2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1447MEDIUM5.1The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic f...
CVE-2018-3689MEDIUM5.5AESM daemon in Intel Software Guard Extensions Platform Software Component for Linux before 2.1.102 can effectively be d...
CVE-2018-6660MEDIUM6.2Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrato...
CVE-2018-1094MEDIUM5.5The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32...
CVE-2018-3821MEDIUM6.1Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud v...
CVE-2018-3820MEDIUM6.1Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that ...
CVE-2018-3741MEDIUM6.1There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-...
CVE-2018-1390MEDIUM5.4IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is vulnerable to cross-s...
CVE-2018-1384MEDIUM5.4IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2018-6588MEDIUM6.1CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to th...
CVE-2018-6587MEDIUM6.1CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to th...
CVE-2018-6586MEDIUM6.1CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profi...
CVE-2018-0196MEDIUM4.9A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote a...
CVE-2018-0180MEDIUM5.9Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenti...
CVE-2018-0179MEDIUM5.9Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenti...
CVE-2018-0163MEDIUM6.5A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthen...
CVE-2018-0161MEDIUM6.3A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain mode...
CVE-2018-7196MEDIUM6.1Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers...
CVE-2018-7194MEDIUM4.9Integer format vulnerability in the ticket number generator in Enhancesoft osTicket before 1.10.2 allows remote attacker...
CVE-2018-7193MEDIUM6.1Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attac...
CVE-2018-7192MEDIUM6.1Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remot...
CVE-2018-6882MEDIUM6.1Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Sui...
CVE-2018-0198MEDIUM5.3A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote atta...
CVE-2018-7673MEDIUM5.1The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.
CVE-2018-1348MEDIUM5.3NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now