2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-16946LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /u...
CVE-2018-15898The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certi...
CVE-2018-2465SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate ...
CVE-2018-2464SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resultin...
CVE-2018-2463The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (...
CVE-2018-2462In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not suf...
CVE-2018-2461Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may...
CVE-2018-2460SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This a...
CVE-2018-2459Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens ...
CVE-2018-2458Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacke...
CVE-2018-2457Under certain conditions SAP Adaptive Server Enterprise, version 16.0, allows some privileged users to access informatio...
CVE-2018-2455SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA...
CVE-2018-2454SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) d...
CVE-2018-6975The AirWatch Agent for iOS prior to 5.8.1 contains a data protection vulnerability whereby the files and keychain entrie...
CVE-2018-16832CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because...
CVE-2018-16831Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in...
CVE-2018-16807In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Ke...
CVE-2018-16806A Pektron Passive Keyless Entry and Start (PKES) system, as used on the Tesla Model S and possibly other vehicles, relie...
CVE-2018-16805In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link...
CVE-2018-11775TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vu...
CVE-2018-16705FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the syst...
CVE-2018-16591FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service acco...
CVE-2018-12608An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both t...
CVE-2018-16802An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running o...
CVE-2018-16797A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary cod...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now