2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-3872CRITICAL9.9An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm...
CVE-2018-3866CRITICAL9.9An exploitable buffer overflow vulnerability exists in the samsungWifiScan handler of video-core's HTTP server of Samsun...
CVE-2018-3856CRITICAL9.9An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 -...
CVE-2018-3919CRITICAL9.9An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in video-core's HTTP...
CVE-2018-3917CRITICAL9.9On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts...
CVE-2018-3905CRITICAL9.9An exploitable buffer overflow vulnerability exists in the camera "create" feature of video-core's HTTP server of Samsun...
CVE-2018-3903CRITICAL9.9On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extract...
CVE-2018-3902CRITICAL9.9An exploitable buffer overflow vulnerability exists in the camera "replace" feature of video-core's HTTP server of Samsu...
CVE-2018-3878CRITICAL9.9Multiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core's HTTP server of Sam...
CVE-2018-3867CRITICAL9.9An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-co...
CVE-2018-3863CRITICAL9.9On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extract...
CVE-2018-3832CRITICAL9An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows...
CVE-2018-6692CRITICAL10Stack-based Buffer Overflow vulnerability in libUPnPHndlr.so in Belkin Wemo Insight Smart Plug allows remote attackers t...
CVE-2018-1000639CRITICAL9.6LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result ...
CVE-2018-3785CRITICAL9.8A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter.
CVE-2018-3784CRITICAL9.8A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserial...
CVE-2018-10511CRITICAL10A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side r...
CVE-2018-8273CRITICAL9.8A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected...
CVE-2018-15152CRITICAL9.1Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote...
CVE-2018-3938CRITICAL9.1An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPEL...
CVE-2018-3937CRITICAL9.1An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series...
CVE-2018-10931CRITICAL9.8It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unaut...
CVE-2018-14933CRITICAL9.8upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par...
CVE-2018-9866CRITICAL9.8A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management S...
CVE-2018-3777CRITICAL9.8Insufficient URI encoding in restforce before 3.0.0 allows attacker to inject arbitrary parameters into Salesforce API r...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now