2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8416 | — | — | 7.3% | Nov 14, 2018 | A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vul... |
| CVE-2018-8415 | — | — | 1.2% | Nov 14, 2018 | A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft Pow... |
| CVE-2018-8408 | — | — | 1.7% | Nov 14, 2018 | An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Wi... |
| CVE-2018-8407 | — | — | 1.7% | Nov 14, 2018 | An information disclosure vulnerability exists when "Kernel Remote Procedure Call Provider" driver improperly initialize... |
| CVE-2018-8256 | — | — | 22.6% | Nov 14, 2018 | A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft ... |
| CVE-2018-16471 | — | — | 1.8% | Nov 13, 2018 | There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data re... |
| CVE-2018-16470 | — | — | 2.0% | Nov 13, 2018 | There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause... |
| CVE-2018-8009 | — | — | 7.6% | Nov 13, 2018 | Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is ex... |
| CVE-2018-17614 | — | — | 9.3% | Nov 13, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Losant Arduino MQTT ... |
| CVE-2018-2491 | — | — | 0.8% | Nov 13, 2018 | When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to t... |
| CVE-2018-2490 | — | — | 0.7% | Nov 13, 2018 | The broadcast messages received by SAP Fiori Client are not protected by permissions. SAP Fiori Client version 1.11.5 in... |
| CVE-2018-2489 | — | — | 0.9% | Nov 13, 2018 | Locally, without any permission, an arbitrary android application could delete the SSO configuration of SAP Fiori Client... |
| CVE-2018-2488 | — | — | 0.8% | Nov 13, 2018 | It is possible for a malware application installed on an Android device to send local push notifications with an empty m... |
| CVE-2018-2487 | — | — | 1.5% | Nov 13, 2018 | SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: Whe... |
| CVE-2018-2485 | — | — | 1.2% | Nov 13, 2018 | It is possible for a malicious application or malware to execute JavaScript in a SAP Fiori application. This can include... |
| CVE-2018-2483 | — | — | 0.9% | Nov 13, 2018 | HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Man... |
| CVE-2018-2482 | — | — | 2.0% | Nov 13, 2018 | SAP Mobile Secure Android Application, Mobile-secure.apk Android client, before version 6.60.19942.0, allows an attacker... |
| CVE-2018-2481 | — | — | 1.5% | Nov 13, 2018 | In some SAP standard roles, in SAP_ABA versions, 7.00 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, 75C to 75D, a trans... |
| CVE-2018-2479 | — | — | 1.3% | Nov 13, 2018 | SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode use... |
| CVE-2018-2478 | — | — | 1.8% | Nov 13, 2018 | An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, ve... |
| CVE-2018-2477 | — | — | 1.7% | Nov 13, 2018 | Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an X... |
| CVE-2018-2476 | — | — | 1.0% | Nov 13, 2018 | Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users ... |
| CVE-2018-2473 | — | — | 1.5% | Nov 13, 2018 | SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient ... |
| CVE-2018-7926 | — | — | 0.2% | Nov 13, 2018 | Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to im... |
| CVE-2018-7925 | — | — | 0.2% | Nov 13, 2018 | The radio module of some Huawei smartphones Emily-AL00A The versions before 8.1.0.171(C00) have a lock-screen bypass vul... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now