2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-11864——Bytes can be written to fuses from Secure region which can be read later by HLOS in Snapdragon Auto, Snapdragon Compute,...
CVE-2018-11845——Usage of non-time-constant comparison functions can lead to information leakage through side channel analysis in Snapdra...
CVE-2018-11820——Use of non-time constant memcmp function creates side channel that leaks information and leads to cryptographic issues i...
CVE-2018-11289——Data truncation during higher to lower type conversion which causes less memory allocation than desired can lead to a bu...
CVE-2018-20795——tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path p...
CVE-2018-20794——tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via pat...
CVE-2018-20793——tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[...
CVE-2018-20792——tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path pa...
CVE-2018-20791——tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mis...
CVE-2018-20790——tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0]...
CVE-2018-20789——tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a pat...
CVE-2018-20788——drivers/leds/leds-aw2023.c in the led driver for custom Linux kernels on the Xiaomi Redmi 6pro daisy-o-oss phone has sev...
CVE-2018-20787——The ft5x46 touchscreen driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has a...
CVE-2018-20786——libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a ...
CVE-2018-20785——Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM...
CVE-2018-18692——A reflected Cross-Site scripting (XSS) vulnerability in SEMCO Semcosoft 5.3 allows remote attackers to inject arbitrary ...
CVE-2018-20783——In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR readin...
CVE-2018-20122——The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1....
CVE-2018-20146——An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could...
CVE-2018-5819——An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can b...
CVE-2018-5818——An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be ...
CVE-2018-5817——A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_...
CVE-2018-20030——An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be explo...
CVE-2018-20241——The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to ...
CVE-2018-20240——The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers t...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now