2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1593 | LOW | 3.7 | 0.4% | Oct 2, 2018 | IBM Multi-Cloud Data Encryption (MDE) 2.1 could allow an unauthorized user to manipulate data due to missing file checks... |
| CVE-2018-1558 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scri... |
| CVE-2018-1557 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1522 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1509 | LOW | 3.7 | 0.9% | Oct 2, 2018 | IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allo... |
| CVE-2018-1498 | MEDIUM | 6.2 | 0.4% | Oct 2, 2018 | IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. I... |
| CVE-2018-1440 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1439 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1405 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1404 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1403 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1395 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-12473 | LOW | 3.1 | 1.8% | Oct 2, 2018 | A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause a... |
| CVE-2018-11043 | — | — | — | Oct 2, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-9069 | MEDIUM | 5.9 | 0.5% | Oct 2, 2018 | In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adeq... |
| CVE-2018-11072 | — | — | 0.4% | Oct 2, 2018 | Dell Digital Delivery versions prior to 3.5.1 contain a DLL Injection Vulnerability. A local authenticated malicious use... |
| CVE-2018-17874 | — | — | 0.6% | Oct 1, 2018 | ExpressionEngine before 4.3.5 has reflected XSS. |
| CVE-2018-17870 | — | — | 0.8% | Oct 1, 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open ... |
| CVE-2018-17869 | — | — | 0.5% | Oct 1, 2018 | DASAN H660GW devices do not implement any CSRF protection mechanism. |
| CVE-2018-17868 | — | — | 0.5% | Oct 1, 2018 | DASAN H660GW devices have Stored XSS in the Port Forwarding functionality. |
| CVE-2018-17867 | — | — | 3.8% | Oct 1, 2018 | The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell me... |
| CVE-2018-4001 | HIGH | 7.8 | 1.5% | Oct 1, 2018 | An exploitable uninitialized pointer vulnerability exists in the Office Open XML parser of Atlantis Word Processor, vers... |
| CVE-2018-4000 | HIGH | 7.8 | 1.0% | Oct 1, 2018 | An exploitable double-free vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5.... |
| CVE-2018-3999 | HIGH | 7.8 | 0.9% | Oct 1, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the JPEG parser of Atlantis Word Processor, version 3... |
| CVE-2018-3998 | HIGH | 7.8 | 1.0% | Oct 1, 2018 | An exploitable heap-based buffer overflow vulnerability exists in the Windows enhanced metafile parser of Atlantis Word ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now