2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11266 | — | — | 0.2% | Nov 27, 2018 | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper inpu... |
| CVE-2018-11261 | — | — | 0.2% | Nov 27, 2018 | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a po... |
| CVE-2018-11260 | — | — | 0.2% | Nov 27, 2018 | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while process... |
| CVE-2018-13376 | — | — | 2.1% | Nov 27, 2018 | An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under we... |
| CVE-2018-9084 | — | — | 0.7% | Nov 27, 2018 | In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validat... |
| CVE-2018-9083 | — | — | 1.1% | Nov 27, 2018 | In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be ... |
| CVE-2018-16096 | — | — | 0.6% | Nov 27, 2018 | In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to suff... |
| CVE-2018-16095 | — | — | 0.9% | Nov 27, 2018 | In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user auth... |
| CVE-2018-16094 | — | — | 0.9% | Nov 27, 2018 | In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings... |
| CVE-2018-16092 | — | — | 0.9% | Nov 27, 2018 | In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files c... |
| CVE-2018-16091 | — | — | 0.6% | Nov 27, 2018 | In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable t... |
| CVE-2018-16090 | — | — | 0.9% | Nov 27, 2018 | In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable t... |
| CVE-2018-16089 | — | — | 1.7% | Nov 27, 2018 | In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insuffi... |
| CVE-2018-11766 | — | — | 3.2% | Nov 27, 2018 | In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user ... |
| CVE-2018-19607 | — | — | 2.2% | Nov 27, 2018 | Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer ... |
| CVE-2018-19595 | — | — | 3.9% | Nov 27, 2018 | PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as... |
| CVE-2018-19587 | — | — | 0.9% | Nov 27, 2018 | In Cesanta Mongoose 6.13, a SIGSEGV exists in the mongoose.c mg_mqtt_add_session() function. |
| CVE-2018-13324 | — | — | 23.2% | Nov 26, 2018 | Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by... |
| CVE-2018-13323 | — | — | 0.7% | Nov 26, 2018 | Cross-site scripting in detail.html in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute JavaScript via ... |
| CVE-2018-13322 | — | — | 1.3% | Nov 26, 2018 | Directory traversal in list_folders method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to list directory c... |
| CVE-2018-13321 | — | — | 1.0% | Nov 26, 2018 | Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal ... |
| CVE-2018-13320 | — | — | 2.8% | Nov 26, 2018 | System Command Injection in network.set_auth_settings in Buffalo TS5600D1206 version 3.70-0.10 allows attackers to execu... |
| CVE-2018-13319 | — | — | 1.2% | Nov 26, 2018 | Incorrect access control in get_portal_info in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to determine sensi... |
| CVE-2018-13318 | — | — | 2.8% | Nov 26, 2018 | System command injection in User.create method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute syst... |
| CVE-2018-13317 | — | — | 1.0% | Nov 26, 2018 | Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now