2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1415IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2018-1414IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted S...
CVE-2018-1392IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user ...
CVE-2018-1391IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user ...
CVE-2018-7409In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.
CVE-2018-7408An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically inst...
CVE-2018-7313SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.
CVE-2018-7287An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default ...
CVE-2018-7286An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asteris...
CVE-2018-7285A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Asterisk maintains its ow...
CVE-2018-7284A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Ce...
CVE-2018-0206A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthentic...
CVE-2018-0205A vulnerability in the User Provisioning tab in the Cisco Prime Collaboration Provisioning Tool could allow an unauthent...
CVE-2018-0204A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, rem...
CVE-2018-0203A vulnerability in the SMTP relay of Cisco Unity Connection could allow an unauthenticated, remote attacker to send unso...
CVE-2018-0201A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-...
CVE-2018-0200A vulnerability in the web-based interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacke...
CVE-2018-0199A vulnerability in Cisco Jabber Client Framework (JCF) could allow an unauthenticated, remote attacker to conduct a cros...
CVE-2018-0148A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Con...
CVE-2018-0146A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker...
CVE-2018-0145A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could all...
CVE-2018-0139HIGH8.6A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice...
CVE-2018-0130A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Softw...
CVE-2018-0124A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass...
CVE-2018-0121A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now