2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16270 | HIGH | 7.5 | 1.2% | Jan 22, 2020 | Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. Th... |
| CVE-2018-16269 | HIGH | 7.5 | 1.4% | Jan 22, 2020 | The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notifica... |
| CVE-2018-16267 | HIGH | 8.1 | 0.7% | Jan 22, 2020 | The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to ... |
| CVE-2018-16266 | HIGH | 8.1 | 0.7% | Jan 22, 2020 | The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to imp... |
| CVE-2018-16263 | HIGH | 8.8 | 0.8% | Jan 22, 2020 | The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper... |
| CVE-2018-16262 | HIGH | 8.8 | 0.8% | Jan 22, 2020 | The pkgmgr system service in Tizen allows an unprivileged process to perform package management actions, due to improper... |
| CVE-2018-10465 | HIGH | 8.8 | 1.2% | Jan 7, 2020 | Jamf Pro 10.x before 10.3.0 has Incorrect Access Control. Jamf Pro user accounts and groups with access to log in to Jam... |
| CVE-2018-7794 | HIGH | 7.5 | 1.4% | Jan 6, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modi... |
| CVE-2018-19834 | HIGH | 7.5 | 0.9% | Dec 31, 2019 | The quaker function of a smart contract implementation for BOMBBA (BOMB), an tradable Ethereum ERC20 token, allows attac... |
| CVE-2018-19833 | HIGH | 7.5 | 0.9% | Dec 31, 2019 | The owned function of a smart contract implementation for DDQ, an tradable Ethereum ERC20 token, allows attackers to cha... |
| CVE-2018-19832 | HIGH | 7.5 | 0.9% | Dec 31, 2019 | The NETM() function of a smart contract implementation for NewIntelTechMedia (NETM), an tradable Ethereum ERC20 token, a... |
| CVE-2018-19831 | HIGH | 7.5 | 0.9% | Dec 31, 2019 | The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token,... |
| CVE-2018-19830 | HIGH | 7.5 | 0.9% | Dec 31, 2019 | The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable ... |
| CVE-2018-20499 | HIGH | 7.2 | 0.7% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and... |
| CVE-2018-20494 | HIGH | 7.5 | 1.6% | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo... |
| CVE-2018-1934 | HIGH | 8.8 | 0.4% | Dec 20, 2019 | IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to exe... |
| CVE-2018-1311 | HIGH | 8.1 | 9.5% | Dec 18, 2019 | The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external ... |
| CVE-2018-11980 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | When a fake broadcast/multicast 11w rmf without mmie received, since no proper length check in wma_process_bip, buffer o... |
| CVE-2018-0728 | HIGH | 7.5 | 1.3% | Dec 4, 2019 | This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerabil... |
| CVE-2018-20090 | HIGH | 8.3 | 0.8% | Nov 26, 2019 | An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass pr... |
| CVE-2018-17860 | HIGH | 7.2 | 1.0% | Nov 26, 2019 | Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.... |
| CVE-2018-13916 | HIGH | 7.8 | 0.2% | Nov 21, 2019 | Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve t... |
| CVE-2018-18368 | HIGH | 7.8 | 0.6% | Nov 15, 2019 | Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerabili... |
| CVE-2018-21026 | HIGH | 7.5 | 1.4% | Nov 12, 2019 | A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read inter... |
| CVE-2018-1721 | HIGH | 8.8 | 1.8% | Nov 9, 2019 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML dat... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now