2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17177 | LOW | 2.4 | 0.2% | Sep 18, 2018 | An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the c... |
| CVE-2018-1644 | LOW | 3.1 | 0.9% | Aug 27, 2018 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 -... |
| CVE-2018-11065 | LOW | 2.7 | 1.3% | Aug 24, 2018 | The WorkPoint component, which is embedded in all RSA Archer, versions 6.1.x, 6.2.x, 6.3.x prior to 6.3.0.7 and 6.4.x pr... |
| CVE-2018-1551 | LOW | 3.1 | 1.1% | Aug 6, 2018 | IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they ... |
| CVE-2018-3084 | LOW | 2.8 | 0.4% | Jul 18, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell: Core / Client). Supported versions tha... |
| CVE-2018-3082 | LOW | 2.7 | 1.4% | Jul 18, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are aff... |
| CVE-2018-3066 | LOW | 3.3 | 1.9% | Jul 18, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are... |
| CVE-2018-2952 | LOW | 3.7 | 4.2% | Jul 18, 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Support... |
| CVE-2018-2767 | LOW | 3.1 | 1.5% | Jul 18, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported vers... |
| CVE-2018-10871 | LOW | 3.8 | 1.0% | Jul 18, 2018 | 389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default,... |
| CVE-2018-12461 | LOW | 3.5 | 0.5% | Jul 10, 2018 | Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation. |
| CVE-2018-10852 | LOW | 3.8 | 1.5% | Jun 26, 2018 | The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, whic... |
| CVE-2018-1120 | LOW | 2.8 | 7.3% | Jun 20, 2018 | A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory... |
| CVE-2018-1419 | LOW | 3.7 | 2.2% | Jun 15, 2018 | IBM WebSphere MQ 8.0 and 9.0, when configured to use a PAM module for authentication, could allow a user to cause a dead... |
| CVE-2018-1121 | LOW | 3.9 | 4.2% | Jun 13, 2018 | procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() return... |
| CVE-2018-1393 | LOW | 3.1 | 1.2% | Jun 13, 2018 | IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.6 could allow an authenticated user to execute... |
| CVE-2018-1369 | LOW | 3.7 | 1.1% | May 29, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead t... |
| CVE-2018-1123 | LOW | 3.9 | 9.1% | May 23, 2018 | procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection ... |
| CVE-2018-1118 | LOW | 2.3 | 0.4% | May 10, 2018 | Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and t... |
| CVE-2018-2419 | LOW | 3.7 | 0.9% | May 9, 2018 | SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18... |
| CVE-2018-2790 | LOW | 3.1 | 5.1% | Apr 19, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions ... |
| CVE-2018-2412 | LOW | 3.8 | 1.4% | Apr 10, 2018 | SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in e... |
| CVE-2018-6659 | LOW | 3.7 | 1.0% | Apr 2, 2018 | Reflected Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows r... |
| CVE-2018-7676 | LOW | 3.9 | 0.9% | Mar 28, 2018 | The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information. |
| CVE-2018-7674 | LOW | 2.1 | 0.8% | Mar 28, 2018 | The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now