2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-13908——Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon ...
CVE-2018-13907——While deserializing any key blob during key operations, buffer overflow could occur, exposing partial key information if...
CVE-2018-13906——The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forge...
CVE-2018-13902——Out of bounds memory read and access due to improper array index validation may lead to unexpected behavior while decodi...
CVE-2018-13901——Due to missing permissions in Android Manifest file, Sensitive information disclosure issue can happen in PCI RCS app in...
CVE-2018-13898——Out-of-Bounds write due to incorrect array index check in PMIC in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum...
CVE-2018-11955——Lack of check on length of reason-code fetched from payload may lead driver access the memory not allocated to the frame...
CVE-2018-11947——The txrx stats req might be double freed in the pdev detach when the host driver is unloading in Snapdragon Auto, Snapdr...
CVE-2018-11942——Failure to initialize the reserved memory which is sent to the firmware might lead to exposure of 1 byte of uninitialize...
CVE-2018-11939——Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT...
CVE-2018-11934——Possible out of bounds write due to improper input validation while processing DO_ACS vendor command in Snapdragon Auto,...
CVE-2018-11929——Lack of input validation in WLAN function can lead to potential heap overflow in Snapdragon Auto, Snapdragon Consumer IO...
CVE-2018-11819——Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT...
CVE-2018-10947——An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset on...
CVE-2018-10946——An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arb...
CVE-2018-12147——Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Service...
CVE-2018-20841——HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via...
CVE-2018-11801——SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a que...
CVE-2018-11800——SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a que...
CVE-2018-20356——An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mon...
CVE-2018-20355——An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mo...
CVE-2018-20354——An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data functio...
CVE-2018-20353——An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data func...
CVE-2018-20352——Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Lib...
CVE-2018-10703——An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now