2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1833 | MEDIUM | 5.3 | 1.7% | Dec 18, 2018 | IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An at... |
| CVE-2018-20199 | MEDIUM | 5.5 | 1.1% | Dec 18, 2018 | A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FA... |
| CVE-2018-20185 | MEDIUM | 5.3 | 2.1% | Dec 17, 2018 | In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPIma... |
| CVE-2018-20123 | MEDIUM | 5.5 | 0.5% | Dec 17, 2018 | pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error. |
| CVE-2018-1891 | MEDIUM | 5.4 | 1.0% | Dec 17, 2018 | IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2018-1889 | MEDIUM | 5.4 | 1.0% | Dec 17, 2018 | IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2018-20169 | MEDIUM | 6.8 | 0.6% | Dec 17, 2018 | An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading o... |
| CVE-2018-1977 | MEDIUM | 5.3 | 1.9% | Dec 14, 2018 | IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A rem... |
| CVE-2018-1848 | MEDIUM | 6.1 | 1.3% | Dec 14, 2018 | IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2018-18984 | MEDIUM | 4.6 | 0.3% | Dec 14, 2018 | Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI informa... |
| CVE-2018-16875 | MEDIUM | 5.9 | 6.3% | Dec 14, 2018 | The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for eac... |
| CVE-2018-14623 | MEDIUM | 4.3 | 1.4% | Dec 14, 2018 | A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to... |
| CVE-2018-15776 | MEDIUM | 6.4 | 0.4% | Dec 13, 2018 | Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated... |
| CVE-2018-15754 | MEDIUM | 4.2 | 1.8% | Dec 13, 2018 | Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identi... |
| CVE-2018-16872 | MEDIUM | 5.3 | 1.1% | Dec 13, 2018 | A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_par... |
| CVE-2018-19489 | MEDIUM | 4.7 | 0.4% | Dec 13, 2018 | v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race conditio... |
| CVE-2018-19364 | MEDIUM | 5.5 | 0.5% | Dec 13, 2018 | hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading ... |
| CVE-2018-20138 | MEDIUM | 5.4 | 0.6% | Dec 13, 2018 | PHP Scripts Mall Entrepreneur B2B Script 3.0.6 allows Stored XSS via Account Settings fields such as FirstName and LastN... |
| CVE-2018-1887 | MEDIUM | 5.9 | 0.2% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, s... |
| CVE-2018-1886 | MEDIUM | 5.3 | 1.3% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to... |
| CVE-2018-1818 | MEDIUM | 5.9 | 0.8% | Dec 13, 2018 | IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it use... |
| CVE-2018-1817 | MEDIUM | 6.1 | 0.9% | Dec 13, 2018 | IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2018-1815 | MEDIUM | 6.1 | 0.9% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is v... |
| CVE-2018-1814 | MEDIUM | 5.9 | 1.0% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses weaker than expected cryptogr... |
| CVE-2018-1813 | MEDIUM | 4.3 | 0.9% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for i... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now