2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-21087 | CRITICAL | 9.8 | 0.4% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software. There is a vnswap heap-based... |
| CVE-2018-21086 | HIGH | 8.1 | 0.3% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition wi... |
| CVE-2018-21085 | HIGH | 8.1 | 0.3% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition wi... |
| CVE-2018-21084 | HIGH | 8.1 | 0.3% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.x) software. There is a race condition wi... |
| CVE-2018-21083 | HIGH | 7.5 | 0.4% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos or Qualcomm chipsets) software... |
| CVE-2018-21082 | HIGH | 8.4 | 0.1% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-s... |
| CVE-2018-21081 | CRITICAL | 9.1 | 0.4% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.x) software. In Dual Messenger, the second app can use the ru... |
| CVE-2018-21092 | MEDIUM | 6.5 | 0.2% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by t... |
| CVE-2018-21091 | HIGH | 7.5 | 0.4% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. Telecom has a System Crash via abnorm... |
| CVE-2018-21090 | CRITICAL | 9.8 | 0.6% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with software through 2017-11-03 (S.LSI modem chipsets). The Exynos mo... |
| CVE-2018-21089 | CRITICAL | 9.8 | 0.8% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.x) (MT6755/MT6757 Mediatek models) software. Bootloader has a... |
| CVE-2018-17954 | HIGH | 7.8 | 0.3% | Apr 3, 2020 | An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, S... |
| CVE-2018-13371 | HIGH | 8.8 | 1.3% | Apr 2, 2020 | An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing se... |
| CVE-2018-11802 | MEDIUM | 4.3 | 2.0% | Apr 1, 2020 | In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any gi... |
| CVE-2018-11106 | CRITICAL | 9.8 | 2.6% | Apr 1, 2020 | NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on t... |
| CVE-2018-20335 | HIGH | 7.5 | 1.4% | Mar 20, 2020 | An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via... |
| CVE-2018-20334 | CRITICAL | 9.8 | 3.8% | Mar 20, 2020 | An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command... |
| CVE-2018-20333 | HIGH | 7.5 | 1.2% | Mar 20, 2020 | An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if ... |
| CVE-2018-21037 | HIGH | 8.8 | 0.5% | Mar 17, 2020 | Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/... |
| CVE-2018-18576 | MEDIUM | 5.3 | 1.4% | Mar 17, 2020 | The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory lis... |
| CVE-2018-19325 | — | — | — | Mar 16, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-14466. Reason: This candidate is a duplicate of ... |
| CVE-2018-13063 | HIGH | 7.5 | 1.3% | Mar 16, 2020 | Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts. |
| CVE-2018-13060 | MEDIUM | 6.5 | 0.9% | Mar 16, 2020 | Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue. |
| CVE-2018-10125 | MEDIUM | 6.1 | 0.8% | Mar 16, 2020 | Contao before 4.5.7 has XSS in the system log. |
| CVE-2018-20586 | MEDIUM | 5.3 | 1.1% | Mar 12, 2020 | bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now