2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-13908Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon ...
CVE-2018-13907While deserializing any key blob during key operations, buffer overflow could occur, exposing partial key information if...
CVE-2018-13906The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forge...
CVE-2018-13902Out of bounds memory read and access due to improper array index validation may lead to unexpected behavior while decodi...
CVE-2018-13901Due to missing permissions in Android Manifest file, Sensitive information disclosure issue can happen in PCI RCS app in...
CVE-2018-13898Out-of-Bounds write due to incorrect array index check in PMIC in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum...
CVE-2018-11955Lack of check on length of reason-code fetched from payload may lead driver access the memory not allocated to the frame...
CVE-2018-11947The txrx stats req might be double freed in the pdev detach when the host driver is unloading in Snapdragon Auto, Snapdr...
CVE-2018-11942Failure to initialize the reserved memory which is sent to the firmware might lead to exposure of 1 byte of uninitialize...
CVE-2018-11939Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT...
CVE-2018-11934Possible out of bounds write due to improper input validation while processing DO_ACS vendor command in Snapdragon Auto,...
CVE-2018-11929Lack of input validation in WLAN function can lead to potential heap overflow in Snapdragon Auto, Snapdragon Consumer IO...
CVE-2018-11819Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT...
CVE-2018-10947An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset on...
CVE-2018-10946An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arb...
CVE-2018-12147Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Service...
CVE-2018-20841HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via...
CVE-2018-11801SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a que...
CVE-2018-11800SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a que...
CVE-2018-20356An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mon...
CVE-2018-20355An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mo...
CVE-2018-20354An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data functio...
CVE-2018-20353An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data func...
CVE-2018-20352Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Lib...
CVE-2018-10703An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now