2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16951 | — | — | 0.8% | Sep 12, 2018 | xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to C... |
| CVE-2018-16949 | — | — | 3.1% | Sep 12, 2018 | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables ... |
| CVE-2018-16948 | — | — | 2.0% | Sep 12, 2018 | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initi... |
| CVE-2018-16947 | — | — | 2.6% | Sep 12, 2018 | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accep... |
| CVE-2018-16946 | — | — | 9.3% | Sep 12, 2018 | LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /u... |
| CVE-2018-15898 | — | — | 0.9% | Sep 11, 2018 | The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certi... |
| CVE-2018-11078 | MEDIUM | 4 | 0.8% | Sep 11, 2018 | Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authen... |
| CVE-2018-11070 | MEDIUM | 5.9 | 1.7% | Sep 11, 2018 | RSA BSAFE Crypto-J versions prior to 6.2.4 and RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel v... |
| CVE-2018-11069 | MEDIUM | 5.9 | 1.3% | Sep 11, 2018 | RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during RSA decryption, also known ... |
| CVE-2018-11068 | MEDIUM | 4.6 | 0.4% | Sep 11, 2018 | RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physic... |
| CVE-2018-16836 | CRITICAL | 9.8 | 61.4% | Sep 11, 2018 | Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attac... |
| CVE-2018-10937 | MEDIUM | 4.6 | 1.1% | Sep 11, 2018 | A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker wi... |
| CVE-2018-2465 | — | — | 2.6% | Sep 11, 2018 | SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate ... |
| CVE-2018-2464 | — | — | 1.0% | Sep 11, 2018 | SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resultin... |
| CVE-2018-2463 | — | — | 1.6% | Sep 11, 2018 | The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (... |
| CVE-2018-2462 | — | — | 1.6% | Sep 11, 2018 | In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not suf... |
| CVE-2018-2461 | — | — | 1.3% | Sep 11, 2018 | Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may... |
| CVE-2018-2460 | — | — | 0.8% | Sep 11, 2018 | SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This a... |
| CVE-2018-2459 | — | — | 1.7% | Sep 11, 2018 | Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens ... |
| CVE-2018-2458 | — | — | 1.7% | Sep 11, 2018 | Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacke... |
| CVE-2018-2457 | — | — | 0.9% | Sep 11, 2018 | Under certain conditions SAP Adaptive Server Enterprise, version 16.0, allows some privileged users to access informatio... |
| CVE-2018-2455 | — | — | 1.3% | Sep 11, 2018 | SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA... |
| CVE-2018-2454 | — | — | 1.3% | Sep 11, 2018 | SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) d... |
| CVE-2018-2452 | MEDIUM | 6.1 | 1.4% | Sep 11, 2018 | The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode u... |
| CVE-2018-1127 | MEDIUM | 4.2 | 1.3% | Sep 11, 2018 | Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Ses... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now