... |
| CVE-2018-15467 | MEDIUM | 6.1 | 1.2% | Jan 11, 2019 | A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an unauth... |
| CVE-2018-15466 | MEDIUM | 5.3 | 1.9% | Jan 11, 2019 | A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CP... |
| CVE-2018-15464 | MEDIUM | 5.8 | 2.3% | Jan 11, 2019 | A vulnerability in Cisco 900 Series Aggregation Services Router (ASR) software could allow an unauthenticated, remote at... |
| CVE-2018-15461 | MEDIUM | 6.1 | 1.2% | Jan 10, 2019 | A vulnerability in the MyWebex component of Cisco Webex Business Suite could allow an unauthenticated, remote attacker t... |
| CVE-2018-20685 | MEDIUM | 5.3 | 3.7% | Jan 10, 2019 | In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filenam... |
| CVE-2018-15458 | MEDIUM | 5.3 | 3.1% | Jan 10, 2019 | A vulnerability in the Shell Access Filter feature of Cisco Firepower Management Center (FMC), when used in conjunction ... |
| CVE-2018-15457 | MEDIUM | 6.1 | 1.2% | Jan 10, 2019 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remo... |
| CVE-2018-15456 | MEDIUM | 4.3 | 1.3% | Jan 10, 2019 | A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacke... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now