2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1541 | MEDIUM | 5.4 | 1.0% | Oct 24, 2018 | IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users ... |
| CVE-2018-18589 | MEDIUM | 6.3 | 1.7% | Oct 23, 2018 | A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring softw... |
| CVE-2018-18585 | MEDIUM | 4.3 | 3.1% | Oct 23, 2018 | chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second ... |
| CVE-2018-18584 | MEDIUM | 6.5 | 3.1% | Oct 23, 2018 | In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small... |
| CVE-2018-18545 | MEDIUM | 6.1 | 0.8% | Oct 21, 2018 | Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter. |
| CVE-2018-18521 | MEDIUM | 5.5 | 1.8% | Oct 19, 2018 | Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers t... |
| CVE-2018-18520 | MEDIUM | 6.5 | 2.8% | Oct 19, 2018 | An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-s... |
| CVE-2018-11079 | MEDIUM | 5.5 | 0.4% | Oct 18, 2018 | Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Data... |
| CVE-2018-1518 | MEDIUM | 6.2 | 0.2% | Oct 18, 2018 | IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local ... |
| CVE-2018-15438 | MEDIUM | 6.5 | 1.2% | Oct 17, 2018 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthentica... |
| CVE-2018-0420 | MEDIUM | 6.5 | 4.6% | Oct 17, 2018 | A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remot... |
| CVE-2018-0381 | MEDIUM | 6.8 | 0.5% | Oct 17, 2018 | A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker... |
| CVE-2018-15435 | MEDIUM | 6.1 | 1.2% | Oct 17, 2018 | A vulnerability in the web-based management interface of Cisco SocialMiner could allow an unauthenticated, remote attack... |
| CVE-2018-15402 | MEDIUM | 5.4 | 0.5% | Oct 17, 2018 | A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker ... |
| CVE-2018-15395 | MEDIUM | 5.4 | 0.6% | Oct 17, 2018 | A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Softw... |
| CVE-2018-0416 | MEDIUM | 5.3 | 2.5% | Oct 17, 2018 | A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticate... |
| CVE-2018-0388 | MEDIUM | 4.8 | 1.0% | Oct 17, 2018 | A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated,... |
| CVE-2018-3286 | MEDIUM | 4.3 | 1.4% | Oct 17, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported vers... |
| CVE-2018-3285 | MEDIUM | 4.9 | 2.1% | Oct 17, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Windows). Supported versions that are... |
| CVE-2018-3284 | MEDIUM | 4.4 | 2.3% | Oct 17, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected... |
| CVE-2018-3282 | MEDIUM | 4.9 | 4.0% | Oct 17, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Storage Engines). Supported versions ... |
| CVE-2018-3280 | MEDIUM | 4.9 | 2.1% | Oct 17, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: JSON). Supported versions that are af... |
| CVE-2018-3279 | MEDIUM | 4.9 | 2.1% | Oct 17, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Supported versions ... |
| CVE-2018-3277 | MEDIUM | 4.9 | 2.7% | Oct 17, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected... |
| CVE-2018-3251 | MEDIUM | 6.5 | 3.1% | Oct 17, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now