2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-9368HIGH7.8In mtkscoaudio debugfs there is a possible arbitrary kernel memory write due to missing bounds check and weakened SELinu...
CVE-2018-9367HIGH7.8In FT_ACDK_CCT_V2_OP_ISP_SET_TUNING_PARAS of Meta_CCAP_Para.cpp, there is a possible out of bounds write due to improper...
CVE-2018-9366HIGH7.8In IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible out of bounds write d...
CVE-2018-9364HIGH7.5In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to ...
CVE-2018-9348MEDIUM6.5In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service du...
CVE-2018-9346MEDIUM5.5In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uniniti...
CVE-2018-9345MEDIUM5.5In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uniniti...
CVE-2018-9344HIGH7.8In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead...
CVE-2018-9341HIGH7.8In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could...
CVE-2018-9340MEDIUM5.5In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to b...
CVE-2018-9339HIGH7.8In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type co...
CVE-2018-9338HIGH7.8In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. Thi...
CVE-2018-25104MEDIUM5.3A vulnerability was found in CoinGate Plugin up to 1.2.7 on PrestaShop. It has been rated as problematic. Affected by th...
CVE-2018-25105CRITICAL9.8The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /i...
CVE-2018-20072HIGH7.8Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of b...
CVE-2018-25103MEDIUM5.3There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers...
CVE-2018-25101LOW3.5A vulnerability, which was classified as problematic, has been found in l2c2technologies Koha up to 20180108. This issue...
CVE-2018-25100MEDIUM5.3The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies f...
CVE-2018-25099CRITICAL9.8In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the...
CVE-2018-25090MEDIUM5.4An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generat...
CVE-2018-25098HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in blockmason credit-protocol. It has been declared as problem...
CVE-2018-25095CRITICAL9.8The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values i...
CVE-2018-25097MEDIUM6.1A vulnerability, which was classified as problematic, was found in Acumos Design Studio up to 2.0.7. Affected is an unkn...
CVE-2018-25096HIGH8.8A vulnerability was found in MdAlAmin-aol Own Health Record 0.1-alpha/0.2-alpha/0.3-alpha/0.3.1-alpha. It has been rated...
CVE-2018-16153HIGH7.5An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authe...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now