2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-7543MEDIUM6.1Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for...
CVE-2018-8976MEDIUM6.5In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringForma...
CVE-2018-1000139MEDIUM6.1I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php...
CVE-2018-1429MEDIUM5.4IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2018-1428MEDIUM6.2IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algori...
CVE-2018-1427MEDIUM6.2IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) contains several environment variables that a ...
CVE-2018-7519MEDIUM5.3In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a heap-based buffer overflow.
CVE-2018-7515MEDIUM5.3In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX...
CVE-2018-7513MEDIUM5.3In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a stack-based buffer overflow.
CVE-2018-1347MEDIUM5.3The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site script...
CVE-2018-1345MEDIUM5.9NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack...
CVE-2018-4844MEDIUM6.7A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI fo...
CVE-2018-4843MEDIUM6.5A vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 4...
CVE-2018-8770MEDIUM5.3Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, contro...
CVE-2018-8754MEDIUM5.5The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly c...
CVE-2018-1199MEDIUM5.3Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4....
CVE-2018-1068MEDIUM6.7A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privi...
CVE-2018-1324MEDIUM5.5A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field par...
CVE-2018-2401MEDIUM5.4SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrust...
CVE-2018-2399MEDIUM6.1Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to ineff...
CVE-2018-2397MEDIUM5.4In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) doe...
CVE-2018-2366MEDIUM4.3SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of pat...
CVE-2018-8099MEDIUM6.5Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26...
CVE-2018-8098MEDIUM6.5Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v...
CVE-2018-1444MEDIUM5.4IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now