2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-16221The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (e...
CVE-2018-16218A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware versio...
CVE-2018-16217The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a re...
CVE-2018-13375An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 ...
CVE-2018-17198Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsuppor...
CVE-2018-17843SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM So...
CVE-2018-12624An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter.
CVE-2018-19613Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.
CVE-2018-19612The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload mal...
CVE-2018-18060An issue was discovered in Bitdefender Engines before 7.76808. A vulnerability has been discovered in the dalvik.xmd par...
CVE-2018-18059An issue was discovered in Bitdefender Engines before 7.76675. A vulnerability has been discovered in the rar.xmd parser...
CVE-2018-18058An issue was discovered in Bitdefender Engines before 7.76662. A vulnerability has been discovered in the iso.xmd parser...
CVE-2018-13925Error in parsing PMT table frees the memory allocated for the map section but does not reset the context map section ref...
CVE-2018-13920Use-after-free condition due to Improper handling of hrtimers when the PMU driver tries to access its events in Snapdrag...
CVE-2018-13899Processing messages after error may result in user after free memory fault in Snapdragon Auto, Snapdragon Compute, Snapd...
CVE-2018-13895Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an ...
CVE-2018-13887Untrusted header fields in GNSS XTRA3 function can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snap...
CVE-2018-13886Unchecked OTA field in GNSS XTRA3 lead to integer overflow and then buffer overflow in Snapdragon Auto, Snapdragon Compu...
CVE-2018-13885Possible memory overread may be lead to access of sensitive data in Snapdragon Auto, Snapdragon Compute, Snapdragon Cons...
CVE-2018-12013Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdra...
CVE-2018-12012While updating blacklisting region shared buffered memory region is not validated against newly updated black list, caus...
CVE-2018-12005An unprivileged user can issue a binder call and cause a system halt in Snapdragon Auto, Snapdragon Compute, Snapdragon ...
CVE-2018-12004Secure keypad is unlocked with secure display still intact in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer E...
CVE-2018-11976ECDSA signature code leaks private keys from secure world to non-secure world in Snapdragon Auto, Snapdragon Compute, Sn...
CVE-2018-11968Improper check before assigning value can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Co...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now