2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-19977——A command injection (missing input validation, escaping) in the ftp upgrade configuration interface on the Auerswald COM...
CVE-2018-16221——The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (e...
CVE-2018-16218——A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware versio...
CVE-2018-16217——The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a re...
CVE-2018-13383MEDIUM6.5A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and e...
CVE-2018-20008MEDIUM6.8iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers...
CVE-2018-13375——An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 ...
CVE-2018-17198——Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsuppor...
CVE-2018-17843——SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM So...
CVE-2018-12624——An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter.
CVE-2018-19613——Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.
CVE-2018-19612——The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload mal...
CVE-2018-18060——An issue was discovered in Bitdefender Engines before 7.76808. A vulnerability has been discovered in the dalvik.xmd par...
CVE-2018-18059——An issue was discovered in Bitdefender Engines before 7.76675. A vulnerability has been discovered in the rar.xmd parser...
CVE-2018-18058——An issue was discovered in Bitdefender Engines before 7.76662. A vulnerability has been discovered in the iso.xmd parser...
CVE-2018-13925——Error in parsing PMT table frees the memory allocated for the map section but does not reset the context map section ref...
CVE-2018-13920——Use-after-free condition due to Improper handling of hrtimers when the PMU driver tries to access its events in Snapdrag...
CVE-2018-13899——Processing messages after error may result in user after free memory fault in Snapdragon Auto, Snapdragon Compute, Snapd...
CVE-2018-13895——Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an ...
CVE-2018-13887——Untrusted header fields in GNSS XTRA3 function can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snap...
CVE-2018-13886——Unchecked OTA field in GNSS XTRA3 lead to integer overflow and then buffer overflow in Snapdragon Auto, Snapdragon Compu...
CVE-2018-13885——Possible memory overread may be lead to access of sensitive data in Snapdragon Auto, Snapdragon Compute, Snapdragon Cons...
CVE-2018-12013——Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdra...
CVE-2018-12012——While updating blacklisting region shared buffered memory region is not validated against newly updated black list, caus...
CVE-2018-12005——An unprivileged user can issue a binder call and cause a system halt in Snapdragon Auto, Snapdragon Compute, Snapdragon ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now