2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-7701Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers...
CVE-2018-8712An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is e...
CVE-2018-8711A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPr...
CVE-2018-8710A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordP...
CVE-2018-6329It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i...
CVE-2018-6328It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, w...
CVE-2018-2402HIGH7.6In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more ...
CVE-2018-2401MEDIUM5.4SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrust...
CVE-2018-2400Under certain conditions SAP Business Process Automation (BPA) By Redwood, 9.00, 9.10, allows an attacker to access info...
CVE-2018-2399MEDIUM6.1Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to ineff...
CVE-2018-2398HIGH7.5Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restr...
CVE-2018-2397MEDIUM5.4In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) doe...
CVE-2018-2366MEDIUM4.3SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of pat...
CVE-2018-7533An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure defau...
CVE-2018-7531An Improper Input Validation issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated us...
CVE-2018-7529A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthentic...
CVE-2018-7508A Cross-site Scripting issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Cross-site scripting may o...
CVE-2018-7504A Protection Mechanism Failure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The X-XSS-Protection r...
CVE-2018-7500A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Pr...
CVE-2018-7496An Information Exposure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The server response header an...
CVE-2018-1077Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information fro...
CVE-2018-1000122A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attac...
CVE-2018-1000121A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker t...
CVE-2018-1000120A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to ...
CVE-2018-0983Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, versi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now