2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16951xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to C...
CVE-2018-16949An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables ...
CVE-2018-16948An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initi...
CVE-2018-16947An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accep...
CVE-2018-16946LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /u...
CVE-2018-15898The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certi...
CVE-2018-11078MEDIUM4Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authen...
CVE-2018-11070MEDIUM5.9RSA BSAFE Crypto-J versions prior to 6.2.4 and RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel v...
CVE-2018-11069MEDIUM5.9RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during RSA decryption, also known ...
CVE-2018-11068MEDIUM4.6RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physic...
CVE-2018-16836CRITICAL9.8Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attac...
CVE-2018-10937MEDIUM4.6A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker wi...
CVE-2018-2465SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate ...
CVE-2018-2464SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resultin...
CVE-2018-2463The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (...
CVE-2018-2462In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not suf...
CVE-2018-2461Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may...
CVE-2018-2460SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This a...
CVE-2018-2459Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens ...
CVE-2018-2458Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacke...
CVE-2018-2457Under certain conditions SAP Adaptive Server Enterprise, version 16.0, allows some privileged users to access informatio...
CVE-2018-2455SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA...
CVE-2018-2454SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) d...
CVE-2018-2452MEDIUM6.1The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode u...
CVE-2018-1127MEDIUM4.2Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Ses...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now