2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-21056 | MEDIUM | 4.6 | 0.1% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with O(8.x) software. The Smartwatch displays Secure Folder Notificati... |
| CVE-2018-21053 | MEDIUM | 4.6 | 0.1% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is Clipboard access in... |
| CVE-2018-21048 | MEDIUM | 6.2 | 0.1% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Notification leak on a locked device ... |
| CVE-2018-21045 | MEDIUM | 6.2 | 0.1% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboard access in the lock... |
| CVE-2018-21092 | MEDIUM | 6.5 | 0.2% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by t... |
| CVE-2018-11802 | MEDIUM | 4.3 | 2.0% | Apr 1, 2020 | In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any gi... |
| CVE-2018-18576 | MEDIUM | 5.3 | 1.4% | Mar 17, 2020 | The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory lis... |
| CVE-2018-13060 | MEDIUM | 6.5 | 0.9% | Mar 16, 2020 | Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue. |
| CVE-2018-10125 | MEDIUM | 6.1 | 0.8% | Mar 16, 2020 | Contao before 4.5.7 has XSS in the system log. |
| CVE-2018-20586 | MEDIUM | 5.3 | 1.1% | Mar 12, 2020 | bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call. |
| CVE-2018-19516 | MEDIUM | 5.3 | 1.1% | Mar 12, 2020 | messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restric... |
| CVE-2018-10704 | MEDIUM | 6.1 | 0.9% | Mar 12, 2020 | yidashi yii2cmf 2.0 has XSS via the /search q parameter. |
| CVE-2018-19658 | MEDIUM | 5.4 | 0.5% | Mar 2, 2020 | The Markdown editor in YXBJ before 8.3.2 on macOS has stored XSS. This behavior may be encountered by some Evernote user... |
| CVE-2018-19599 | MEDIUM | 5.4 | 0.7% | Mar 2, 2020 | Monstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: ... |
| CVE-2018-17572 | MEDIUM | 4.8 | 0.7% | Mar 2, 2020 | InfluxDB 0.9.5 has Reflected XSS in the Write Data module. |
| CVE-2018-15820 | MEDIUM | 6.1 | 0.9% | Mar 2, 2020 | EasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter. |
| CVE-2018-14384 | MEDIUM | 4.8 | 0.8% | Mar 2, 2020 | The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerabil... |
| CVE-2018-8878 | MEDIUM | 5.3 | 1.5% | Feb 27, 2020 | Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382... |
| CVE-2018-8877 | MEDIUM | 5.3 | 1.4% | Feb 27, 2020 | Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382... |
| CVE-2018-13313 | MEDIUM | 6.5 | 1.0% | Feb 24, 2020 | In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. Th... |
| CVE-2018-21033 | MEDIUM | 6.5 | 0.8% | Feb 14, 2020 | A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi In... |
| CVE-2018-21032 | MEDIUM | 4.3 | 0.9% | Feb 14, 2020 | A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authe... |
| CVE-2018-3987 | MEDIUM | 5.5 | 0.4% | Feb 13, 2020 | An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Andro... |
| CVE-2018-19441 | MEDIUM | 4.7 | 0.3% | Jan 27, 2020 | An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library g... |
| CVE-2018-20105 | MEDIUM | 5.5 | 0.4% | Jan 27, 2020 | A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUS... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now