2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-2478An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, ve...
CVE-2018-2477Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an X...
CVE-2018-2476Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users ...
CVE-2018-2473SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient ...
CVE-2018-7926Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to im...
CVE-2018-7925The radio module of some Huawei smartphones Emily-AL00A The versions before 8.1.0.171(C00) have a lock-screen bypass vul...
CVE-2018-7910Some Huawei smartphones ALP-AL00B 8.0.0.118D(C00), ALP-TL00B 8.0.0.118D(C01), BLA-AL00B 8.0.0.118D(C00), BLA-L09C 8.0.0....
CVE-2018-14658MEDIUM6.1A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.key...
CVE-2018-14657HIGH8.1A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force ...
CVE-2018-14655MEDIUM4.6A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible ...
CVE-2018-12416HIGH7.1The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager c...
CVE-2018-6260NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a...
CVE-2018-1808MEDIUM4.3IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input contr...
CVE-2018-1792HIGH8.8IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local...
CVE-2018-17187The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.s...
CVE-2018-16850CRITICAL9.8postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ....
CVE-2018-1293Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-15795HIGH8.1Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating s...
CVE-2018-15772Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an uncontroll...
CVE-2018-15771Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an informatio...
CVE-2018-15452MEDIUM5.5A vulnerability in the DLL loading component of Cisco Advanced Malware Protection (AMP) for Endpoints on Windows could a...
CVE-2018-18591MEDIUM6.8A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9...
CVE-2018-19246PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users w...
CVE-2018-19244An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "...
CVE-2018-19229An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/art.php?typeid=1 biaoti parameter.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now