2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1541MEDIUM5.4IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users ...
CVE-2018-18589MEDIUM6.3A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring softw...
CVE-2018-18585MEDIUM4.3chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second ...
CVE-2018-18584MEDIUM6.5In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small...
CVE-2018-18545MEDIUM6.1Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter.
CVE-2018-18521MEDIUM5.5Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers t...
CVE-2018-18520MEDIUM6.5An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-s...
CVE-2018-11079MEDIUM5.5Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Data...
CVE-2018-1518MEDIUM6.2IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local ...
CVE-2018-15438MEDIUM6.5A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthentica...
CVE-2018-0420MEDIUM6.5A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remot...
CVE-2018-0381MEDIUM6.8A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker...
CVE-2018-15435MEDIUM6.1A vulnerability in the web-based management interface of Cisco SocialMiner could allow an unauthenticated, remote attack...
CVE-2018-15402MEDIUM5.4A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker ...
CVE-2018-15395MEDIUM5.4A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Softw...
CVE-2018-0416MEDIUM5.3A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticate...
CVE-2018-0388MEDIUM4.8A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated,...
CVE-2018-3286MEDIUM4.3Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported vers...
CVE-2018-3285MEDIUM4.9Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Windows). Supported versions that are...
CVE-2018-3284MEDIUM4.4Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected...
CVE-2018-3282MEDIUM4.9Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Storage Engines). Supported versions ...
CVE-2018-3280MEDIUM4.9Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: JSON). Supported versions that are af...
CVE-2018-3279MEDIUM4.9Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Supported versions ...
CVE-2018-3277MEDIUM4.9Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected...
CVE-2018-3251MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now