2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1841MEDIUM6.2IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/mas...
CVE-2018-7363MEDIUM4.3All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since app...
CVE-2018-7361MEDIUM6.5All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by null pointer dereference vulnerability, which m...
CVE-2018-1797MEDIUM6.3IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attac...
CVE-2018-1639MEDIUM4.3The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user t...
CVE-2018-5407MEDIUM4.7Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks...
CVE-2018-1643MEDIUM6.1The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-sit...
CVE-2018-19289MEDIUM6.1An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via ...
CVE-2018-19286MEDIUM6.1The server in mubu note 2018-11-11 has XSS by configuring an account with a crafted name value (along with an arbitrary ...
CVE-2018-7358MEDIUM6.5ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper cha...
CVE-2018-7357MEDIUM6.5ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper acc...
CVE-2018-8568MEDIUM5.4An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c...
CVE-2018-14658MEDIUM6.1A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.key...
CVE-2018-14655MEDIUM4.6A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible ...
CVE-2018-1808MEDIUM4.3IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input contr...
CVE-2018-15452MEDIUM5.5A vulnerability in the DLL loading component of Cisco Advanced Malware Protection (AMP) for Endpoints on Windows could a...
CVE-2018-18591MEDIUM6.8A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9...
CVE-2018-19217MEDIUM6.5In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to...
CVE-2018-19211MEDIUM5.5In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a den...
CVE-2018-19208MEDIUM6.5In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListe...
CVE-2018-1884MEDIUM4.8IBM Case Manager 5.2.0.0, 5.2.0.4, 5.2.1.0, 5.2.1.7, 5.3.0.0, and 5.3.3.0 is vulnerable to a "zip slip" vulnerability wh...
CVE-2018-1798MEDIUM6.1IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows...
CVE-2018-1786MEDIUM5.3IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. ...
CVE-2018-14644MEDIUM5.3An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query...
CVE-2018-1872MEDIUM5.4IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now