2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-21039HIGH7.5An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass fea...
CVE-2018-21088HIGH7.5An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can cause a reboot because InputMeth...
CVE-2018-21086HIGH8.1An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition wi...
CVE-2018-21085HIGH8.1An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition wi...
CVE-2018-21084HIGH8.1An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.x) software. There is a race condition wi...
CVE-2018-21083HIGH7.5An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos or Qualcomm chipsets) software...
CVE-2018-21082HIGH8.4An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-s...
CVE-2018-21091HIGH7.5An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. Telecom has a System Crash via abnorm...
CVE-2018-17954HIGH7.8An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, S...
CVE-2018-13371HIGH8.8An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing se...
CVE-2018-20335HIGH7.5An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via...
CVE-2018-20333HIGH7.5An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if ...
CVE-2018-21037HIGH8.8Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/...
CVE-2018-13063HIGH7.5Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
CVE-2018-18894HIGH7.5Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the ...
CVE-2018-11838HIGH7.8Possible double free issue in WLAN due to lack of checking memory free condition. in Snapdragon Auto, Snapdragon Compute...
CVE-2018-5951HIGH7.5An issue was discovered in Mikrotik RouterOS. Crafting a packet that has a size of 1 byte and sending it to an IPv6 addr...
CVE-2018-20343HIGH7.8Multiple buffer overflow vulnerabilities have been found in Ken Silverman Build Engine 1. An attacker could craft a spec...
CVE-2018-19798HIGH8.8Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the applicatio...
CVE-2018-15819HIGH7.5EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.
CVE-2018-17058HIGH8.8An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerabilit...
CVE-2018-21035HIGH7.5In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits can...
CVE-2018-16994HIGH7.5An issue was discovered on PHOENIX CONTACT AXL F BK PN <=1.0.4, AXL F BK ETH <= 1.12, and AXL F BK ETH XC <= 1.11 device...
CVE-2018-14553HIGH7.5gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an appl...
CVE-2018-12476HIGH7.5Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now