2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-10951MEDIUM6.5mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows z...
CVE-2018-2423MEDIUM5.3SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent...
CVE-2018-2422MEDIUM5.3SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimat...
CVE-2018-2421MEDIUM5.3SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimat...
CVE-2018-2420MEDIUM6.5SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including sc...
CVE-2018-2418MEDIUM5.5SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the appl...
CVE-2018-2417MEDIUM5.3Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access informatio...
CVE-2018-2415MEDIUM4.7SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7...
CVE-2018-8912MEDIUM6.5Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station before 2.5.1-0844 allows remo...
CVE-2018-8911MEDIUM6.5Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote ...
CVE-2018-6511MEDIUM5.4A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts i...
CVE-2018-6510MEDIUM5.4A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts i...
CVE-2018-1313MEDIUM5.3In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Serve...
CVE-2018-5448MEDIUM4.8Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could...
CVE-2018-5446MEDIUM4.9Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format.
CVE-2018-10726MEDIUM5.4A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the...
CVE-2018-0288MEDIUM5.3A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote attacker to access s...
CVE-2018-0286MEDIUM5.3A vulnerability in the netconf interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cau...
CVE-2018-0278MEDIUM6.5A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote atta...
CVE-2018-0249MEDIUM4.3A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Q...
CVE-2018-0245MEDIUM5.3A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unau...
CVE-2018-10237MEDIUM5.9Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of...
CVE-2018-10289MEDIUM5.5In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary ...
CVE-2018-10126MEDIUM6.5ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a cer...
CVE-2018-10078MEDIUM4.8Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to i...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now