2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-11864Bytes can be written to fuses from Secure region which can be read later by HLOS in Snapdragon Auto, Snapdragon Compute,...
CVE-2018-11845Usage of non-time-constant comparison functions can lead to information leakage through side channel analysis in Snapdra...
CVE-2018-11820Use of non-time constant memcmp function creates side channel that leaks information and leads to cryptographic issues i...
CVE-2018-11289Data truncation during higher to lower type conversion which causes less memory allocation than desired can lead to a bu...
CVE-2018-20795tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path p...
CVE-2018-20794tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via pat...
CVE-2018-20793tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[...
CVE-2018-20792tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path pa...
CVE-2018-20791tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mis...
CVE-2018-20790tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0]...
CVE-2018-20789tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a pat...
CVE-2018-20788drivers/leds/leds-aw2023.c in the led driver for custom Linux kernels on the Xiaomi Redmi 6pro daisy-o-oss phone has sev...
CVE-2018-20787The ft5x46 touchscreen driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has a...
CVE-2018-20786libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a ...
CVE-2018-20785Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM...
CVE-2018-18692A reflected Cross-Site scripting (XSS) vulnerability in SEMCO Semcosoft 5.3 allows remote attackers to inject arbitrary ...
CVE-2018-20783In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR readin...
CVE-2018-20122The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1....
CVE-2018-20146An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could...
CVE-2018-5819An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can b...
CVE-2018-5818An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be ...
CVE-2018-5817A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_...
CVE-2018-20030An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be explo...
CVE-2018-20241The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to ...
CVE-2018-20240The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers t...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now