2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1593LOW3.7IBM Multi-Cloud Data Encryption (MDE) 2.1 could allow an unauthorized user to manipulate data due to missing file checks...
CVE-2018-1558MEDIUM5.4IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scri...
CVE-2018-1557MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1522MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1509LOW3.7IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allo...
CVE-2018-1498MEDIUM6.2IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. I...
CVE-2018-1440MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1439MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1405MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1404MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1403MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1395MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-12473LOW3.1A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause a...
CVE-2018-11043Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-9069MEDIUM5.9In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adeq...
CVE-2018-11072Dell Digital Delivery versions prior to 3.5.1 contain a DLL Injection Vulnerability. A local authenticated malicious use...
CVE-2018-17874ExpressionEngine before 4.3.5 has reflected XSS.
CVE-2018-17870An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open ...
CVE-2018-17869DASAN H660GW devices do not implement any CSRF protection mechanism.
CVE-2018-17868DASAN H660GW devices have Stored XSS in the Port Forwarding functionality.
CVE-2018-17867The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell me...
CVE-2018-4001HIGH7.8An exploitable uninitialized pointer vulnerability exists in the Office Open XML parser of Atlantis Word Processor, vers...
CVE-2018-4000HIGH7.8An exploitable double-free vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5....
CVE-2018-3999HIGH7.8An exploitable stack-based buffer overflow vulnerability exists in the JPEG parser of Atlantis Word Processor, version 3...
CVE-2018-3998HIGH7.8An exploitable heap-based buffer overflow vulnerability exists in the Windows enhanced metafile parser of Atlantis Word ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now