2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13908 | — | — | 0.2% | Jun 14, 2019 | Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon ... |
| CVE-2018-13907 | — | — | 0.7% | Jun 14, 2019 | While deserializing any key blob during key operations, buffer overflow could occur, exposing partial key information if... |
| CVE-2018-13906 | — | — | 0.7% | Jun 14, 2019 | The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forge... |
| CVE-2018-13902 | — | — | 0.7% | Jun 14, 2019 | Out of bounds memory read and access due to improper array index validation may lead to unexpected behavior while decodi... |
| CVE-2018-13901 | — | — | 0.2% | Jun 14, 2019 | Due to missing permissions in Android Manifest file, Sensitive information disclosure issue can happen in PCI RCS app in... |
| CVE-2018-13898 | — | — | 0.7% | Jun 14, 2019 | Out-of-Bounds write due to incorrect array index check in PMIC in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum... |
| CVE-2018-11955 | — | — | 0.8% | Jun 14, 2019 | Lack of check on length of reason-code fetched from payload may lead driver access the memory not allocated to the frame... |
| CVE-2018-11947 | — | — | 0.2% | Jun 14, 2019 | The txrx stats req might be double freed in the pdev detach when the host driver is unloading in Snapdragon Auto, Snapdr... |
| CVE-2018-11942 | — | — | 0.2% | Jun 14, 2019 | Failure to initialize the reserved memory which is sent to the firmware might lead to exposure of 1 byte of uninitialize... |
| CVE-2018-11939 | — | — | 0.2% | Jun 14, 2019 | Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT... |
| CVE-2018-11934 | — | — | 0.2% | Jun 14, 2019 | Possible out of bounds write due to improper input validation while processing DO_ACS vendor command in Snapdragon Auto,... |
| CVE-2018-11929 | — | — | 0.2% | Jun 14, 2019 | Lack of input validation in WLAN function can lead to potential heap overflow in Snapdragon Auto, Snapdragon Consumer IO... |
| CVE-2018-11819 | — | — | 0.2% | Jun 14, 2019 | Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT... |
| CVE-2018-10947 | — | — | 0.4% | Jun 13, 2019 | An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset on... |
| CVE-2018-10946 | — | — | 0.5% | Jun 13, 2019 | An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arb... |
| CVE-2018-12147 | — | — | 0.5% | Jun 13, 2019 | Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Service... |
| CVE-2018-20841 | — | — | 47.9% | Jun 11, 2019 | HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via... |
| CVE-2018-11801 | — | — | 5.2% | Jun 11, 2019 | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a que... |
| CVE-2018-11800 | — | — | 5.2% | Jun 11, 2019 | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a que... |
| CVE-2018-20356 | — | — | 3.6% | Jun 10, 2019 | An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mon... |
| CVE-2018-20355 | — | — | 3.6% | Jun 10, 2019 | An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mo... |
| CVE-2018-20354 | — | — | 3.6% | Jun 10, 2019 | An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data functio... |
| CVE-2018-20353 | — | — | 3.6% | Jun 10, 2019 | An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data func... |
| CVE-2018-20352 | — | — | 2.7% | Jun 10, 2019 | Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Lib... |
| CVE-2018-10703 | — | — | 2.6% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now