2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-2469 | — | — | 1.7% | Oct 9, 2018 | Under certain conditions SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access info... |
| CVE-2018-2468 | — | — | 1.7% | Oct 9, 2018 | Under certain conditions the backup server in SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an at... |
| CVE-2018-2467 | — | — | 1.4% | Oct 9, 2018 | In the Software Development Kit in SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, using the specially cr... |
| CVE-2018-2466 | — | — | 0.8% | Oct 9, 2018 | In Impact and Lineage Analysis in SAP Data Services, version 4.2, the management console does not sufficiently validate ... |
| CVE-2018-18071 | — | — | 1.4% | Oct 9, 2018 | An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data... |
| CVE-2018-18069 | — | — | 12.8% | Oct 8, 2018 | process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_fil... |
| CVE-2018-18065 | — | — | 17.2% | Oct 8, 2018 | _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by ... |
| CVE-2018-17977 | — | — | 0.4% | Oct 8, 2018 | The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP ... |
| CVE-2018-17775 | — | — | 1.0% | Oct 8, 2018 | Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local us... |
| CVE-2018-15903 | — | — | 0.7% | Oct 8, 2018 | The Discuss v1.2.1 module in Claromentis 8.2.2 is vulnerable to stored Cross Site Scripting (XSS). An authenticated atta... |
| CVE-2018-17443 | — | — | 5.7% | Oct 8, 2018 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS... |
| CVE-2018-17442 | — | — | 14.2% | Oct 8, 2018 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerabili... |
| CVE-2018-17441 | — | — | 5.7% | Oct 8, 2018 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser... |
| CVE-2018-17440 | — | — | 36.9% | Oct 8, 2018 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves b... |
| CVE-2018-16297 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16296 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16295 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16294 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16293 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16292 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16291 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-1000810 | — | — | 3.0% | Oct 8, 2018 | The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contai... |
| CVE-2018-1000809 | — | — | 1.7% | Oct 8, 2018 | privacyIDEA version 2.23.1 and earlier contains a Improper Input Validation vulnerability in token validation api that c... |
| CVE-2018-1000808 | — | — | 1.9% | Oct 8, 2018 | Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before R... |
| CVE-2018-1000803 | — | — | 1.3% | Oct 8, 2018 | Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now