2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1660 | MEDIUM | 5.4 | 1.1% | Sep 27, 2018 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to em... |
| CVE-2018-16672 | MEDIUM | 6.5 | 1.7% | Sep 26, 2018 | An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elemen... |
| CVE-2018-1768 | MEDIUM | 5.6 | 0.4% | Sep 26, 2018 | IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test... |
| CVE-2018-1683 | MEDIUM | 5.9 | 2.0% | Sep 26, 2018 | IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the fa... |
| CVE-2018-1610 | MEDIUM | 5.4 | 0.7% | Sep 26, 2018 | IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This ... |
| CVE-2018-1550 | MEDIUM | 6.2 | 0.3% | Sep 26, 2018 | IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would c... |
| CVE-2018-1664 | MEDIUM | 6.2 | 0.4% | Sep 25, 2018 | IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15... |
| CVE-2018-1659 | MEDIUM | 5.4 | 0.7% | Sep 25, 2018 | IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting.... |
| CVE-2018-1560 | MEDIUM | 5.4 | 0.7% | Sep 25, 2018 | IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting.... |
| CVE-2018-1539 | MEDIUM | 5.4 | 1.3% | Sep 25, 2018 | IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass... |
| CVE-2018-15963 | MEDIUM | 5.3 | 5.7% | Sep 25, 2018 | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a secu... |
| CVE-2018-15962 | MEDIUM | 5.3 | 5.5% | Sep 25, 2018 | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a dire... |
| CVE-2018-6682 | MEDIUM | 6.1 | 0.7% | Sep 24, 2018 | Cross Site Scripting Exposure in McAfee True Key (TK) 4.0.0.0 and earlier allows local users to expose confidential data... |
| CVE-2018-3913 | MEDIUM | 6.7 | 0.4% | Sep 21, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT... |
| CVE-2018-17300 | MEDIUM | 4.8 | 0.6% | Sep 21, 2018 | Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section na... |
| CVE-2018-6503 | MEDIUM | 6.5 | 1.1% | Sep 20, 2018 | A potential Access Control vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior... |
| CVE-2018-6502 | MEDIUM | 6.5 | 1.3% | Sep 20, 2018 | A potential Reflected Cross-Site Scripting (XSS) Security vulnerability has been identified in ArcSight Management Cente... |
| CVE-2018-1800 | MEDIUM | 5.1 | 0.3% | Sep 20, 2018 | IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive inf... |
| CVE-2018-1674 | MEDIUM | 6.3 | 1.7% | Sep 20, 2018 | IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote att... |
| CVE-2018-3830 | MEDIUM | 6.1 | 1.9% | Sep 19, 2018 | Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could ... |
| CVE-2018-3829 | MEDIUM | 5.3 | 0.8% | Sep 19, 2018 | In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on ne... |
| CVE-2018-3823 | MEDIUM | 5.4 | 0.6% | Sep 19, 2018 | X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manag... |
| CVE-2018-17206 | MEDIUM | 4.9 | 2.0% | Sep 19, 2018 | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c i... |
| CVE-2018-17204 | MEDIUM | 4.3 | 1.9% | Sep 19, 2018 | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in li... |
| CVE-2018-1782 | MEDIUM | 6.5 | 0.3% | Sep 19, 2018 | IBM GPFS (IBM Spectrum Scale 5.0.1.0 and 5.0.1.1) allows a local, unprivileged user to cause a kernel panic on a node ru... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now