2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16946 | — | — | 9.3% | Sep 12, 2018 | LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /u... |
| CVE-2018-15898 | — | — | 0.9% | Sep 11, 2018 | The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certi... |
| CVE-2018-2465 | — | — | 2.6% | Sep 11, 2018 | SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate ... |
| CVE-2018-2464 | — | — | 1.0% | Sep 11, 2018 | SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resultin... |
| CVE-2018-2463 | — | — | 1.6% | Sep 11, 2018 | The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (... |
| CVE-2018-2462 | — | — | 1.6% | Sep 11, 2018 | In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not suf... |
| CVE-2018-2461 | — | — | 1.3% | Sep 11, 2018 | Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may... |
| CVE-2018-2460 | — | — | 0.8% | Sep 11, 2018 | SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This a... |
| CVE-2018-2459 | — | — | 1.7% | Sep 11, 2018 | Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens ... |
| CVE-2018-2458 | — | — | 1.7% | Sep 11, 2018 | Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacke... |
| CVE-2018-2457 | — | — | 0.9% | Sep 11, 2018 | Under certain conditions SAP Adaptive Server Enterprise, version 16.0, allows some privileged users to access informatio... |
| CVE-2018-2455 | — | — | 1.3% | Sep 11, 2018 | SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA... |
| CVE-2018-2454 | — | — | 1.3% | Sep 11, 2018 | SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) d... |
| CVE-2018-6975 | — | — | 0.3% | Sep 11, 2018 | The AirWatch Agent for iOS prior to 5.8.1 contains a data protection vulnerability whereby the files and keychain entrie... |
| CVE-2018-16832 | — | — | 0.6% | Sep 11, 2018 | CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because... |
| CVE-2018-16831 | — | — | 2.7% | Sep 11, 2018 | Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in... |
| CVE-2018-16807 | — | — | 1.4% | Sep 11, 2018 | In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Ke... |
| CVE-2018-16806 | — | — | 0.5% | Sep 10, 2018 | A Pektron Passive Keyless Entry and Start (PKES) system, as used on the Tesla Model S and possibly other vehicles, relie... |
| CVE-2018-16805 | — | — | 0.8% | Sep 10, 2018 | In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link... |
| CVE-2018-11775 | — | — | 7.0% | Sep 10, 2018 | TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vu... |
| CVE-2018-16705 | — | — | 1.6% | Sep 10, 2018 | FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the syst... |
| CVE-2018-16591 | — | — | 2.2% | Sep 10, 2018 | FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service acco... |
| CVE-2018-12608 | — | — | 0.9% | Sep 10, 2018 | An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both t... |
| CVE-2018-16802 | — | — | 2.2% | Sep 10, 2018 | An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running o... |
| CVE-2018-16797 | — | — | 2.7% | Sep 10, 2018 | A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary cod... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now