2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7701 | — | — | 3.1% | Mar 15, 2018 | Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers... |
| CVE-2018-8712 | — | — | 1.8% | Mar 14, 2018 | An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is e... |
| CVE-2018-8711 | — | — | 2.0% | Mar 14, 2018 | A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPr... |
| CVE-2018-8710 | — | — | 4.3% | Mar 14, 2018 | A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordP... |
| CVE-2018-6329 | — | — | 62.5% | Mar 14, 2018 | It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i... |
| CVE-2018-6328 | — | — | 65.5% | Mar 14, 2018 | It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, w... |
| CVE-2018-2402 | HIGH | 7.6 | 1.6% | Mar 14, 2018 | In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more ... |
| CVE-2018-2401 | MEDIUM | 5.4 | 1.7% | Mar 14, 2018 | SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrust... |
| CVE-2018-2400 | — | — | 1.7% | Mar 14, 2018 | Under certain conditions SAP Business Process Automation (BPA) By Redwood, 9.00, 9.10, allows an attacker to access info... |
| CVE-2018-2399 | MEDIUM | 6.1 | 1.3% | Mar 14, 2018 | Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to ineff... |
| CVE-2018-2398 | HIGH | 7.5 | 1.0% | Mar 14, 2018 | Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restr... |
| CVE-2018-2397 | MEDIUM | 5.4 | 1.0% | Mar 14, 2018 | In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) doe... |
| CVE-2018-2366 | MEDIUM | 4.3 | 1.6% | Mar 14, 2018 | SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of pat... |
| CVE-2018-7533 | — | — | 0.3% | Mar 14, 2018 | An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure defau... |
| CVE-2018-7531 | — | — | 1.4% | Mar 14, 2018 | An Improper Input Validation issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated us... |
| CVE-2018-7529 | — | — | 2.1% | Mar 14, 2018 | A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthentic... |
| CVE-2018-7508 | — | — | 0.9% | Mar 14, 2018 | A Cross-site Scripting issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Cross-site scripting may o... |
| CVE-2018-7504 | — | — | 0.9% | Mar 14, 2018 | A Protection Mechanism Failure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The X-XSS-Protection r... |
| CVE-2018-7500 | — | — | 1.9% | Mar 14, 2018 | A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Pr... |
| CVE-2018-7496 | — | — | 1.3% | Mar 14, 2018 | An Information Exposure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The server response header an... |
| CVE-2018-1077 | — | — | 1.1% | Mar 14, 2018 | Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information fro... |
| CVE-2018-1000122 | — | — | 9.4% | Mar 14, 2018 | A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attac... |
| CVE-2018-1000121 | — | — | 9.6% | Mar 14, 2018 | A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker t... |
| CVE-2018-1000120 | — | — | 12.1% | Mar 14, 2018 | A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to ... |
| CVE-2018-0983 | — | — | 1.2% | Mar 14, 2018 | Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, versi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now