2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-9581LOW3.3In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE and android.net.wifi.S...
CVE-2018-9425HIGH7.8In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could le...
CVE-2018-19592HIGH7.8The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows un...
CVE-2018-11782MEDIUM6.5In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit ...
CVE-2018-9090MEDIUM6.1CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (a...
CVE-2018-21019HIGH7.5Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to rea...
CVE-2018-21018CRITICAL9.8Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
CVE-2018-17789MEDIUM6.5Prospecta Master Data Online (MDO) allows CSRF.
CVE-2018-11200MEDIUM6.1An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field.
CVE-2018-1847MEDIUM6.5IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) v2.0.0.0 through 2.0.0.5, v2.1.0.0 through 2.1.0.4, v2.1...
CVE-2018-7820CRITICAL9.8A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could c...
CVE-2018-20336HIGH7.5An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parse_req_queries ...
CVE-2018-21017MEDIUM6.5GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.
CVE-2018-21016MEDIUM6.5audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of servi...
CVE-2018-21015MEDIUM6.5AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL poi...
CVE-2018-7081CRITICAL9.8A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacke...
CVE-2018-17200CRITICAL9.8The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via th...
CVE-2018-21014MEDIUM5.4The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.
CVE-2018-21013CRITICAL9.8The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator a...
CVE-2018-21012MEDIUM6.1The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.
CVE-2018-21011HIGH7.5The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.
CVE-2018-11198An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.
CVE-2018-18630HIGH7.8A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default install...
CVE-2018-6240NVIDIA Tegra contains a vulnerability in BootRom where a user with kernel level privileges can write an arbitrary value ...
CVE-2018-11569Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5....

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now