2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1455MEDIUM4.3IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which coul...
CVE-2018-3646MEDIUM5.6Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure ...
CVE-2018-3620MEDIUM5.6Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure ...
CVE-2018-14781MEDIUM5.3Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” opti...
CVE-2018-10634MEDIUM4.8Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently...
CVE-2018-10864MEDIUM5.3An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A...
CVE-2018-11770MEDIUM4.2From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su...
CVE-2018-3776MEDIUM5.3Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being lo...
CVE-2018-10626MEDIUM4.4Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded...
CVE-2018-10622MEDIUM5.2Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c...
CVE-2018-10908MEDIUM6.5It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By upload...
CVE-2018-3778MEDIUM5.3Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
CVE-2018-15203MEDIUM6.5An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to ad...
CVE-2018-5383MEDIUM6.8Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions bef...
CVE-2018-5953MEDIUM5.5The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensit...
CVE-2018-1690MEDIUM5.4IBM Rhapsody Model Manager 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2018-1528MEDIUM4.3IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the...
CVE-2018-1422MEDIUM5.4IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable...
CVE-2018-14773MEDIUM6.5An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, ...
CVE-2018-6590MEDIUM6.1CA API Developer Portal 4.x, prior to v4.2.5.3 and v4.2.7.1, has an unspecified reflected cross-site scripting vulnerabi...
CVE-2018-10921MEDIUM4.3Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially le...
CVE-2018-1554MEDIUM5.4IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2018-8032MEDIUM6.1Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/serv...
CVE-2018-10920MEDIUM6.8Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison c...
CVE-2018-10894MEDIUM5.4It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A maliciou...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now