2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-14063The increaseApproval function of a smart contract implementation for Tracto (TRCT), an Ethereum ERC20 token, has an inte...
CVE-2018-14060OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D befo...
CVE-2018-14010OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.1...
CVE-2018-14056ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intende...
CVE-2018-14055ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to es...
CVE-2018-1000211Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorize...
CVE-2018-1000210YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior o...
CVE-2018-1000209Sensu, Inc. Sensu Core version Before version 1.4.2-3 contains a Insecure Permissions vulnerability in Sensu Core on Win...
CVE-2018-1000208MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class...
CVE-2018-1000207MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before pa...
CVE-2018-1000206JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that...
CVE-2018-7535An issue was discovered in TotalAV v4.1.7. An unprivileged user could modify or overwrite all of the product's files bec...
CVE-2018-14054A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0. A dangling pointer is freed again...
CVE-2018-10098In MicroWorld eScan Internet Security Suite (ISS) for Business 14.0.1400.2029, the driver econceal.sys allows a non-priv...
CVE-2018-10018The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a lo...
CVE-2018-9070For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart ...
CVE-2018-9067The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, i...
CVE-2018-14052An issue has been found in libwav through 2017-04-20. It is a SEGV in the function apply_gain in wav_gain/wav_gain.c.
CVE-2018-14051The function wav_read in libwav.c in libwav through 2017-04-20 has an infinite loop.
CVE-2018-14050An issue has been found in libwav through 2017-04-20. It is a SEGV in the function wav_free in libwav.c.
CVE-2018-14049An issue has been found in libwav through 2017-04-20. It is a SEGV in the function print_info in wav_info/wav_info.c.
CVE-2018-14047An issue has been found in PNGwriter 0.7.0. It is a SEGV in pngwriter::readfromfile in pngwriter.cc. NOTE: there is a "W...
CVE-2018-14046Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.
CVE-2018-14045The FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows...
CVE-2018-14044The RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allo...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now