2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-8860In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker may be able to capture firmware updates through the adjace...
CVE-2018-6021Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call param...
CVE-2018-6020In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when maki...
CVE-2018-2423MEDIUM5.3SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent...
CVE-2018-2422MEDIUM5.3SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimat...
CVE-2018-2421MEDIUM5.3SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimat...
CVE-2018-2420MEDIUM6.5SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including sc...
CVE-2018-2419LOW3.7SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18...
CVE-2018-2418MEDIUM5.5SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the appl...
CVE-2018-2417MEDIUM5.3Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access informatio...
CVE-2018-2416SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.
CVE-2018-2415MEDIUM4.7SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7...
CVE-2018-8866In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker on an adjacent network could perform command injection.
CVE-2018-8179A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E...
CVE-2018-8178A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka "Microsoft...
CVE-2018-8177A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8174HIGH7.5A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows...
CVE-2018-8173A remote code execution vulnerability exists in Microsoft InfoPath when the software fails to properly handle objects in...
CVE-2018-8170An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory, aka "...
CVE-2018-8168An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c...
CVE-2018-8167An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles ...
CVE-2018-8166An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ...
CVE-2018-8165An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje...
CVE-2018-8164An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ...
CVE-2018-8163An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now