2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11874Buffer overflow if the length of passphrase is more than 32 when setting up secure NDP connection in Snapdragon Mobile i...
CVE-2018-11873Improper input validation leads to buffer overwrite in the WLAN function that handles WLAN roam buffer in Snapdragon Mob...
CVE-2018-11872Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile ...
CVE-2018-11871Buffer overwrite can happen in WLAN function while processing set pdev parameter command due to lack of input validation...
CVE-2018-11870Buffer overwrite can occur when the legacy rates count received from the host is not checked against the maximum number ...
CVE-2018-11867Lack of buffer length check before copying in WLAN function while processing FIPS event, can lead to a buffer overflow i...
CVE-2018-11866Integer overflow may happen in WLAN when calculating an internal structure size due to lack of validation of the input l...
CVE-2018-11865Integer overflow may happen when calculating an internal structure size due to lack of validation of the input length in...
CVE-2018-11862Buffer overflow can happen in WLAN module due to lack of validation of the input length in Snapdragon Mobile in version ...
CVE-2018-11861Buffer overflow can happen in WLAN function due to lack of validation of the input length in Snapdragon Mobile in versio...
CVE-2018-11859Buffer overwrite can happen in WLAN due to lack of validation of the input length in Snapdragon Mobile in version SD 845...
CVE-2018-11858When processing IE set command, buffer overwrite may occur due to lack of input validation of the IE length in Snapdrago...
CVE-2018-11857Improper input validation in WLAN encrypt/decrypt module can lead to a buffer copy in Snapdragon Mobile in version SD 83...
CVE-2018-11856Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile ...
CVE-2018-1767MEDIUM6.1IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnera...
CVE-2018-1766MEDIUM5.4IBM Team Concert (RTC) 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerabilit...
CVE-2018-1380LOW2.7IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with C...
CVE-2018-0735MEDIUM5.9The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could...
CVE-2018-18792An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.
CVE-2018-18791An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.
CVE-2018-18790An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This nee...
CVE-2018-18789An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.
CVE-2018-18788An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This n...
CVE-2018-18787An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.
CVE-2018-18786An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now