2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-2478 | — | — | 1.8% | Nov 13, 2018 | An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, ve... |
| CVE-2018-2477 | — | — | 1.7% | Nov 13, 2018 | Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an X... |
| CVE-2018-2476 | — | — | 1.0% | Nov 13, 2018 | Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users ... |
| CVE-2018-2473 | — | — | 1.5% | Nov 13, 2018 | SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient ... |
| CVE-2018-7926 | — | — | 0.2% | Nov 13, 2018 | Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to im... |
| CVE-2018-7925 | — | — | 0.2% | Nov 13, 2018 | The radio module of some Huawei smartphones Emily-AL00A The versions before 8.1.0.171(C00) have a lock-screen bypass vul... |
| CVE-2018-7910 | — | — | 0.3% | Nov 13, 2018 | Some Huawei smartphones ALP-AL00B 8.0.0.118D(C00), ALP-TL00B 8.0.0.118D(C01), BLA-AL00B 8.0.0.118D(C00), BLA-L09C 8.0.0.... |
| CVE-2018-14658 | MEDIUM | 6.1 | 1.1% | Nov 13, 2018 | A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.key... |
| CVE-2018-14657 | HIGH | 8.1 | 1.2% | Nov 13, 2018 | A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force ... |
| CVE-2018-14655 | MEDIUM | 4.6 | 1.2% | Nov 13, 2018 | A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible ... |
| CVE-2018-12416 | HIGH | 7.1 | 0.6% | Nov 13, 2018 | The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager c... |
| CVE-2018-6260 | — | — | 0.4% | Nov 13, 2018 | NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a... |
| CVE-2018-1808 | MEDIUM | 4.3 | 1.6% | Nov 13, 2018 | IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input contr... |
| CVE-2018-1792 | HIGH | 8.8 | 0.5% | Nov 13, 2018 | IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local... |
| CVE-2018-17187 | — | — | 2.5% | Nov 13, 2018 | The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.s... |
| CVE-2018-16850 | CRITICAL | 9.8 | 5.1% | Nov 13, 2018 | postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER .... |
| CVE-2018-1293 | — | — | — | Nov 13, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-15795 | HIGH | 8.1 | 1.3% | Nov 13, 2018 | Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating s... |
| CVE-2018-15772 | — | — | 0.4% | Nov 13, 2018 | Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an uncontroll... |
| CVE-2018-15771 | — | — | 0.4% | Nov 13, 2018 | Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an informatio... |
| CVE-2018-15452 | MEDIUM | 5.5 | 0.3% | Nov 13, 2018 | A vulnerability in the DLL loading component of Cisco Advanced Malware Protection (AMP) for Endpoints on Windows could a... |
| CVE-2018-18591 | MEDIUM | 6.8 | 1.0% | Nov 13, 2018 | A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9... |
| CVE-2018-19246 | — | — | 22.5% | Nov 13, 2018 | PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users w... |
| CVE-2018-19244 | — | — | 2.0% | Nov 13, 2018 | An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "... |
| CVE-2018-19229 | — | — | 0.6% | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/art.php?typeid=1 biaoti parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now