2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-5813MEDIUM6.5An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to t...
CVE-2018-5800MEDIUM6.5An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions ...
CVE-2018-1896MEDIUM4.6IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to ...
CVE-2018-1883MEDIUM5.3A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow attackers to execute a ...
CVE-2018-1663MEDIUM5.9IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information,...
CVE-2018-19665MEDIUM5.7The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
CVE-2018-9566MEDIUM5.7In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a missing bounds check. ...
CVE-2018-9552MEDIUM5.5In ihevcd_sao_shift_ctb of ihevcd_sao.c there is a possible out of bounds write due to missing bounds check. This could ...
CVE-2018-9548MEDIUM5.5In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missing URI validation. Th...
CVE-2018-1935MEDIUM4.3IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request...
CVE-2018-1871MEDIUM5.4IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross...
CVE-2018-1525MEDIUM5.9IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the fa...
CVE-2018-1505MEDIUM4IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the ...
CVE-2018-1504MEDIUM6.1IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By p...
CVE-2018-19886MEDIUM5.5An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud...
CVE-2018-1002101MEDIUM5.9In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up...
CVE-2018-1732MEDIUM5.3IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used...
CVE-2018-1728MEDIUM5.4IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2018-1697MEDIUM4.3IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a specially crafted HTTP ...
CVE-2018-1650MEDIUM5.9IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication confi...
CVE-2018-1568MEDIUM4IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user on the system. IBM X...
CVE-2018-6982MEDIUM6.5VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stac...
CVE-2018-19841MEDIUM5.5The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause...
CVE-2018-1840MEDIUM6IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, ca...
CVE-2018-6332MEDIUM5.9A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spe...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now