2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-7673MEDIUM5.1The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.
CVE-2018-1348MEDIUM5.3NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in...
CVE-2018-7543MEDIUM6.1Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for...
CVE-2018-8976MEDIUM6.5In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringForma...
CVE-2018-1000139MEDIUM6.1I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php...
CVE-2018-1429MEDIUM5.4IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2018-1428MEDIUM6.2IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algori...
CVE-2018-1427MEDIUM6.2IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) contains several environment variables that a ...
CVE-2018-7519MEDIUM5.3In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a heap-based buffer overflow.
CVE-2018-7515MEDIUM5.3In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX...
CVE-2018-7513MEDIUM5.3In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a stack-based buffer overflow.
CVE-2018-1347MEDIUM5.3The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site script...
CVE-2018-1345MEDIUM5.9NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack...
CVE-2018-4844MEDIUM6.7A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI fo...
CVE-2018-4843MEDIUM6.5A vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 4...
CVE-2018-8770MEDIUM5.3Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, contro...
CVE-2018-8754MEDIUM5.5The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly c...
CVE-2018-1199MEDIUM5.3Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4....
CVE-2018-1068MEDIUM6.7A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privi...
CVE-2018-1324MEDIUM5.5A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field par...
CVE-2018-2401MEDIUM5.4SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrust...
CVE-2018-2399MEDIUM6.1Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to ineff...
CVE-2018-2397MEDIUM5.4In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) doe...
CVE-2018-2366MEDIUM4.3SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of pat...
CVE-2018-8099MEDIUM6.5Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now