2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-8476A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in ...
CVE-2018-8471An elevation of privilege vulnerability exists in the way that the Microsoft RemoteFX Virtual GPU miniport driver handle...
CVE-2018-8454An information disclosure vulnerability exists when Windows Audio Service fails to properly handle objects in memory, ak...
CVE-2018-8450A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote C...
CVE-2018-8417A security feature bypass vulnerability exists in Microsoft JScript that could allow an attacker to bypass Device Guard,...
CVE-2018-8416A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vul...
CVE-2018-8415A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft Pow...
CVE-2018-8408An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Wi...
CVE-2018-8407An information disclosure vulnerability exists when "Kernel Remote Procedure Call Provider" driver improperly initialize...
CVE-2018-8256A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft ...
CVE-2018-16471There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data re...
CVE-2018-16470There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause...
CVE-2018-6980HIGH7.2VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authori...
CVE-2018-8009Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is ex...
CVE-2018-17614This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Losant Arduino MQTT ...
CVE-2018-2491When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to t...
CVE-2018-2490The broadcast messages received by SAP Fiori Client are not protected by permissions. SAP Fiori Client version 1.11.5 in...
CVE-2018-2489Locally, without any permission, an arbitrary android application could delete the SSO configuration of SAP Fiori Client...
CVE-2018-2488It is possible for a malware application installed on an Android device to send local push notifications with an empty m...
CVE-2018-2487SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: Whe...
CVE-2018-2485It is possible for a malicious application or malware to execute JavaScript in a SAP Fiori application. This can include...
CVE-2018-2483HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Man...
CVE-2018-2482SAP Mobile Secure Android Application, Mobile-secure.apk Android client, before version 6.60.19942.0, allows an attacker...
CVE-2018-2481In some SAP standard roles, in SAP_ABA versions, 7.00 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, 75C to 75D, a trans...
CVE-2018-2479SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode use...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now