2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-2474SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticate...
CVE-2018-2472SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently e...
CVE-2018-2471Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access i...
CVE-2018-2470In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do ...
CVE-2018-2469Under certain conditions SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access info...
CVE-2018-2468Under certain conditions the backup server in SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an at...
CVE-2018-2467In the Software Development Kit in SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, using the specially cr...
CVE-2018-2466In Impact and Lineage Analysis in SAP Data Services, version 4.2, the management console does not sufficiently validate ...
CVE-2018-12479MEDIUM6.5A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying craft...
CVE-2018-12478MEDIUM4.8A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system...
CVE-2018-12477LOW3.5A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletio...
CVE-2018-12474MEDIUM5.4Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extra...
CVE-2018-18071An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data...
CVE-2018-18070MEDIUM5.9An issue was discovered in Daimler Mercedes-Benz COMAND 17/13.0 50.12 on Mercedes-Benz C-Class 2018 vehicles. Defining o...
CVE-2018-18069process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_fil...
CVE-2018-14656HIGH7A missing address check in the callers of the show_opcodes() in the Linux kernel allows an attacker to dump the kernel m...
CVE-2018-18066HIGH7.5snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an un...
CVE-2018-18065_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by ...
CVE-2018-18064MEDIUM6.5cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ beca...
CVE-2018-17977The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP ...
CVE-2018-17775Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local us...
CVE-2018-15903The Discuss v1.2.1 module in Claromentis 8.2.2 is vulnerable to stored Cross Site Scripting (XSS). An authenticated atta...
CVE-2018-3997HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, versio...
CVE-2018-3996HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.2....
CVE-2018-3992HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, versio...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now