2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1447 | MEDIUM | 5.1 | 0.9% | Apr 4, 2018 | The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic f... |
| CVE-2018-3689 | MEDIUM | 5.5 | 0.2% | Apr 3, 2018 | AESM daemon in Intel Software Guard Extensions Platform Software Component for Linux before 2.1.102 can effectively be d... |
| CVE-2018-6660 | MEDIUM | 6.2 | 1.7% | Apr 2, 2018 | Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrato... |
| CVE-2018-1094 | MEDIUM | 5.5 | 2.1% | Apr 2, 2018 | The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32... |
| CVE-2018-3821 | MEDIUM | 6.1 | 0.7% | Mar 30, 2018 | Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud v... |
| CVE-2018-3820 | MEDIUM | 6.1 | 0.7% | Mar 30, 2018 | Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that ... |
| CVE-2018-3741 | MEDIUM | 6.1 | 1.2% | Mar 30, 2018 | There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-... |
| CVE-2018-1390 | MEDIUM | 5.4 | 1.0% | Mar 30, 2018 | IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is vulnerable to cross-s... |
| CVE-2018-1384 | MEDIUM | 5.4 | 1.1% | Mar 30, 2018 | IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2018-6588 | MEDIUM | 6.1 | 0.9% | Mar 29, 2018 | CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to th... |
| CVE-2018-6587 | MEDIUM | 6.1 | 0.9% | Mar 29, 2018 | CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to th... |
| CVE-2018-6586 | MEDIUM | 6.1 | 0.9% | Mar 29, 2018 | CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profi... |
| CVE-2018-0196 | MEDIUM | 4.9 | 1.0% | Mar 28, 2018 | A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote a... |
| CVE-2018-0180 | MEDIUM | 5.9 | 5.1% | Mar 28, 2018 | Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenti... |
| CVE-2018-0179 | MEDIUM | 5.9 | 5.1% | Mar 28, 2018 | Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenti... |
| CVE-2018-0163 | MEDIUM | 6.5 | 0.7% | Mar 28, 2018 | A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthen... |
| CVE-2018-0161 | MEDIUM | 6.3 | 4.2% | Mar 28, 2018 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain mode... |
| CVE-2018-7196 | MEDIUM | 6.1 | 2.5% | Mar 27, 2018 | Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers... |
| CVE-2018-7194 | MEDIUM | 4.9 | 1.3% | Mar 27, 2018 | Integer format vulnerability in the ticket number generator in Enhancesoft osTicket before 1.10.2 allows remote attacker... |
| CVE-2018-7193 | MEDIUM | 6.1 | 2.5% | Mar 27, 2018 | Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attac... |
| CVE-2018-7192 | MEDIUM | 6.1 | 2.1% | Mar 27, 2018 | Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remot... |
| CVE-2018-6882 | MEDIUM | 6.1 | 25.4% | Mar 27, 2018 | Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Sui... |
| CVE-2018-0198 | MEDIUM | 5.3 | 1.8% | Mar 27, 2018 | A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote atta... |
| CVE-2018-7673 | MEDIUM | 5.1 | 0.8% | Mar 26, 2018 | The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack. |
| CVE-2018-1348 | MEDIUM | 5.3 | 1.1% | Mar 26, 2018 | NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now