2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1999007 | MEDIUM | 5.4 | 0.9% | Jul 23, 2018 | A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewo... |
| CVE-2018-1999005 | MEDIUM | 5.4 | 0.9% | Jul 23, 2018 | A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.jav... |
| CVE-2018-1999004 | MEDIUM | 4.3 | 0.9% | Jul 23, 2018 | A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java th... |
| CVE-2018-1999003 | MEDIUM | 4.3 | 0.8% | Jul 23, 2018 | A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allow... |
| CVE-2018-1513 | MEDIUM | 5.4 | 2.9% | Jul 23, 2018 | IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2018-1503 | MEDIUM | 4.3 | 2.0% | Jul 23, 2018 | IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a remotely authenticated attacker to to send invalid or malformed headers... |
| CVE-2018-14512 | MEDIUM | 6.1 | 1.1% | Jul 23, 2018 | An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject a... |
| CVE-2018-14500 | MEDIUM | 6.1 | 0.8% | Jul 22, 2018 | joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter. |
| CVE-2018-3771 | MEDIUM | 6.1 | 0.9% | Jul 20, 2018 | An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory... |
| CVE-2018-3770 | MEDIUM | 5.5 | 0.5% | Jul 20, 2018 | A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can resul... |
| CVE-2018-1679 | MEDIUM | 5.3 | 1.8% | Jul 20, 2018 | IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user to obtain sensitive i... |
| CVE-2018-1564 | MEDIUM | 4.4 | 0.4% | Jul 20, 2018 | IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow a local user with administrator privileges to... |
| CVE-2018-1563 | MEDIUM | 5.4 | 2.8% | Jul 20, 2018 | IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site... |
| CVE-2018-1470 | MEDIUM | 4.3 | 1.8% | Jul 20, 2018 | IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive informatio... |
| CVE-2018-1398 | MEDIUM | 5.3 | 2.4% | Jul 20, 2018 | IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain... |
| CVE-2018-9062 | MEDIUM | 6.8 | 0.5% | Jul 19, 2018 | In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrar... |
| CVE-2018-1587 | MEDIUM | 4.3 | 1.0% | Jul 19, 2018 | IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design ... |
| CVE-2018-1585 | MEDIUM | 5.4 | 0.7% | Jul 19, 2018 | IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design ... |
| CVE-2018-1536 | MEDIUM | 5.4 | 0.7% | Jul 19, 2018 | IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design ... |
| CVE-2018-1535 | MEDIUM | 5.4 | 0.7% | Jul 19, 2018 | IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design ... |
| CVE-2018-14404 | MEDIUM | 6.5 | 3.7% | Jul 19, 2018 | A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 wh... |
| CVE-2018-14395 | MEDIUM | 6.5 | 2.0% | Jul 19, 2018 | libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial of service (application crash caused by ... |
| CVE-2018-3081 | MEDIUM | 5 | 2.4% | Jul 18, 2018 | Vulnerability in the MySQL Client component of Oracle MySQL (subcomponent: Client programs). Supported versions that are... |
| CVE-2018-3080 | MEDIUM | 4.9 | 2.0% | Jul 18, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are aff... |
| CVE-2018-3079 | MEDIUM | 4.9 | 2.0% | Jul 18, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now