2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-2766 | MEDIUM | 4.9 | 3.1% | Apr 19, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected... |
| CVE-2018-2761 | MEDIUM | 5.9 | 4.0% | Apr 19, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are... |
| CVE-2018-2759 | MEDIUM | 4.9 | 2.8% | Apr 19, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected... |
| CVE-2018-2587 | MEDIUM | 6.5 | 2.0% | Apr 19, 2018 | Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). Supp... |
| CVE-2018-5431 | MEDIUM | 6.3 | 0.6% | Apr 17, 2018 | The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community ... |
| CVE-2018-10178 | MEDIUM | 5.3 | 1.1% | Apr 17, 2018 | The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via ve... |
| CVE-2018-5382 | MEDIUM | 4.4 | 0.3% | Apr 16, 2018 | The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity ... |
| CVE-2018-1086 | MEDIUM | 4.3 | 1.7% | Apr 12, 2018 | pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd servi... |
| CVE-2018-10061 | MEDIUM | 5.4 | 1.1% | Apr 12, 2018 | Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occ... |
| CVE-2018-10060 | MEDIUM | 5.4 | 1.0% | Apr 12, 2018 | Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_ur... |
| CVE-2018-0023 | MEDIUM | 5.5 | 0.3% | Apr 11, 2018 | JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github. T... |
| CVE-2018-0019 | MEDIUM | 5.3 | 1.6% | Apr 11, 2018 | A vulnerability in Junos OS SNMP MIB-II subagent daemon (mib2d) may allow a remote network based attacker to cause the m... |
| CVE-2018-1483 | MEDIUM | 6.1 | 1.3% | Apr 11, 2018 | IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2018-10017 | MEDIUM | 6.5 | 2.2% | Apr 11, 2018 | soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial o... |
| CVE-2018-3838 | MEDIUM | 6.5 | 1.8% | Apr 10, 2018 | An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL... |
| CVE-2018-3837 | MEDIUM | 5.5 | 1.2% | Apr 10, 2018 | An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedi... |
| CVE-2018-2413 | MEDIUM | 5.4 | 1.5% | Apr 10, 2018 | SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in e... |
| CVE-2018-2410 | MEDIUM | 5.4 | 1.0% | Apr 10, 2018 | SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross... |
| CVE-2018-2409 | MEDIUM | 6.3 | 1.3% | Apr 10, 2018 | Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain ... |
| CVE-2018-2406 | MEDIUM | 5.3 | 0.4% | Apr 10, 2018 | Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0... |
| CVE-2018-2405 | MEDIUM | 5.4 | 1.0% | Apr 10, 2018 | SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an ... |
| CVE-2018-2404 | MEDIUM | 4.3 | 2.0% | Apr 10, 2018 | SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation. |
| CVE-2018-2403 | MEDIUM | 5.4 | 1.2% | Apr 10, 2018 | Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise ... |
| CVE-2018-1271 | MEDIUM | 5.9 | 35.7% | Apr 6, 2018 | Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow app... |
| CVE-2018-1081 | MEDIUM | 5.3 | 1.5% | Apr 4, 2018 | A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Una... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now