2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1841 | MEDIUM | 6.2 | 0.4% | Nov 19, 2018 | IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/mas... |
| CVE-2018-7363 | MEDIUM | 4.3 | 0.9% | Nov 16, 2018 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since app... |
| CVE-2018-7361 | MEDIUM | 6.5 | 0.8% | Nov 16, 2018 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by null pointer dereference vulnerability, which m... |
| CVE-2018-1797 | MEDIUM | 6.3 | 2.0% | Nov 16, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attac... |
| CVE-2018-1639 | MEDIUM | 4.3 | 1.1% | Nov 16, 2018 | The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user t... |
| CVE-2018-5407 | MEDIUM | 4.7 | 3.4% | Nov 15, 2018 | Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks... |
| CVE-2018-1643 | MEDIUM | 6.1 | 1.5% | Nov 15, 2018 | The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-sit... |
| CVE-2018-19289 | MEDIUM | 6.1 | 1.2% | Nov 15, 2018 | An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via ... |
| CVE-2018-19286 | MEDIUM | 6.1 | 0.7% | Nov 15, 2018 | The server in mubu note 2018-11-11 has XSS by configuring an account with a crafted name value (along with an arbitrary ... |
| CVE-2018-7358 | MEDIUM | 6.5 | 89.6% | Nov 14, 2018 | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper cha... |
| CVE-2018-7357 | MEDIUM | 6.5 | 87.9% | Nov 14, 2018 | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper acc... |
| CVE-2018-8568 | MEDIUM | 5.4 | 2.2% | Nov 14, 2018 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c... |
| CVE-2018-14658 | MEDIUM | 6.1 | 1.1% | Nov 13, 2018 | A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.key... |
| CVE-2018-14655 | MEDIUM | 4.6 | 1.2% | Nov 13, 2018 | A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible ... |
| CVE-2018-1808 | MEDIUM | 4.3 | 1.6% | Nov 13, 2018 | IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input contr... |
| CVE-2018-15452 | MEDIUM | 5.5 | 0.3% | Nov 13, 2018 | A vulnerability in the DLL loading component of Cisco Advanced Malware Protection (AMP) for Endpoints on Windows could a... |
| CVE-2018-18591 | MEDIUM | 6.8 | 1.0% | Nov 13, 2018 | A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9... |
| CVE-2018-19217 | MEDIUM | 6.5 | 1.1% | Nov 12, 2018 | In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to... |
| CVE-2018-19211 | MEDIUM | 5.5 | 0.9% | Nov 12, 2018 | In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a den... |
| CVE-2018-19208 | MEDIUM | 6.5 | 1.5% | Nov 12, 2018 | In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListe... |
| CVE-2018-1884 | MEDIUM | 4.8 | 2.7% | Nov 12, 2018 | IBM Case Manager 5.2.0.0, 5.2.0.4, 5.2.1.0, 5.2.1.7, 5.3.0.0, and 5.3.3.0 is vulnerable to a "zip slip" vulnerability wh... |
| CVE-2018-1798 | MEDIUM | 6.1 | 1.5% | Nov 12, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2018-1786 | MEDIUM | 5.3 | 2.4% | Nov 12, 2018 | IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. ... |
| CVE-2018-14644 | MEDIUM | 5.3 | 4.8% | Nov 9, 2018 | An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query... |
| CVE-2018-1872 | MEDIUM | 5.4 | 1.0% | Nov 9, 2018 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now