2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1705 | MEDIUM | 6.5 | 1.3% | Aug 28, 2018 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclo... |
| CVE-2018-15919 | MEDIUM | 5.3 | 3.6% | Aug 28, 2018 | Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existenc... |
| CVE-2018-3927 | MEDIUM | 6.8 | 1.1% | Aug 27, 2018 | An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung Sma... |
| CVE-2018-15875 | MEDIUM | 6.1 | 1.2% | Aug 25, 2018 | Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the ... |
| CVE-2018-15874 | MEDIUM | 6.1 | 1.2% | Aug 25, 2018 | Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into th... |
| CVE-2018-15120 | MEDIUM | 6.5 | 11.5% | Aug 24, 2018 | libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denia... |
| CVE-2018-1755 | MEDIUM | 5.9 | 3.5% | Aug 24, 2018 | IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorr... |
| CVE-2018-1699 | MEDIUM | 6.3 | 1.7% | Aug 24, 2018 | IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection. A remote attacker could send specially-cra... |
| CVE-2018-14789 | MEDIUM | 6.7 | 0.4% | Aug 22, 2018 | In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an... |
| CVE-2018-10919 | MEDIUM | 4.3 | 2.2% | Aug 22, 2018 | The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access contro... |
| CVE-2018-10918 | MEDIUM | 5.2 | 2.5% | Aug 22, 2018 | A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An auth... |
| CVE-2018-10858 | MEDIUM | 4.3 | 4.3% | Aug 22, 2018 | A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malici... |
| CVE-2018-1140 | MEDIUM | 6.5 | 10.8% | Aug 22, 2018 | A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker ... |
| CVE-2018-10846 | MEDIUM | 5.6 | 0.4% | Aug 22, 2018 | A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was fou... |
| CVE-2018-10845 | MEDIUM | 5.9 | 3.6% | Aug 22, 2018 | It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote atta... |
| CVE-2018-10844 | MEDIUM | 5.9 | 3.6% | Aug 22, 2018 | It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote atta... |
| CVE-2018-1599 | MEDIUM | 5.4 | 0.8% | Aug 22, 2018 | IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By pe... |
| CVE-2018-10932 | MEDIUM | 4.3 | 1.0% | Aug 21, 2018 | lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is dis... |
| CVE-2018-1517 | MEDIUM | 5.9 | 4.0% | Aug 20, 2018 | A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict... |
| CVE-2018-1394 | MEDIUM | 5.4 | 0.7% | Aug 20, 2018 | Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2018-15574 | MEDIUM | 6.1 | 0.8% | Aug 20, 2018 | An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scrip... |
| CVE-2018-15473 | MEDIUM | 5.3 | 98.6% | Aug 17, 2018 | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati... |
| CVE-2018-11771 | MEDIUM | 5.5 | 5.3% | Aug 16, 2018 | When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputSt... |
| CVE-2018-1715 | MEDIUM | 5.4 | 0.7% | Aug 16, 2018 | IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to ... |
| CVE-2018-10917 | MEDIUM | 6.8 | 1.1% | Aug 15, 2018 | pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repos... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now