2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9581 | LOW | 3.3 | 0.2% | Sep 27, 2019 | In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE and android.net.wifi.S... |
| CVE-2018-9425 | HIGH | 7.8 | 0.1% | Sep 27, 2019 | In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could le... |
| CVE-2018-19592 | HIGH | 7.8 | 1.1% | Sep 27, 2019 | The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows un... |
| CVE-2018-11782 | MEDIUM | 6.5 | 2.4% | Sep 26, 2019 | In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit ... |
| CVE-2018-9090 | MEDIUM | 6.1 | 0.8% | Sep 24, 2019 | CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (a... |
| CVE-2018-21019 | HIGH | 7.5 | 1.7% | Sep 23, 2019 | Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to rea... |
| CVE-2018-21018 | CRITICAL | 9.8 | 2.6% | Sep 22, 2019 | Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions. |
| CVE-2018-17789 | MEDIUM | 6.5 | 0.7% | Sep 20, 2019 | Prospecta Master Data Online (MDO) allows CSRF. |
| CVE-2018-11200 | MEDIUM | 6.1 | 0.8% | Sep 20, 2019 | An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field. |
| CVE-2018-1847 | MEDIUM | 6.5 | 2.1% | Sep 18, 2019 | IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) v2.0.0.0 through 2.0.0.5, v2.1.0.0 through 2.1.0.4, v2.1... |
| CVE-2018-7820 | CRITICAL | 9.8 | 1.0% | Sep 17, 2019 | A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could c... |
| CVE-2018-20336 | HIGH | 7.5 | 2.0% | Sep 17, 2019 | An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parse_req_queries ... |
| CVE-2018-21017 | MEDIUM | 6.5 | 1.2% | Sep 16, 2019 | GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c. |
| CVE-2018-21016 | MEDIUM | 6.5 | 1.4% | Sep 16, 2019 | audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of servi... |
| CVE-2018-21015 | MEDIUM | 6.5 | 1.4% | Sep 16, 2019 | AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL poi... |
| CVE-2018-7081 | CRITICAL | 9.8 | 5.9% | Sep 13, 2019 | A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacke... |
| CVE-2018-17200 | CRITICAL | 9.8 | 5.0% | Sep 11, 2019 | The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via th... |
| CVE-2018-21014 | MEDIUM | 5.4 | 0.7% | Sep 9, 2019 | The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS. |
| CVE-2018-21013 | CRITICAL | 9.8 | 2.0% | Sep 9, 2019 | The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator a... |
| CVE-2018-21012 | MEDIUM | 6.1 | 0.9% | Sep 9, 2019 | The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS. |
| CVE-2018-21011 | HIGH | 7.5 | 1.7% | Sep 9, 2019 | The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details. |
| CVE-2018-11198 | — | — | 0.9% | Sep 6, 2019 | An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json. |
| CVE-2018-18630 | HIGH | 7.8 | 0.3% | Sep 6, 2019 | A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default install... |
| CVE-2018-6240 | — | — | 0.2% | Sep 6, 2019 | NVIDIA Tegra contains a vulnerability in BootRom where a user with kernel level privileges can write an arbitrary value ... |
| CVE-2018-11569 | — | — | 1.7% | Sep 5, 2019 | Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now