2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-2492HIGH7.1SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted...
CVE-2018-2486SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, re...
CVE-2018-20064doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?...
CVE-2018-18810MEDIUM6.8The Administrator Service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, and TIBCO Manag...
CVE-2018-20062CRITICAL9.8An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP...
CVE-2018-20061A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a...
CVE-2018-20060urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., ...
CVE-2018-19970In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a paylo...
CVE-2018-19969phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clic...
CVE-2018-19968An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transfor...
CVE-2018-1904HIGH8.1IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code thro...
CVE-2018-1900MEDIUM5.4IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vu...
CVE-2018-18359Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perfor...
CVE-2018-18358Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the loca...
CVE-2018-18357Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote att...
CVE-2018-18356An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a r...
CVE-2018-18355Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote att...
CVE-2018-18354Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allow...
CVE-2018-18353Failure to dismiss http auth dialogs on navigation in Network Authentication in Google Chrome on Android prior to 71.0.3...
CVE-2018-18352Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prior to 71.0.3578.80 al...
CVE-2018-18351Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0....
CVE-2018-18350Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remot...
CVE-2018-18349Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 al...
CVE-2018-18348Incorrect handling of bidirectional domain names with RTL characters in Omnibox in Google Chrome prior to 71.0.3578.80 a...
CVE-2018-18347Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now