2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1833MEDIUM5.3IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An at...
CVE-2018-20199MEDIUM5.5A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FA...
CVE-2018-20185MEDIUM5.3In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPIma...
CVE-2018-20123MEDIUM5.5pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.
CVE-2018-1891MEDIUM5.4IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr...
CVE-2018-1889MEDIUM5.4IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2018-20169MEDIUM6.8An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading o...
CVE-2018-1977MEDIUM5.3IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A rem...
CVE-2018-1848MEDIUM6.1IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2018-18984MEDIUM4.6Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI informa...
CVE-2018-16875MEDIUM5.9The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for eac...
CVE-2018-14623MEDIUM4.3A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to...
CVE-2018-15776MEDIUM6.4Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated...
CVE-2018-15754MEDIUM4.2Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identi...
CVE-2018-16872MEDIUM5.3A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_par...
CVE-2018-19489MEDIUM4.7v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race conditio...
CVE-2018-19364MEDIUM5.5hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading ...
CVE-2018-20138MEDIUM5.4PHP Scripts Mall Entrepreneur B2B Script 3.0.6 allows Stored XSS via Account Settings fields such as FirstName and LastN...
CVE-2018-1887MEDIUM5.9IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, s...
CVE-2018-1886MEDIUM5.3IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to...
CVE-2018-1818MEDIUM5.9IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it use...
CVE-2018-1817MEDIUM6.1IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr...
CVE-2018-1815MEDIUM6.1IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is v...
CVE-2018-1814MEDIUM5.9IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses weaker than expected cryptogr...
CVE-2018-1813MEDIUM4.3IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for i...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now