2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11864 | — | — | 0.2% | Feb 25, 2019 | Bytes can be written to fuses from Secure region which can be read later by HLOS in Snapdragon Auto, Snapdragon Compute,... |
| CVE-2018-11845 | — | — | 0.2% | Feb 25, 2019 | Usage of non-time-constant comparison functions can lead to information leakage through side channel analysis in Snapdra... |
| CVE-2018-11820 | — | — | 0.2% | Feb 25, 2019 | Use of non-time constant memcmp function creates side channel that leaks information and leads to cryptographic issues i... |
| CVE-2018-11289 | — | — | 0.2% | Feb 25, 2019 | Data truncation during higher to lower type conversion which causes less memory allocation than desired can lead to a bu... |
| CVE-2018-20795 | — | — | 3.5% | Feb 25, 2019 | tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path p... |
| CVE-2018-20794 | — | — | 4.0% | Feb 25, 2019 | tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via pat... |
| CVE-2018-20793 | — | — | 5.0% | Feb 25, 2019 | tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[... |
| CVE-2018-20792 | — | — | 3.5% | Feb 25, 2019 | tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path pa... |
| CVE-2018-20791 | — | — | 0.8% | Feb 25, 2019 | tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mis... |
| CVE-2018-20790 | — | — | 3.6% | Feb 25, 2019 | tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0]... |
| CVE-2018-20789 | — | — | 3.6% | Feb 25, 2019 | tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a pat... |
| CVE-2018-20788 | — | — | 0.8% | Feb 25, 2019 | drivers/leds/leds-aw2023.c in the led driver for custom Linux kernels on the Xiaomi Redmi 6pro daisy-o-oss phone has sev... |
| CVE-2018-20787 | — | — | 0.8% | Feb 25, 2019 | The ft5x46 touchscreen driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has a... |
| CVE-2018-20786 | — | — | 3.0% | Feb 24, 2019 | libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a ... |
| CVE-2018-20785 | — | — | 0.5% | Feb 23, 2019 | Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM... |
| CVE-2018-18692 | — | — | 1.0% | Feb 23, 2019 | A reflected Cross-Site scripting (XSS) vulnerability in SEMCO Semcosoft 5.3 allows remote attackers to inject arbitrary ... |
| CVE-2018-20783 | — | — | 5.7% | Feb 21, 2019 | In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR readin... |
| CVE-2018-20122 | — | — | 4.8% | Feb 21, 2019 | The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.... |
| CVE-2018-20146 | — | — | 0.4% | Feb 21, 2019 | An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could... |
| CVE-2018-5819 | — | — | 2.8% | Feb 20, 2019 | An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can b... |
| CVE-2018-5818 | — | — | 2.3% | Feb 20, 2019 | An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be ... |
| CVE-2018-5817 | — | — | 2.5% | Feb 20, 2019 | A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_... |
| CVE-2018-20030 | — | — | 3.8% | Feb 20, 2019 | An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be explo... |
| CVE-2018-20241 | — | — | 0.9% | Feb 20, 2019 | The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to ... |
| CVE-2018-20240 | — | — | 0.9% | Feb 20, 2019 | The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers t... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now