2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-2486 | — | — | 0.8% | Dec 11, 2018 | SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, re... |
| CVE-2018-20064 | — | — | 2.7% | Dec 11, 2018 | doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?... |
| CVE-2018-20061 | — | — | 1.4% | Dec 11, 2018 | A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a... |
| CVE-2018-20060 | — | — | 4.5% | Dec 11, 2018 | urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., ... |
| CVE-2018-19970 | — | — | 2.6% | Dec 11, 2018 | In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a paylo... |
| CVE-2018-19969 | — | — | 1.1% | Dec 11, 2018 | phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clic... |
| CVE-2018-19968 | — | — | 3.3% | Dec 11, 2018 | An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transfor... |
| CVE-2018-18359 | — | — | 1.4% | Dec 11, 2018 | Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perfor... |
| CVE-2018-18358 | — | — | 0.4% | Dec 11, 2018 | Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the loca... |
| CVE-2018-18357 | — | — | 1.1% | Dec 11, 2018 | Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote att... |
| CVE-2018-18356 | — | — | 3.1% | Dec 11, 2018 | An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a r... |
| CVE-2018-18355 | — | — | 1.1% | Dec 11, 2018 | Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote att... |
| CVE-2018-18354 | — | — | 1.4% | Dec 11, 2018 | Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allow... |
| CVE-2018-18353 | — | — | 1.4% | Dec 11, 2018 | Failure to dismiss http auth dialogs on navigation in Network Authentication in Google Chrome on Android prior to 71.0.3... |
| CVE-2018-18352 | — | — | 1.4% | Dec 11, 2018 | Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prior to 71.0.3578.80 al... |
| CVE-2018-18351 | — | — | 2.5% | Dec 11, 2018 | Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.... |
| CVE-2018-18350 | — | — | 1.4% | Dec 11, 2018 | Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remot... |
| CVE-2018-18349 | — | — | 1.0% | Dec 11, 2018 | Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 al... |
| CVE-2018-18348 | — | — | 1.1% | Dec 11, 2018 | Incorrect handling of bidirectional domain names with RTL characters in Omnibox in Google Chrome prior to 71.0.3578.80 a... |
| CVE-2018-18347 | — | — | 1.4% | Dec 11, 2018 | Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed ... |
| CVE-2018-18346 | — | — | 1.3% | Dec 11, 2018 | Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to pre... |
| CVE-2018-18345 | — | — | 1.4% | Dec 11, 2018 | Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker who h... |
| CVE-2018-18344 | — | — | 1.5% | Dec 11, 2018 | Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.... |
| CVE-2018-18343 | — | — | 1.4% | Dec 11, 2018 | Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote a... |
| CVE-2018-18342 | — | — | 2.7% | Dec 11, 2018 | Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now