2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16221 | — | — | 1.5% | May 29, 2019 | The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (e... |
| CVE-2018-16218 | — | — | 1.3% | May 29, 2019 | A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware versio... |
| CVE-2018-16217 | — | — | 3.3% | May 29, 2019 | The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a re... |
| CVE-2018-13375 | — | — | 0.6% | May 28, 2019 | An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 ... |
| CVE-2018-17198 | — | — | 4.1% | May 28, 2019 | Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsuppor... |
| CVE-2018-17843 | — | — | 2.0% | May 24, 2019 | SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM So... |
| CVE-2018-12624 | — | — | 0.9% | May 24, 2019 | An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter. |
| CVE-2018-19613 | — | — | 0.6% | May 24, 2019 | Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF. |
| CVE-2018-19612 | — | — | 2.0% | May 24, 2019 | The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload mal... |
| CVE-2018-18060 | — | — | 1.0% | May 24, 2019 | An issue was discovered in Bitdefender Engines before 7.76808. A vulnerability has been discovered in the dalvik.xmd par... |
| CVE-2018-18059 | — | — | 1.0% | May 24, 2019 | An issue was discovered in Bitdefender Engines before 7.76675. A vulnerability has been discovered in the rar.xmd parser... |
| CVE-2018-18058 | — | — | 0.8% | May 24, 2019 | An issue was discovered in Bitdefender Engines before 7.76662. A vulnerability has been discovered in the iso.xmd parser... |
| CVE-2018-13925 | — | — | 0.9% | May 24, 2019 | Error in parsing PMT table frees the memory allocated for the map section but does not reset the context map section ref... |
| CVE-2018-13920 | — | — | 0.2% | May 24, 2019 | Use-after-free condition due to Improper handling of hrtimers when the PMU driver tries to access its events in Snapdrag... |
| CVE-2018-13899 | — | — | 0.2% | May 24, 2019 | Processing messages after error may result in user after free memory fault in Snapdragon Auto, Snapdragon Compute, Snapd... |
| CVE-2018-13895 | — | — | 0.2% | May 24, 2019 | Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an ... |
| CVE-2018-13887 | — | — | 1.1% | May 24, 2019 | Untrusted header fields in GNSS XTRA3 function can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snap... |
| CVE-2018-13886 | — | — | 1.1% | May 24, 2019 | Unchecked OTA field in GNSS XTRA3 lead to integer overflow and then buffer overflow in Snapdragon Auto, Snapdragon Compu... |
| CVE-2018-13885 | — | — | 0.2% | May 24, 2019 | Possible memory overread may be lead to access of sensitive data in Snapdragon Auto, Snapdragon Compute, Snapdragon Cons... |
| CVE-2018-12013 | — | — | 0.2% | May 24, 2019 | Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdra... |
| CVE-2018-12012 | — | — | 0.2% | May 24, 2019 | While updating blacklisting region shared buffered memory region is not validated against newly updated black list, caus... |
| CVE-2018-12005 | — | — | 0.2% | May 24, 2019 | An unprivileged user can issue a binder call and cause a system halt in Snapdragon Auto, Snapdragon Compute, Snapdragon ... |
| CVE-2018-12004 | — | — | 0.2% | May 24, 2019 | Secure keypad is unlocked with secure display still intact in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer E... |
| CVE-2018-11976 | — | — | 0.2% | May 24, 2019 | ECDSA signature code leaks private keys from secure world to non-secure world in Snapdragon Auto, Snapdragon Compute, Sn... |
| CVE-2018-11968 | — | — | 0.2% | May 24, 2019 | Improper check before assigning value can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Co... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now