2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-2766MEDIUM4.9Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected...
CVE-2018-2761MEDIUM5.9Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are...
CVE-2018-2759MEDIUM4.9Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected...
CVE-2018-2587MEDIUM6.5Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). Supp...
CVE-2018-5431MEDIUM6.3The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community ...
CVE-2018-10178MEDIUM5.3The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via ve...
CVE-2018-5382MEDIUM4.4The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity ...
CVE-2018-1086MEDIUM4.3pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd servi...
CVE-2018-10061MEDIUM5.4Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occ...
CVE-2018-10060MEDIUM5.4Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_ur...
CVE-2018-0023MEDIUM5.5JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github. T...
CVE-2018-0019MEDIUM5.3A vulnerability in Junos OS SNMP MIB-II subagent daemon (mib2d) may allow a remote network based attacker to cause the m...
CVE-2018-1483MEDIUM6.1IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2018-10017MEDIUM6.5soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial o...
CVE-2018-3838MEDIUM6.5An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL...
CVE-2018-3837MEDIUM5.5An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedi...
CVE-2018-2413MEDIUM5.4SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in e...
CVE-2018-2410MEDIUM5.4SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross...
CVE-2018-2409MEDIUM6.3Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain ...
CVE-2018-2406MEDIUM5.3Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0...
CVE-2018-2405MEDIUM5.4SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an ...
CVE-2018-2404MEDIUM4.3SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.
CVE-2018-2403MEDIUM5.4Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise ...
CVE-2018-1271MEDIUM5.9Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow app...
CVE-2018-1081MEDIUM5.3A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Una...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now