2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-21087CRITICAL9.8An issue was discovered on Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software. There is a vnswap heap-based...
CVE-2018-21086HIGH8.1An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition wi...
CVE-2018-21085HIGH8.1An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition wi...
CVE-2018-21084HIGH8.1An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.x) software. There is a race condition wi...
CVE-2018-21083HIGH7.5An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos or Qualcomm chipsets) software...
CVE-2018-21082HIGH8.4An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-s...
CVE-2018-21081CRITICAL9.1An issue was discovered on Samsung mobile devices with N(7.x) software. In Dual Messenger, the second app can use the ru...
CVE-2018-21092MEDIUM6.5An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by t...
CVE-2018-21091HIGH7.5An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. Telecom has a System Crash via abnorm...
CVE-2018-21090CRITICAL9.8An issue was discovered on Samsung mobile devices with software through 2017-11-03 (S.LSI modem chipsets). The Exynos mo...
CVE-2018-21089CRITICAL9.8An issue was discovered on Samsung mobile devices with N(7.x) (MT6755/MT6757 Mediatek models) software. Bootloader has a...
CVE-2018-17954HIGH7.8An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, S...
CVE-2018-13371HIGH8.8An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing se...
CVE-2018-11802MEDIUM4.3In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any gi...
CVE-2018-11106CRITICAL9.8NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on t...
CVE-2018-20335HIGH7.5An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via...
CVE-2018-20334CRITICAL9.8An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command...
CVE-2018-20333HIGH7.5An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if ...
CVE-2018-21037HIGH8.8Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/...
CVE-2018-18576MEDIUM5.3The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory lis...
CVE-2018-19325Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-14466. Reason: This candidate is a duplicate of ...
CVE-2018-13063HIGH7.5Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
CVE-2018-13060MEDIUM6.5Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
CVE-2018-10125MEDIUM6.1Contao before 4.5.7 has XSS in the system log.
CVE-2018-20586MEDIUM5.3bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now