2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1805 | MEDIUM | 4.3 | 1.0% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an error message that in... |
| CVE-2018-1803 | MEDIUM | 6.1 | 1.2% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to h... |
| CVE-2018-1740 | MEDIUM | 5.4 | 0.7% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site script... |
| CVE-2018-1667 | MEDIUM | 5.4 | 0.7% | Dec 13, 2018 | IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.... |
| CVE-2018-1665 | MEDIUM | 5.9 | 1.0% | Dec 13, 2018 | IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.... |
| CVE-2018-1653 | MEDIUM | 5.4 | 1.0% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site script... |
| CVE-2018-7691 | MEDIUM | 6.5 | 7.2% | Dec 13, 2018 | A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.... |
| CVE-2018-7690 | MEDIUM | 6.5 | 7.4% | Dec 13, 2018 | A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.... |
| CVE-2018-1926 | MEDIUM | 4.3 | 1.2% | Dec 12, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, cause... |
| CVE-2018-1901 | MEDIUM | 5 | 1.5% | Dec 12, 2018 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on th... |
| CVE-2018-1480 | MEDIUM | 4 | 1.1% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization to... |
| CVE-2018-1478 | MEDIUM | 6.1 | 1.1% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 could allow a remote attacker to hijack the clicking acti... |
| CVE-2018-1476 | MEDIUM | 5.3 | 1.4% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users. Th... |
| CVE-2018-1474 | MEDIUM | 6.1 | 1.2% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused ... |
| CVE-2018-8650 | MEDIUM | 5.4 | 1.6% | Dec 12, 2018 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2018-20097 | MEDIUM | 6.5 | 2.3% | Dec 12, 2018 | There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafte... |
| CVE-2018-8580 | MEDIUM | 4.3 | 4.3% | Dec 12, 2018 | An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server... |
| CVE-2018-2504 | MEDIUM | 6.1 | 1.1% | Dec 11, 2018 | SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in... |
| CVE-2018-18810 | MEDIUM | 6.8 | 1.2% | Dec 11, 2018 | The Administrator Service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, and TIBCO Manag... |
| CVE-2018-1900 | MEDIUM | 5.4 | 1.0% | Dec 11, 2018 | IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vu... |
| CVE-2018-1654 | MEDIUM | 6.8 | 1.3% | Dec 11, 2018 | IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phish... |
| CVE-2018-1652 | MEDIUM | 6.2 | 0.4% | Dec 11, 2018 | IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.... |
| CVE-2018-20029 | MEDIUM | 5.5 | 0.3% | Dec 10, 2018 | The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a d... |
| CVE-2018-3988 | MEDIUM | 4.7 | 0.5% | Dec 10, 2018 | Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses th... |
| CVE-2018-1957 | MEDIUM | 4 | 0.4% | Dec 10, 2018 | IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by th... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now