2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1455MEDIUM4.3IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which coul...
CVE-2018-3646MEDIUM5.6Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure ...
CVE-2018-3620MEDIUM5.6Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure ...
CVE-2018-14781MEDIUM5.3Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” opti...
CVE-2018-10634MEDIUM4.8Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently...
CVE-2018-10864MEDIUM5.3An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A...
CVE-2018-11770MEDIUM4.2From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su...
CVE-2018-3776MEDIUM5.3Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being lo...
CVE-2018-10626MEDIUM4.4Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded...
CVE-2018-10622MEDIUM5.2Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c...
CVE-2018-10908MEDIUM6.5It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By upload...
CVE-2018-3778MEDIUM5.3Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
CVE-2018-15203MEDIUM6.5An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to ad...
CVE-2018-5383MEDIUM6.8Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions bef...
CVE-2018-5953MEDIUM5.5The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensit...
CVE-2018-1690MEDIUM5.4IBM Rhapsody Model Manager 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2018-1528MEDIUM4.3IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the...
CVE-2018-1422MEDIUM5.4IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable...
CVE-2018-14773MEDIUM6.5An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, ...
CVE-2018-6590MEDIUM6.1CA API Developer Portal 4.x, prior to v4.2.5.3 and v4.2.7.1, has an unspecified reflected cross-site scripting vulnerabi...
CVE-2018-1155MEDIUM5.4In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to i...
CVE-2018-10921MEDIUM4.3Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially le...
CVE-2018-1554MEDIUM5.4IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2018-8032MEDIUM6.1Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/serv...
CVE-2018-10920MEDIUM6.8Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison c...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now