2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-16270HIGH7.5Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. Th...
CVE-2018-16269HIGH7.5The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notifica...
CVE-2018-16267HIGH8.1The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to ...
CVE-2018-16266HIGH8.1The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to imp...
CVE-2018-16263HIGH8.8The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper...
CVE-2018-16262HIGH8.8The pkgmgr system service in Tizen allows an unprivileged process to perform package management actions, due to improper...
CVE-2018-10465HIGH8.8Jamf Pro 10.x before 10.3.0 has Incorrect Access Control. Jamf Pro user accounts and groups with access to log in to Jam...
CVE-2018-7794HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modi...
CVE-2018-19834HIGH7.5The quaker function of a smart contract implementation for BOMBBA (BOMB), an tradable Ethereum ERC20 token, allows attac...
CVE-2018-19833HIGH7.5The owned function of a smart contract implementation for DDQ, an tradable Ethereum ERC20 token, allows attackers to cha...
CVE-2018-19832HIGH7.5The NETM() function of a smart contract implementation for NewIntelTechMedia (NETM), an tradable Ethereum ERC20 token, a...
CVE-2018-19831HIGH7.5The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token,...
CVE-2018-19830HIGH7.5The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable ...
CVE-2018-20499HIGH7.2An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and...
CVE-2018-20494HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo...
CVE-2018-1934HIGH8.8IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to exe...
CVE-2018-1311HIGH8.1The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external ...
CVE-2018-11980HIGH7.8When a fake broadcast/multicast 11w rmf without mmie received, since no proper length check in wma_process_bip, buffer o...
CVE-2018-0728HIGH7.5This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerabil...
CVE-2018-20090HIGH8.3An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass pr...
CVE-2018-17860HIGH7.2Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0....
CVE-2018-13916HIGH7.8Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve t...
CVE-2018-18368HIGH7.8Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerabili...
CVE-2018-21026HIGH7.5A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read inter...
CVE-2018-1721HIGH8.8IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML dat...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now