2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-21056MEDIUM4.6An issue was discovered on Samsung mobile devices with O(8.x) software. The Smartwatch displays Secure Folder Notificati...
CVE-2018-21053MEDIUM4.6An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is Clipboard access in...
CVE-2018-21048MEDIUM6.2An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Notification leak on a locked device ...
CVE-2018-21045MEDIUM6.2An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboard access in the lock...
CVE-2018-21092MEDIUM6.5An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by t...
CVE-2018-11802MEDIUM4.3In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any gi...
CVE-2018-18576MEDIUM5.3The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory lis...
CVE-2018-13060MEDIUM6.5Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
CVE-2018-10125MEDIUM6.1Contao before 4.5.7 has XSS in the system log.
CVE-2018-20586MEDIUM5.3bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call.
CVE-2018-19516MEDIUM5.3messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restric...
CVE-2018-10704MEDIUM6.1yidashi yii2cmf 2.0 has XSS via the /search q parameter.
CVE-2018-19658MEDIUM5.4The Markdown editor in YXBJ before 8.3.2 on macOS has stored XSS. This behavior may be encountered by some Evernote user...
CVE-2018-19599MEDIUM5.4Monstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: ...
CVE-2018-17572MEDIUM4.8InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
CVE-2018-15820MEDIUM6.1EasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter.
CVE-2018-14384MEDIUM4.8The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerabil...
CVE-2018-8878MEDIUM5.3Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382...
CVE-2018-8877MEDIUM5.3Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382...
CVE-2018-13313MEDIUM6.5In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. Th...
CVE-2018-21033MEDIUM6.5A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi In...
CVE-2018-21032MEDIUM4.3A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authe...
CVE-2018-3987MEDIUM5.5An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Andro...
CVE-2018-19441MEDIUM4.7An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library g...
CVE-2018-20105MEDIUM5.5A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUS...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now