2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14705 | CRITICAL | 9.8 | 1.9% | Feb 24, 2020 | In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any... |
| CVE-2018-13313 | MEDIUM | 6.5 | 1.0% | Feb 24, 2020 | In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. Th... |
| CVE-2018-16994 | HIGH | 7.5 | 1.6% | Feb 18, 2020 | An issue was discovered on PHOENIX CONTACT AXL F BK PN <=1.0.4, AXL F BK ETH <= 1.12, and AXL F BK ETH XC <= 1.11 device... |
| CVE-2018-21033 | MEDIUM | 6.5 | 0.8% | Feb 14, 2020 | A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi In... |
| CVE-2018-21032 | MEDIUM | 4.3 | 0.9% | Feb 14, 2020 | A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authe... |
| CVE-2018-3987 | MEDIUM | 5.5 | 0.4% | Feb 13, 2020 | An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Andro... |
| CVE-2018-14553 | HIGH | 7.5 | 3.4% | Feb 11, 2020 | gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an appl... |
| CVE-2018-5746 | — | — | — | Feb 7, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2018-19441 | MEDIUM | 4.7 | 0.3% | Jan 27, 2020 | An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library g... |
| CVE-2018-20105 | MEDIUM | 5.5 | 0.4% | Jan 27, 2020 | A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUS... |
| CVE-2018-12476 | HIGH | 7.5 | 1.0% | Jan 27, 2020 | Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows... |
| CVE-2018-8654 | MEDIUM | 6.5 | 1.8% | Jan 24, 2020 | An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation o... |
| CVE-2018-16272 | CRITICAL | 9.8 | 1.6% | Jan 22, 2020 | The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-F... |
| CVE-2018-16271 | MEDIUM | 6.5 | 0.8% | Jan 22, 2020 | The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged ... |
| CVE-2018-16270 | HIGH | 7.5 | 1.2% | Jan 22, 2020 | Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. Th... |
| CVE-2018-16269 | HIGH | 7.5 | 1.4% | Jan 22, 2020 | The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notifica... |
| CVE-2018-16268 | MEDIUM | 4.3 | 0.5% | Jan 22, 2020 | The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actio... |
| CVE-2018-16267 | HIGH | 8.1 | 0.7% | Jan 22, 2020 | The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to ... |
| CVE-2018-16266 | HIGH | 8.1 | 0.7% | Jan 22, 2020 | The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to imp... |
| CVE-2018-16265 | MEDIUM | 6.5 | 0.6% | Jan 22, 2020 | The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the ... |
| CVE-2018-16264 | MEDIUM | 6.5 | 0.6% | Jan 22, 2020 | The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive inf... |
| CVE-2018-16263 | HIGH | 8.8 | 0.8% | Jan 22, 2020 | The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper... |
| CVE-2018-16262 | HIGH | 8.8 | 0.8% | Jan 22, 2020 | The pkgmgr system service in Tizen allows an unprivileged process to perform package management actions, due to improper... |
| CVE-2018-17981 | MEDIUM | 6.1 | 0.8% | Jan 22, 2020 | Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter. |
| CVE-2018-18811 | — | — | — | Jan 15, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now