2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-2383Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
CVE-2018-2382A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to st...
CVE-2018-2381SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20...
CVE-2018-2379In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evalu...
CVE-2018-2378In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications...
CVE-2018-2377In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved...
CVE-2018-2376In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space...
CVE-2018-2375In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space...
CVE-2018-2374In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space...
CVE-2018-2373Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to ex...
CVE-2018-2372A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could en...
CVE-2018-2371The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controll...
CVE-2018-2370Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad,...
CVE-2018-2369Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would othe...
CVE-2018-2364SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode ...
CVE-2018-6910HIGH7.5DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/in...
CVE-2018-5459An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An at...
CVE-2018-6954HIGH7.8systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local ...
CVE-2018-6953In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual compon...
CVE-2018-1383A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privi...
CVE-2018-6952A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.
CVE-2018-6951An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer derefe...
CVE-2018-6948In CCN-lite 2, the function ccnl_prefix_to_str_detailed can cause a buffer overflow, when writing a prefix to the buffer...
CVE-2018-6928PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term.
CVE-2018-0488ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now