2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-14043mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_ac...
CVE-2018-14042In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
CVE-2018-14041In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
CVE-2018-14040In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
CVE-2018-6969VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitatio...
CVE-2018-14036Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in ...
CVE-2018-14035An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5VM_memc...
CVE-2018-14034An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5O_pline_reset i...
CVE-2018-14033An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_layou...
CVE-2018-14032Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11206. Reason: This candidate is a reservation ...
CVE-2018-14031An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy ...
CVE-2018-14029CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as dem...
CVE-2018-14014In waimai Super Cms 20150505, there is a CSRF vulnerability that can add an admin account via admin.php?m=Member&a=admin...
CVE-2018-14012WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI.
CVE-2018-5529The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged proces...
CVE-2018-13796An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web pa...
CVE-2018-13458qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to...
CVE-2018-13457qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to...
CVE-2018-13441qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows atta...
CVE-2018-14004An integer overflow vulnerability exists in the function transfer_tokens_after_ICO of GlobeCoin (GLB), an Ethereum token...
CVE-2018-14002An integer overflow vulnerability exists in the function distribute of MP3 Coin (MP3), an Ethereum token smart contract....
CVE-2018-14001An integer overflow vulnerability exists in the function batchTransfer of SHARKTECH (SKT), an Ethereum token smart contr...
CVE-2018-13836An integer overflow vulnerability exists in the function multiTransfer of Rocket Coin (XRC), an Ethereum token smart con...
CVE-2018-12540In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returne...
CVE-2018-8024In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointin...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now