2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1558 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scri... |
| CVE-2018-1557 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1522 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1498 | MEDIUM | 6.2 | 0.4% | Oct 2, 2018 | IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. I... |
| CVE-2018-1440 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1439 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1405 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1404 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1403 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1395 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-9069 | MEDIUM | 5.9 | 0.5% | Oct 2, 2018 | In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adeq... |
| CVE-2018-1672 | MEDIUM | 5 | 1.2% | Oct 1, 2018 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios,... |
| CVE-2018-1420 | MEDIUM | 5.3 | 1.3% | Oct 1, 2018 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Co... |
| CVE-2018-17218 | MEDIUM | 5.4 | 0.6% | Oct 1, 2018 | An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is reflected XSS in the SQUEAL search function. |
| CVE-2018-1250 | MEDIUM | 6.5 | 1.6% | Sep 28, 2018 | Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote ... |
| CVE-2018-1246 | MEDIUM | 4.7 | 1.1% | Sep 28, 2018 | Dell EMC Unity and UnityVSA contains reflected cross-site scripting vulnerability. A remote unauthenticated attacker cou... |
| CVE-2018-11075 | MEDIUM | 5.8 | 1.5% | Sep 28, 2018 | RSA Authentication Manager versions prior to 8.3 P3 contain a reflected cross-site scripting vulnerability in a Security... |
| CVE-2018-11074 | MEDIUM | 6.1 | 2.0% | Sep 28, 2018 | RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which... |
| CVE-2018-11073 | MEDIUM | 6.5 | 1.1% | Sep 28, 2018 | RSA Authentication Manager versions prior to 8.3 P3 contain a stored cross-site scripting vulnerability in the Operation... |
| CVE-2018-1704 | MEDIUM | 6.8 | 0.7% | Sep 28, 2018 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker... |
| CVE-2018-17581 | MEDIUM | 6.5 | 2.4% | Sep 28, 2018 | CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive func... |
| CVE-2018-15611 | MEDIUM | 6.3 | 0.3% | Sep 27, 2018 | A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authentica... |
| CVE-2018-14650 | MEDIUM | 5.9 | 0.4% | Sep 27, 2018 | It was discovered that sos-collector does not properly set the default permissions of newly created files, making all fi... |
| CVE-2018-1820 | MEDIUM | 5.4 | 1.0% | Sep 27, 2018 | IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2018-1716 | MEDIUM | 6.1 | 1.3% | Sep 27, 2018 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to em... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now