2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17983 | — | — | 2.0% | Oct 4, 2018 | cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry. |
| CVE-2018-17891 | — | — | 0.7% | Oct 4, 2018 | Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contac... |
| CVE-2018-17849 | — | — | 0.5% | Oct 4, 2018 | Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScrip... |
| CVE-2018-16457 | — | — | 1.5% | Oct 4, 2018 | PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_... |
| CVE-2018-16456 | — | — | 0.7% | Oct 4, 2018 | PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has ... |
| CVE-2018-16455 | MEDIUM | 6.1 | 0.7% | Oct 4, 2018 | PHP Scripts Mall Market Place Script 1.0.1 allows XSS via a keyword. |
| CVE-2018-16453 | — | — | 0.7% | Oct 4, 2018 | PHP Scripts Mall Domain Lookup Script 3.0.5 allows XSS in the search bar. |
| CVE-2018-16326 | — | — | 0.7% | Oct 4, 2018 | PHP Scripts Mall Olx Clone 3.4.2 has XSS. |
| CVE-2018-13258 | — | — | 2.1% | Oct 4, 2018 | Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that should... |
| CVE-2018-0505 | — | — | 1.9% | Oct 4, 2018 | Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's acco... |
| CVE-2018-0504 | — | — | 2.8% | Oct 4, 2018 | Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/... |
| CVE-2018-0503 | — | — | 1.5% | Oct 4, 2018 | Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimi... |
| CVE-2018-17876 | — | — | 1.0% | Oct 4, 2018 | A Stored XSS vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product. |
| CVE-2018-17872 | — | — | 2.2% | Oct 4, 2018 | Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions. |
| CVE-2018-17871 | MEDIUM | 6.5 | 1.8% | Oct 4, 2018 | Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control. |
| CVE-2018-1819 | MEDIUM | 6.3 | 1.7% | Oct 4, 2018 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable t... |
| CVE-2018-1670 | LOW | 3.1 | 1.2% | Oct 4, 2018 | IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain ... |
| CVE-2018-1604 | MEDIUM | 5.4 | 0.7% | Oct 4, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1603 | MEDIUM | 5.4 | 0.7% | Oct 4, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1602 | MEDIUM | 5.4 | 0.7% | Oct 4, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-12472 | HIGH | 7.3 | 1.5% | Oct 4, 2018 | A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Aff... |
| CVE-2018-12471 | MEDIUM | 6.5 | 1.5% | Oct 4, 2018 | A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server... |
| CVE-2018-12470 | CRITICAL | 9.8 | 2.0% | Oct 4, 2018 | A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary S... |
| CVE-2018-5492 | — | — | 2.9% | Oct 4, 2018 | NetApp E-Series SANtricity OS Controller Software 11.30 and later version 11.30.5 is susceptible to unauthenticated remo... |
| CVE-2018-11784 | — | — | 94.5% | Oct 4, 2018 | When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a r... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now