2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11257 | — | — | 0.2% | Jul 6, 2018 | Permissions, Privileges, and Access Controls in TA in Snapdragon Mobile has an options that allows RPMB erase for secure... |
| CVE-2018-13110 | — | — | 6.5% | Jul 6, 2018 | All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerabilit... |
| CVE-2018-13109 | — | — | 35.9% | Jul 6, 2018 | All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerabili... |
| CVE-2018-13108 | — | — | 1.6% | Jul 6, 2018 | All ADB broadband gateways / routers based on the Epicentro platform are affected by a local root jailbreak vulnerabilit... |
| CVE-2018-11124 | — | — | 1.9% | Jul 6, 2018 | Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows... |
| CVE-2018-13348 | — | — | 2.1% | Jul 6, 2018 | The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at ... |
| CVE-2018-13347 | — | — | 2.6% | Jul 6, 2018 | mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002. |
| CVE-2018-13346 | — | — | 2.3% | Jul 6, 2018 | The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start i... |
| CVE-2018-13340 | — | — | 0.7% | Jul 5, 2018 | Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request. |
| CVE-2018-13339 | — | — | 0.9% | Jul 5, 2018 | Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an ... |
| CVE-2018-9998 | — | — | 1.8% | Jul 5, 2018 | Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4... |
| CVE-2018-9997 | — | — | 1.9% | Jul 5, 2018 | Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7... |
| CVE-2018-8738 | — | — | 2.3% | Jul 5, 2018 | Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS. |
| CVE-2018-8046 | — | — | 67.0% | Jul 5, 2018 | The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passe... |
| CVE-2018-13052 | — | — | 1.2% | Jul 5, 2018 | In CyberArk Endpoint Privilege Manager (formerly Viewfinity), Privilege Escalation is possible if the attacker has one p... |
| CVE-2018-13031 | — | — | 1.1% | Jul 5, 2018 | DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account. |
| CVE-2018-12739 | — | — | 2.4% | Jul 5, 2018 | In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266. |
| CVE-2018-12571 | — | — | 30.3% | Jul 5, 2018 | uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to tr... |
| CVE-2018-12113 | — | — | 7.0% | Jul 5, 2018 | Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code e... |
| CVE-2018-12103 | — | — | 0.5% | Jul 5, 2018 | An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta... |
| CVE-2018-10988 | — | — | 0.2% | Jul 5, 2018 | An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at bo... |
| CVE-2018-10987 | — | — | 3.0% | Jul 5, 2018 | An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated re... |
| CVE-2018-7944 | — | — | 0.3% | Jul 5, 2018 | Huawei smart phones Emily-AL00A with software 8.1.0.106(SP2C00) and 8.1.0.107(SP5C00) have a Factory Reset Protection (F... |
| CVE-2018-13325 | — | — | 0.9% | Jul 5, 2018 | The _sell function of a smart contract implementation for GROWCHAIN (GROW), an Ethereum token, has an integer overflow. |
| CVE-2018-12976 | — | — | 4.5% | Jul 5, 2018 | In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now