2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-2383 | — | — | 0.7% | Feb 14, 2018 | Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53. |
| CVE-2018-2382 | — | — | 0.9% | Feb 14, 2018 | A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to st... |
| CVE-2018-2381 | — | — | 1.3% | Feb 14, 2018 | SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20... |
| CVE-2018-2379 | — | — | 0.9% | Feb 14, 2018 | In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evalu... |
| CVE-2018-2378 | — | — | 0.9% | Feb 14, 2018 | In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications... |
| CVE-2018-2377 | — | — | 0.9% | Feb 14, 2018 | In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved... |
| CVE-2018-2376 | — | — | 0.9% | Feb 14, 2018 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space... |
| CVE-2018-2375 | — | — | 0.9% | Feb 14, 2018 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space... |
| CVE-2018-2374 | — | — | 1.2% | Feb 14, 2018 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space... |
| CVE-2018-2373 | — | — | 1.2% | Feb 14, 2018 | Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to ex... |
| CVE-2018-2372 | — | — | 0.9% | Feb 14, 2018 | A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could en... |
| CVE-2018-2371 | — | — | 1.0% | Feb 14, 2018 | The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controll... |
| CVE-2018-2370 | — | — | 1.2% | Feb 14, 2018 | Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad,... |
| CVE-2018-2369 | — | — | 1.5% | Feb 14, 2018 | Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would othe... |
| CVE-2018-2364 | — | — | 1.0% | Feb 14, 2018 | SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode ... |
| CVE-2018-6910 | HIGH | 7.5 | 19.0% | Feb 13, 2018 | DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/in... |
| CVE-2018-5459 | — | — | 2.7% | Feb 13, 2018 | An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An at... |
| CVE-2018-6954 | HIGH | 7.8 | 0.5% | Feb 13, 2018 | systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local ... |
| CVE-2018-6953 | — | — | 1.6% | Feb 13, 2018 | In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual compon... |
| CVE-2018-1383 | — | — | 2.7% | Feb 13, 2018 | A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privi... |
| CVE-2018-6952 | — | — | 8.4% | Feb 13, 2018 | A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6. |
| CVE-2018-6951 | — | — | 8.6% | Feb 13, 2018 | An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer derefe... |
| CVE-2018-6948 | — | — | 1.6% | Feb 13, 2018 | In CCN-lite 2, the function ccnl_prefix_to_str_detailed can cause a buffer overflow, when writing a prefix to the buffer... |
| CVE-2018-6928 | — | — | 1.7% | Feb 13, 2018 | PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term. |
| CVE-2018-0488 | — | — | 4.9% | Feb 13, 2018 | ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now