2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1951 | MEDIUM | 5.4 | 1.0% | Jan 4, 2019 | IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to ... |
| CVE-2018-1888 | MEDIUM | 5.3 | 1.2% | Jan 4, 2019 | An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitra... |
| CVE-2018-1859 | MEDIUM | 4.3 | 1.0% | Jan 4, 2019 | IBM API Connect 5.0.0.0 through 5.0.8.4 could allow a user authenticated as an administrator with limited rights to esca... |
| CVE-2018-1657 | MEDIUM | 5.4 | 1.0% | Jan 4, 2019 | IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to ... |
| CVE-2018-3986 | MEDIUM | 5.5 | 0.4% | Jan 3, 2019 | An exploitable information disclosure vulnerability exists in the "Secret Chats" functionality of the Telegram Android m... |
| CVE-2018-15780 | MEDIUM | 4.3 | 1.2% | Jan 3, 2019 | RSA Archer versions prior to 6.5.0.1 contain an improper access control vulnerability. A remote malicious user could pot... |
| CVE-2018-16885 | MEDIUM | 4.7 | 0.4% | Jan 3, 2019 | A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with ... |
| CVE-2018-16876 | MEDIUM | 5.3 | 2.5% | Jan 3, 2019 | ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on... |
| CVE-2018-20662 | MEDIUM | 6.5 | 2.2% | Jan 3, 2019 | In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by... |
| CVE-2018-20650 | MEDIUM | 6.5 | 2.7% | Jan 1, 2019 | A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack... |
| CVE-2018-6341 | MEDIUM | 6.1 | 3.4% | Dec 31, 2018 | React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names a... |
| CVE-2018-20623 | MEDIUM | 5.5 | 1.8% | Dec 31, 2018 | In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archiv... |
| CVE-2018-20622 | MEDIUM | 6.5 | 2.9% | Dec 31, 2018 | JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used. |
| CVE-2018-6668 | MEDIUM | 6.1 | 0.4% | Dec 31, 2018 | A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows execution bypass... |
| CVE-2018-19937 | MEDIUM | 6.6 | 0.3% | Dec 31, 2018 | A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by ope... |
| CVE-2018-19918 | MEDIUM | 5.4 | 0.7% | Dec 31, 2018 | CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI. |
| CVE-2018-19906 | MEDIUM | 5.4 | 0.7% | Dec 31, 2018 | Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter. |
| CVE-2018-19905 | MEDIUM | 5.4 | 0.7% | Dec 31, 2018 | HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter. |
| CVE-2018-19904 | MEDIUM | 6.1 | 0.9% | Dec 31, 2018 | Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field. |
| CVE-2018-18593 | MEDIUM | 6.5 | 6.6% | Dec 31, 2018 | Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, ve... |
| CVE-2018-20590 | MEDIUM | 4.8 | 0.6% | Dec 30, 2018 | Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/users.php user ID. |
| CVE-2018-20584 | MEDIUM | 6.5 | 2.9% | Dec 30, 2018 | JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the... |
| CVE-2018-7366 | MEDIUM | 4.3 | 0.6% | Dec 28, 2018 | ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the... |
| CVE-2018-20217 | MEDIUM | 5.3 | 1.5% | Dec 26, 2018 | A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtai... |
| CVE-2018-19615 | MEDIUM | 6.1 | 3.3% | Dec 26, 2018 | Rockwell Automation Allen-Bradley PowerMonitor 1000 all versions. A remote attacker could inject arbitrary code into a t... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now