2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7543 | MEDIUM | 6.1 | 3.5% | Mar 26, 2018 | Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for... |
| CVE-2018-8976 | MEDIUM | 6.5 | 2.1% | Mar 25, 2018 | In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringForma... |
| CVE-2018-1000139 | MEDIUM | 6.1 | 0.9% | Mar 23, 2018 | I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php... |
| CVE-2018-1429 | MEDIUM | 5.4 | 1.1% | Mar 23, 2018 | IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2018-1428 | MEDIUM | 6.2 | 0.3% | Mar 22, 2018 | IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algori... |
| CVE-2018-1427 | MEDIUM | 6.2 | 0.5% | Mar 22, 2018 | IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) contains several environment variables that a ... |
| CVE-2018-7519 | MEDIUM | 5.3 | 0.4% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a heap-based buffer overflow. |
| CVE-2018-7515 | MEDIUM | 5.3 | 0.3% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX... |
| CVE-2018-7513 | MEDIUM | 5.3 | 0.4% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a stack-based buffer overflow. |
| CVE-2018-1347 | MEDIUM | 5.3 | 0.7% | Mar 21, 2018 | The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site script... |
| CVE-2018-1345 | MEDIUM | 5.9 | 0.7% | Mar 21, 2018 | NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack... |
| CVE-2018-4844 | MEDIUM | 6.7 | 0.4% | Mar 20, 2018 | A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI fo... |
| CVE-2018-4843 | MEDIUM | 6.5 | 0.5% | Mar 20, 2018 | A vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 4... |
| CVE-2018-8770 | MEDIUM | 5.3 | 60.6% | Mar 18, 2018 | Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, contro... |
| CVE-2018-8754 | MEDIUM | 5.5 | 0.3% | Mar 18, 2018 | The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly c... |
| CVE-2018-1199 | MEDIUM | 5.3 | 2.9% | Mar 16, 2018 | Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.... |
| CVE-2018-1068 | MEDIUM | 6.7 | 0.5% | Mar 16, 2018 | A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privi... |
| CVE-2018-1324 | MEDIUM | 5.5 | 3.7% | Mar 16, 2018 | A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field par... |
| CVE-2018-2401 | MEDIUM | 5.4 | 1.7% | Mar 14, 2018 | SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrust... |
| CVE-2018-2399 | MEDIUM | 6.1 | 1.3% | Mar 14, 2018 | Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to ineff... |
| CVE-2018-2397 | MEDIUM | 5.4 | 1.0% | Mar 14, 2018 | In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) doe... |
| CVE-2018-2366 | MEDIUM | 4.3 | 1.6% | Mar 14, 2018 | SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of pat... |
| CVE-2018-8099 | MEDIUM | 6.5 | 1.4% | Mar 14, 2018 | Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26... |
| CVE-2018-8098 | MEDIUM | 6.5 | 1.4% | Mar 14, 2018 | Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v... |
| CVE-2018-1444 | MEDIUM | 5.4 | 1.0% | Mar 14, 2018 | IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now