2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10951 | MEDIUM | 6.5 | 1.2% | May 10, 2018 | mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows z... |
| CVE-2018-2423 | MEDIUM | 5.3 | 2.6% | May 9, 2018 | SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent... |
| CVE-2018-2422 | MEDIUM | 5.3 | 2.0% | May 9, 2018 | SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimat... |
| CVE-2018-2421 | MEDIUM | 5.3 | 2.6% | May 9, 2018 | SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimat... |
| CVE-2018-2420 | MEDIUM | 6.5 | 1.6% | May 9, 2018 | SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including sc... |
| CVE-2018-2418 | MEDIUM | 5.5 | 1.8% | May 9, 2018 | SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the appl... |
| CVE-2018-2417 | MEDIUM | 5.3 | 1.4% | May 9, 2018 | Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access informatio... |
| CVE-2018-2415 | MEDIUM | 4.7 | 1.2% | May 9, 2018 | SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7... |
| CVE-2018-8912 | MEDIUM | 6.5 | 1.0% | May 9, 2018 | Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station before 2.5.1-0844 allows remo... |
| CVE-2018-8911 | MEDIUM | 6.5 | 1.0% | May 9, 2018 | Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote ... |
| CVE-2018-6511 | MEDIUM | 5.4 | 0.6% | May 8, 2018 | A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts i... |
| CVE-2018-6510 | MEDIUM | 5.4 | 0.5% | May 8, 2018 | A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts i... |
| CVE-2018-1313 | MEDIUM | 5.3 | 4.5% | May 7, 2018 | In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Serve... |
| CVE-2018-5448 | MEDIUM | 4.8 | 0.7% | May 4, 2018 | Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could... |
| CVE-2018-5446 | MEDIUM | 4.9 | 0.4% | May 4, 2018 | Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format. |
| CVE-2018-10726 | MEDIUM | 5.4 | 0.7% | May 4, 2018 | A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the... |
| CVE-2018-0288 | MEDIUM | 5.3 | 2.7% | May 2, 2018 | A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote attacker to access s... |
| CVE-2018-0286 | MEDIUM | 5.3 | 3.3% | May 2, 2018 | A vulnerability in the netconf interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cau... |
| CVE-2018-0278 | MEDIUM | 6.5 | 2.2% | May 2, 2018 | A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote atta... |
| CVE-2018-0249 | MEDIUM | 4.3 | 0.6% | May 2, 2018 | A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Q... |
| CVE-2018-0245 | MEDIUM | 5.3 | 2.4% | May 2, 2018 | A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unau... |
| CVE-2018-10237 | MEDIUM | 5.9 | 5.1% | Apr 26, 2018 | Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of... |
| CVE-2018-10289 | MEDIUM | 5.5 | 1.1% | Apr 22, 2018 | In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary ... |
| CVE-2018-10126 | MEDIUM | 6.5 | 1.9% | Apr 21, 2018 | ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a cer... |
| CVE-2018-10078 | MEDIUM | 4.8 | 2.1% | Apr 20, 2018 | Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to i... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now