2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1558MEDIUM5.4IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scri...
CVE-2018-1557MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1522MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1498MEDIUM6.2IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. I...
CVE-2018-1440MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1439MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1405MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1404MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1403MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-1395MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2018-9069MEDIUM5.9In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adeq...
CVE-2018-1672MEDIUM5IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios,...
CVE-2018-1420MEDIUM5.3IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Co...
CVE-2018-17218MEDIUM5.4An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is reflected XSS in the SQUEAL search function.
CVE-2018-1250MEDIUM6.5Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote ...
CVE-2018-1246MEDIUM4.7Dell EMC Unity and UnityVSA contains reflected cross-site scripting vulnerability. A remote unauthenticated attacker cou...
CVE-2018-11075MEDIUM5.8RSA Authentication Manager versions prior to 8.3 P3 contain a reflected cross-site scripting vulnerability in a Security...
CVE-2018-11074MEDIUM6.1RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which...
CVE-2018-11073MEDIUM6.5RSA Authentication Manager versions prior to 8.3 P3 contain a stored cross-site scripting vulnerability in the Operation...
CVE-2018-1704MEDIUM6.8IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker...
CVE-2018-17581MEDIUM6.5CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive func...
CVE-2018-15611MEDIUM6.3A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authentica...
CVE-2018-14650MEDIUM5.9It was discovered that sos-collector does not properly set the default permissions of newly created files, making all fi...
CVE-2018-1820MEDIUM5.4IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2018-1716MEDIUM6.1IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to em...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now