2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-12056The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random...
CVE-2018-11687An integer overflow in the distributeBTR function of a smart contract implementation for Bitcoin Red (BTCR), an Ethereum...
CVE-2018-10369A Cross-site scripting (XSS) vulnerability was discovered on Intelbras Win 240 V1.1.0 devices. An attacker can change th...
CVE-2018-0952An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary...
CVE-2018-6973VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in ...
CVE-2018-13394The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Ques...
CVE-2018-13393The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confl...
CVE-2018-12539In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Ec...
CVE-2018-12537In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter car...
CVE-2018-14922Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web ...
CVE-2018-14888inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or threa...
CVE-2018-14429man-cgi before 1.16 allows Local File Inclusion via absolute path traversal, as demonstrated by a cgi-bin/man-cgi?/etc/p...
CVE-2018-14424The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destr...
CVE-2018-14348libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to ...
CVE-2018-5392mingw-w64 version 5.0.4 by default produces executables that opt in to ASLR, but are not compatible with ASLR. ASLR is a...
CVE-2018-2451XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced ...
CVE-2018-2450SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted data...
CVE-2018-2449SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authenticat...
CVE-2018-2448Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to ac...
CVE-2018-2447SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute craft...
CVE-2018-2445AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnera...
CVE-2018-2444SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, r...
CVE-2018-2442In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI...
CVE-2018-2441Under certain conditions the SAP Change and Transport System (ABAP), SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNE...
CVE-2018-0131A vulnerability in the implementation of RSA-encrypted nonces in Cisco IOS Software and Cisco IOS XE Software could allo...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now