2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-21039 | HIGH | 7.5 | 0.4% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass fea... |
| CVE-2018-21088 | HIGH | 7.5 | 0.4% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can cause a reboot because InputMeth... |
| CVE-2018-21086 | HIGH | 8.1 | 0.3% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition wi... |
| CVE-2018-21085 | HIGH | 8.1 | 0.3% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition wi... |
| CVE-2018-21084 | HIGH | 8.1 | 0.3% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.x) software. There is a race condition wi... |
| CVE-2018-21083 | HIGH | 7.5 | 0.4% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos or Qualcomm chipsets) software... |
| CVE-2018-21082 | HIGH | 8.4 | 0.1% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-s... |
| CVE-2018-21091 | HIGH | 7.5 | 0.4% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. Telecom has a System Crash via abnorm... |
| CVE-2018-17954 | HIGH | 7.8 | 0.3% | Apr 3, 2020 | An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, S... |
| CVE-2018-13371 | HIGH | 8.8 | 1.3% | Apr 2, 2020 | An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing se... |
| CVE-2018-20335 | HIGH | 7.5 | 1.4% | Mar 20, 2020 | An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via... |
| CVE-2018-20333 | HIGH | 7.5 | 1.2% | Mar 20, 2020 | An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if ... |
| CVE-2018-21037 | HIGH | 8.8 | 0.5% | Mar 17, 2020 | Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/... |
| CVE-2018-13063 | HIGH | 7.5 | 1.3% | Mar 16, 2020 | Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts. |
| CVE-2018-18894 | HIGH | 7.5 | 1.7% | Mar 10, 2020 | Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the ... |
| CVE-2018-11838 | HIGH | 7.8 | 0.2% | Mar 5, 2020 | Possible double free issue in WLAN due to lack of checking memory free condition. in Snapdragon Auto, Snapdragon Compute... |
| CVE-2018-5951 | HIGH | 7.5 | 4.3% | Mar 2, 2020 | An issue was discovered in Mikrotik RouterOS. Crafting a packet that has a size of 1 byte and sending it to an IPv6 addr... |
| CVE-2018-20343 | HIGH | 7.8 | 2.2% | Mar 2, 2020 | Multiple buffer overflow vulnerabilities have been found in Ken Silverman Build Engine 1. An attacker could craft a spec... |
| CVE-2018-19798 | HIGH | 8.8 | 3.1% | Mar 2, 2020 | Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the applicatio... |
| CVE-2018-15819 | HIGH | 7.5 | 1.8% | Mar 2, 2020 | EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js. |
| CVE-2018-17058 | HIGH | 8.8 | 1.3% | Mar 2, 2020 | An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerabilit... |
| CVE-2018-21035 | HIGH | 7.5 | 2.3% | Feb 28, 2020 | In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits can... |
| CVE-2018-16994 | HIGH | 7.5 | 1.6% | Feb 18, 2020 | An issue was discovered on PHOENIX CONTACT AXL F BK PN <=1.0.4, AXL F BK ETH <= 1.12, and AXL F BK ETH XC <= 1.11 device... |
| CVE-2018-14553 | HIGH | 7.5 | 3.4% | Feb 11, 2020 | gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an appl... |
| CVE-2018-12476 | HIGH | 7.5 | 1.0% | Jan 27, 2020 | Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now