2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-8910MEDIUM6.5Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Drive before 1.0.1-10253 allows remote authen...
CVE-2018-1130MEDIUM5.5Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit() function in net/dc...
CVE-2018-10951MEDIUM6.5mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows z...
CVE-2018-2423MEDIUM5.3SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent...
CVE-2018-2422MEDIUM5.3SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimat...
CVE-2018-2421MEDIUM5.3SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimat...
CVE-2018-2420MEDIUM6.5SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including sc...
CVE-2018-2418MEDIUM5.5SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the appl...
CVE-2018-2417MEDIUM5.3Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access informatio...
CVE-2018-2415MEDIUM4.7SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7...
CVE-2018-8912MEDIUM6.5Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station before 2.5.1-0844 allows remo...
CVE-2018-8911MEDIUM6.5Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote ...
CVE-2018-6511MEDIUM5.4A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts i...
CVE-2018-6510MEDIUM5.4A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts i...
CVE-2018-1313MEDIUM5.3In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Serve...
CVE-2018-5448MEDIUM4.8Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could...
CVE-2018-5446MEDIUM4.9Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format.
CVE-2018-10726MEDIUM5.4A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the...
CVE-2018-0288MEDIUM5.3A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote attacker to access s...
CVE-2018-0286MEDIUM5.3A vulnerability in the netconf interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cau...
CVE-2018-0278MEDIUM6.5A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote atta...
CVE-2018-0249MEDIUM4.3A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Q...
CVE-2018-0245MEDIUM5.3A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unau...
CVE-2018-10237MEDIUM5.9Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of...
CVE-2018-10289MEDIUM5.5In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now