2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-21050CRITICAL9.8An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software. There is a Buffer o...
CVE-2018-21049CRITICAL9.8An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software. There is an arbitra...
CVE-2018-21044CRITICAL9.8An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) software. The sem Trustlet has a buffer overflo...
CVE-2018-21042CRITICAL9.8An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows instal...
CVE-2018-21038CRITICAL9.8An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows aut...
CVE-2018-21087CRITICAL9.8An issue was discovered on Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software. There is a vnswap heap-based...
CVE-2018-21081CRITICAL9.1An issue was discovered on Samsung mobile devices with N(7.x) software. In Dual Messenger, the second app can use the ru...
CVE-2018-21090CRITICAL9.8An issue was discovered on Samsung mobile devices with software through 2017-11-03 (S.LSI modem chipsets). The Exynos mo...
CVE-2018-21089CRITICAL9.8An issue was discovered on Samsung mobile devices with N(7.x) (MT6755/MT6757 Mediatek models) software. Bootloader has a...
CVE-2018-11106CRITICAL9.8NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on t...
CVE-2018-20334CRITICAL9.8An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command...
CVE-2018-14502CRITICAL9.8controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users...
CVE-2018-16357CRITICAL9.8An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.
CVE-2018-16356CRITICAL9.8An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.
CVE-2018-14705CRITICAL9.8In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any...
CVE-2018-16272CRITICAL9.8The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-F...
CVE-2018-10389CRITICAL9.8Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perfor...
CVE-2018-10388CRITICAL9.8Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perfor...
CVE-2018-10387CRITICAL9.8Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of serv...
CVE-2018-7282CRITICAL9.8The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based b...
CVE-2018-0730CRITICAL9.8This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix...
CVE-2018-0729CRITICAL9.8This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fi...
CVE-2018-8879CRITICAL9.8Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0....
CVE-2018-20687CRITICAL9.8An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway b...
CVE-2018-4031CRITICAL10An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lie...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now