2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1455 | MEDIUM | 4.3 | 0.8% | Aug 15, 2018 | IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which coul... |
| CVE-2018-3646 | MEDIUM | 5.6 | 8.1% | Aug 14, 2018 | Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure ... |
| CVE-2018-3620 | MEDIUM | 5.6 | 5.6% | Aug 14, 2018 | Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure ... |
| CVE-2018-14781 | MEDIUM | 5.3 | 0.7% | Aug 13, 2018 | Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” opti... |
| CVE-2018-10634 | MEDIUM | 4.8 | 0.5% | Aug 13, 2018 | Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently... |
| CVE-2018-10864 | MEDIUM | 5.3 | 1.2% | Aug 13, 2018 | An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A... |
| CVE-2018-11770 | MEDIUM | 4.2 | 65.9% | Aug 13, 2018 | From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su... |
| CVE-2018-3776 | MEDIUM | 5.3 | 1.3% | Aug 12, 2018 | Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being lo... |
| CVE-2018-10626 | MEDIUM | 4.4 | 0.4% | Aug 10, 2018 | Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded... |
| CVE-2018-10622 | MEDIUM | 5.2 | 0.4% | Aug 10, 2018 | Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c... |
| CVE-2018-10908 | MEDIUM | 6.5 | 1.2% | Aug 9, 2018 | It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By upload... |
| CVE-2018-3778 | MEDIUM | 5.3 | 1.4% | Aug 8, 2018 | Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized. |
| CVE-2018-15203 | MEDIUM | 6.5 | 0.4% | Aug 8, 2018 | An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to ad... |
| CVE-2018-5383 | MEDIUM | 6.8 | 0.8% | Aug 7, 2018 | Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions bef... |
| CVE-2018-5953 | MEDIUM | 5.5 | 0.4% | Aug 7, 2018 | The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensit... |
| CVE-2018-1690 | MEDIUM | 5.4 | 0.7% | Aug 7, 2018 | IBM Rhapsody Model Manager 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2018-1528 | MEDIUM | 4.3 | 1.3% | Aug 6, 2018 | IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the... |
| CVE-2018-1422 | MEDIUM | 5.4 | 1.0% | Aug 6, 2018 | IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable... |
| CVE-2018-14773 | MEDIUM | 6.5 | 58.1% | Aug 3, 2018 | An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, ... |
| CVE-2018-6590 | MEDIUM | 6.1 | 0.7% | Aug 3, 2018 | CA API Developer Portal 4.x, prior to v4.2.5.3 and v4.2.7.1, has an unspecified reflected cross-site scripting vulnerabi... |
| CVE-2018-10921 | MEDIUM | 4.3 | 1.0% | Aug 2, 2018 | Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially le... |
| CVE-2018-1554 | MEDIUM | 5.4 | 1.0% | Aug 2, 2018 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2018-8032 | MEDIUM | 6.1 | 10.6% | Aug 2, 2018 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/serv... |
| CVE-2018-10920 | MEDIUM | 6.8 | 3.2% | Aug 2, 2018 | Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison c... |
| CVE-2018-10894 | MEDIUM | 5.4 | 0.4% | Aug 1, 2018 | It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A maliciou... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now