2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10606 | HIGH | 8.8 | 1.9% | Sep 26, 2018 | WECON LeviStudio Versions 1.8.29 and 1.8.44 have multiple heap-based buffer overflow vulnerabilities that can be exploit... |
| CVE-2018-10602 | HIGH | 8.8 | 1.9% | Sep 26, 2018 | WECON LeviStudio Versions 1.8.29 and 1.8.44 have multiple stack-based buffer overflow vulnerabilities that can be exploi... |
| CVE-2018-16672 | MEDIUM | 6.5 | 1.7% | Sep 26, 2018 | An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elemen... |
| CVE-2018-15606 | — | — | 0.6% | Sep 26, 2018 | An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an ... |
| CVE-2018-7355 | — | — | 1.9% | Sep 26, 2018 | All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scrip... |
| CVE-2018-1785 | HIGH | 7.5 | 1.1% | Sep 26, 2018 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that co... |
| CVE-2018-1768 | MEDIUM | 5.6 | 0.4% | Sep 26, 2018 | IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test... |
| CVE-2018-1683 | MEDIUM | 5.9 | 2.0% | Sep 26, 2018 | IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the fa... |
| CVE-2018-1610 | MEDIUM | 5.4 | 0.7% | Sep 26, 2018 | IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This ... |
| CVE-2018-1550 | MEDIUM | 6.2 | 0.3% | Sep 26, 2018 | IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would c... |
| CVE-2018-1545 | HIGH | 7.5 | 1.0% | Sep 26, 2018 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that co... |
| CVE-2018-7907 | — | — | 0.7% | Sep 26, 2018 | Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, A... |
| CVE-2018-3972 | CRITICAL | 9.8 | 3.7% | Sep 26, 2018 | An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as us... |
| CVE-2018-17538 | — | — | 2.5% | Sep 26, 2018 | Axon (formerly TASER International) Evidence Sync 3.15.89 is vulnerable to process injection. NOTE: the vendor's positio... |
| CVE-2018-14634 | HIGH | 7.8 | 14.8% | Sep 25, 2018 | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a... |
| CVE-2018-11763 | — | — | 51.0% | Sep 25, 2018 | In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, s... |
| CVE-2018-1669 | HIGH | 7.1 | 1.9% | Sep 25, 2018 | IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15... |
| CVE-2018-1664 | MEDIUM | 6.2 | 0.4% | Sep 25, 2018 | IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15... |
| CVE-2018-1659 | MEDIUM | 5.4 | 0.7% | Sep 25, 2018 | IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting.... |
| CVE-2018-1607 | HIGH | 7.1 | 1.9% | Sep 25, 2018 | IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity... |
| CVE-2018-1588 | HIGH | 7.1 | 1.9% | Sep 25, 2018 | IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to... |
| CVE-2018-1560 | MEDIUM | 5.4 | 0.7% | Sep 25, 2018 | IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting.... |
| CVE-2018-1539 | MEDIUM | 5.4 | 1.3% | Sep 25, 2018 | IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass... |
| CVE-2018-6119 | — | — | 0.9% | Sep 25, 2018 | Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents... |
| CVE-2018-6055 | — | — | 1.1% | Sep 25, 2018 | Insufficient policy enforcement in Catalog Service in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now