2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-14705CRITICAL9.8In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any...
CVE-2018-13313MEDIUM6.5In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. Th...
CVE-2018-16994HIGH7.5An issue was discovered on PHOENIX CONTACT AXL F BK PN <=1.0.4, AXL F BK ETH <= 1.12, and AXL F BK ETH XC <= 1.11 device...
CVE-2018-21033MEDIUM6.5A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi In...
CVE-2018-21032MEDIUM4.3A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authe...
CVE-2018-3987MEDIUM5.5An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Andro...
CVE-2018-14553HIGH7.5gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an appl...
CVE-2018-5746Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2018-19441MEDIUM4.7An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library g...
CVE-2018-20105MEDIUM5.5A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUS...
CVE-2018-12476HIGH7.5Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows...
CVE-2018-8654MEDIUM6.5An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation o...
CVE-2018-16272CRITICAL9.8The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-F...
CVE-2018-16271MEDIUM6.5The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged ...
CVE-2018-16270HIGH7.5Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. Th...
CVE-2018-16269HIGH7.5The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notifica...
CVE-2018-16268MEDIUM4.3The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actio...
CVE-2018-16267HIGH8.1The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to ...
CVE-2018-16266HIGH8.1The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to imp...
CVE-2018-16265MEDIUM6.5The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the ...
CVE-2018-16264MEDIUM6.5The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive inf...
CVE-2018-16263HIGH8.8The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper...
CVE-2018-16262HIGH8.8The pkgmgr system service in Tizen allows an unprivileged process to perform package management actions, due to improper...
CVE-2018-17981MEDIUM6.1Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.
CVE-2018-18811Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now