2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1660MEDIUM5.4IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2018-16672MEDIUM6.5An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elemen...
CVE-2018-1768MEDIUM5.6IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test...
CVE-2018-1683MEDIUM5.9IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the fa...
CVE-2018-1610MEDIUM5.4IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This ...
CVE-2018-1550MEDIUM6.2IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would c...
CVE-2018-1664MEDIUM6.2IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15...
CVE-2018-1659MEDIUM5.4IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting....
CVE-2018-1560MEDIUM5.4IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting....
CVE-2018-1539MEDIUM5.4IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass...
CVE-2018-15963MEDIUM5.3Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a secu...
CVE-2018-15962MEDIUM5.3Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a dire...
CVE-2018-6682MEDIUM6.1Cross Site Scripting Exposure in McAfee True Key (TK) 4.0.0.0 and earlier allows local users to expose confidential data...
CVE-2018-3913MEDIUM6.7An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT...
CVE-2018-17300MEDIUM4.8Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section na...
CVE-2018-6503MEDIUM6.5A potential Access Control vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior...
CVE-2018-6502MEDIUM6.5A potential Reflected Cross-Site Scripting (XSS) Security vulnerability has been identified in ArcSight Management Cente...
CVE-2018-1800MEDIUM5.1IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive inf...
CVE-2018-1674MEDIUM6.3IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote att...
CVE-2018-3830MEDIUM6.1Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could ...
CVE-2018-3829MEDIUM5.3In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on ne...
CVE-2018-3823MEDIUM5.4X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manag...
CVE-2018-17206MEDIUM4.9An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c i...
CVE-2018-17204MEDIUM4.3An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in li...
CVE-2018-1782MEDIUM6.5IBM GPFS (IBM Spectrum Scale 5.0.1.0 and 5.0.1.1) allows a local, unprivileged user to cause a kernel panic on a node ru...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now