2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-17968A gambling smart contract implementation for RuletkaIo, an Ethereum gambling game, generates a random value that is pred...
CVE-2018-17877A lottery smart contract implementation for Greedy 599, an Ethereum gambling game, generates a random value that is pred...
CVE-2018-17873An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 ...
CVE-2018-17448An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10....
CVE-2018-17447An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before...
CVE-2018-17446A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 1...
CVE-2018-17445A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x befo...
CVE-2018-17444A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x be...
CVE-2018-16235Telligent Community 6.x, 7.x, 8.x, 9.x before 9.2.10.11796, 10.1.x before 10.1.10.11792, and 10.2.x before 10.2.3.4725 h...
CVE-2018-16226A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could a...
CVE-2018-15497The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality....
CVE-2018-12901A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an...
CVE-2018-18628An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStrea...
CVE-2018-14828Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to...
CVE-2018-14820Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path ...
CVE-2018-14806Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrar...
CVE-2018-18626An issue was discovered in PHPYun V4.6. There is a vulnerability that can delete any file or directory via the "admin/in...
CVE-2018-18622An issue was discovered in Waimai Super Cms 20150505. There is XSS via the index.php?m=public&a=doregister username para...
CVE-2018-18608DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is u...
CVE-2018-8569A remote code execution vulnerability exists in the Yammer desktop application due to the loading of arbitrary content, ...
CVE-2018-18607An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as ...
CVE-2018-18606An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd...
CVE-2018-18605A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File D...
CVE-2018-18603360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.s...
CVE-2018-18599Stegdetect through 2018-05-26 has an out-of-bounds write in f5_compress in the f5.c file.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now