2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1354 | — | — | 1.7% | Jun 27, 2018 | An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, ... |
| CVE-2018-1553 | MEDIUM | 5.3 | 2.9% | Jun 27, 2018 | IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information... |
| CVE-2018-1543 | MEDIUM | 5.9 | 1.1% | Jun 27, 2018 | IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to pro... |
| CVE-2018-1507 | MEDIUM | 5.4 | 1.0% | Jun 27, 2018 | IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2018-1457 | CRITICAL | 9.8 | 2.5% | Jun 27, 2018 | An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS a... |
| CVE-2018-1306 | — | — | 43.9% | Jun 27, 2018 | The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote a... |
| CVE-2018-12919 | — | — | 0.7% | Jun 27, 2018 | In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter. |
| CVE-2018-12918 | CRITICAL | 9.8 | 1.4% | Jun 27, 2018 | In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcB_register_fields in bootstrap.c. |
| CVE-2018-12917 | — | — | 1.5% | Jun 27, 2018 | In libpbc.a in PBC through 2017-03-02, there is a heap-based buffer over-read in _pbcM_ip_new in map.c. |
| CVE-2018-12916 | — | — | 1.5% | Jun 27, 2018 | In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcP_message_default in proto.c. |
| CVE-2018-12915 | — | — | 1.5% | Jun 27, 2018 | In libpbc.a in PBC through 2017-03-02, there is a buffer over-read in calc_hash in map.c. |
| CVE-2018-12914 | — | — | 3.9% | Jun 27, 2018 | A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that conta... |
| CVE-2018-12913 | — | — | 1.5% | Jun 27, 2018 | In Miniz 2.0.7, tinfl_decompress in miniz_tinfl.c has an infinite loop because sym2 and counter can both remain equal to... |
| CVE-2018-12912 | — | — | 2.7% | Jun 27, 2018 | An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via a... |
| CVE-2018-12536 | MEDIUM | 5.3 | 4.3% | Jun 27, 2018 | In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad q... |
| CVE-2018-5437 | MEDIUM | 6.8 | 0.9% | Jun 27, 2018 | The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analys... |
| CVE-2018-5436 | MEDIUM | 6.5 | 1.0% | Jun 27, 2018 | The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO ... |
| CVE-2018-5435 | CRITICAL | 9.6 | 3.2% | Jun 27, 2018 | The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analys... |
| CVE-2018-12909 | — | — | 18.6% | Jun 27, 2018 | Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the we... |
| CVE-2018-12908 | — | — | 10.7% | Jun 27, 2018 | Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti... |
| CVE-2018-8025 | — | — | 1.8% | Jun 27, 2018 | CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP.... |
| CVE-2018-12907 | — | — | 1.3% | Jun 27, 2018 | In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to t... |
| CVE-2018-12905 | — | — | 42.2% | Jun 27, 2018 | joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions. |
| CVE-2018-12904 | — | — | 1.2% | Jun 27, 2018 | In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause... |
| CVE-2018-12903 | — | — | 0.6% | Jun 26, 2018 | In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now