2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8860 | — | — | 0.7% | May 9, 2018 | In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker may be able to capture firmware updates through the adjace... |
| CVE-2018-6021 | — | — | 1.3% | May 9, 2018 | Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call param... |
| CVE-2018-6020 | — | — | 1.1% | May 9, 2018 | In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when maki... |
| CVE-2018-2423 | MEDIUM | 5.3 | 2.6% | May 9, 2018 | SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent... |
| CVE-2018-2422 | MEDIUM | 5.3 | 2.0% | May 9, 2018 | SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimat... |
| CVE-2018-2421 | MEDIUM | 5.3 | 2.6% | May 9, 2018 | SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimat... |
| CVE-2018-2420 | MEDIUM | 6.5 | 1.6% | May 9, 2018 | SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including sc... |
| CVE-2018-2419 | LOW | 3.7 | 0.9% | May 9, 2018 | SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18... |
| CVE-2018-2418 | MEDIUM | 5.5 | 1.8% | May 9, 2018 | SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the appl... |
| CVE-2018-2417 | MEDIUM | 5.3 | 1.4% | May 9, 2018 | Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access informatio... |
| CVE-2018-2416 | — | — | 1.5% | May 9, 2018 | SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source. |
| CVE-2018-2415 | MEDIUM | 4.7 | 1.2% | May 9, 2018 | SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7... |
| CVE-2018-8866 | — | — | 2.2% | May 9, 2018 | In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker on an adjacent network could perform command injection. |
| CVE-2018-8179 | — | — | 12.9% | May 9, 2018 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E... |
| CVE-2018-8178 | — | — | 14.2% | May 9, 2018 | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka "Microsoft... |
| CVE-2018-8177 | — | — | 10.7% | May 9, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8174 | HIGH | 7.5 | 87.6% | May 9, 2018 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows... |
| CVE-2018-8173 | — | — | 18.6% | May 9, 2018 | A remote code execution vulnerability exists in Microsoft InfoPath when the software fails to properly handle objects in... |
| CVE-2018-8170 | — | — | 1.0% | May 9, 2018 | An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory, aka "... |
| CVE-2018-8168 | — | — | 2.4% | May 9, 2018 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c... |
| CVE-2018-8167 | — | — | 1.0% | May 9, 2018 | An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles ... |
| CVE-2018-8166 | — | — | 1.2% | May 9, 2018 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ... |
| CVE-2018-8165 | — | — | 1.3% | May 9, 2018 | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje... |
| CVE-2018-8164 | — | — | 1.4% | May 9, 2018 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ... |
| CVE-2018-8163 | — | — | 12.3% | May 9, 2018 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now