2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1705MEDIUM6.5IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclo...
CVE-2018-15919MEDIUM5.3Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existenc...
CVE-2018-3927MEDIUM6.8An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung Sma...
CVE-2018-15875MEDIUM6.1Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the ...
CVE-2018-15874MEDIUM6.1Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into th...
CVE-2018-15120MEDIUM6.5libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denia...
CVE-2018-1755MEDIUM5.9IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorr...
CVE-2018-1699MEDIUM6.3IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection. A remote attacker could send specially-cra...
CVE-2018-14789MEDIUM6.7In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an...
CVE-2018-10919MEDIUM4.3The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access contro...
CVE-2018-10918MEDIUM5.2A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An auth...
CVE-2018-10858MEDIUM4.3A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malici...
CVE-2018-1140MEDIUM6.5A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker ...
CVE-2018-10846MEDIUM5.6A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was fou...
CVE-2018-10845MEDIUM5.9It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote atta...
CVE-2018-10844MEDIUM5.9It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote atta...
CVE-2018-1599MEDIUM5.4IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By pe...
CVE-2018-10932MEDIUM4.3lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is dis...
CVE-2018-1517MEDIUM5.9A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict...
CVE-2018-1394MEDIUM5.4Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2018-15574MEDIUM6.1An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scrip...
CVE-2018-15473MEDIUM5.3OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati...
CVE-2018-11771MEDIUM5.5When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputSt...
CVE-2018-1715MEDIUM5.4IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to ...
CVE-2018-10917MEDIUM6.8pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repos...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now