2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14043 | — | — | 1.7% | Jul 13, 2018 | mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_ac... |
| CVE-2018-14042 | — | — | 4.0% | Jul 13, 2018 | In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip. |
| CVE-2018-14041 | — | — | 4.3% | Jul 13, 2018 | In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. |
| CVE-2018-14040 | — | — | 4.1% | Jul 13, 2018 | In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. |
| CVE-2018-6969 | — | — | 0.4% | Jul 13, 2018 | VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitatio... |
| CVE-2018-14036 | — | — | 3.1% | Jul 13, 2018 | Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in ... |
| CVE-2018-14035 | — | — | 1.2% | Jul 13, 2018 | An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5VM_memc... |
| CVE-2018-14034 | — | — | 1.2% | Jul 13, 2018 | An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5O_pline_reset i... |
| CVE-2018-14033 | — | — | 1.6% | Jul 13, 2018 | An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_layou... |
| CVE-2018-14032 | — | — | — | Jul 13, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11206. Reason: This candidate is a reservation ... |
| CVE-2018-14031 | — | — | 1.6% | Jul 13, 2018 | An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy ... |
| CVE-2018-14029 | — | — | 2.5% | Jul 13, 2018 | CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as dem... |
| CVE-2018-14014 | — | — | 0.5% | Jul 12, 2018 | In waimai Super Cms 20150505, there is a CSRF vulnerability that can add an admin account via admin.php?m=Member&a=admin... |
| CVE-2018-14012 | — | — | 1.6% | Jul 12, 2018 | WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI. |
| CVE-2018-5529 | — | — | 0.5% | Jul 12, 2018 | The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged proces... |
| CVE-2018-13796 | — | — | 2.5% | Jul 12, 2018 | An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web pa... |
| CVE-2018-13458 | — | — | 4.5% | Jul 12, 2018 | qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to... |
| CVE-2018-13457 | — | — | 4.5% | Jul 12, 2018 | qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to... |
| CVE-2018-13441 | — | — | 1.3% | Jul 12, 2018 | qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows atta... |
| CVE-2018-14004 | — | — | 0.9% | Jul 12, 2018 | An integer overflow vulnerability exists in the function transfer_tokens_after_ICO of GlobeCoin (GLB), an Ethereum token... |
| CVE-2018-14002 | — | — | 1.2% | Jul 12, 2018 | An integer overflow vulnerability exists in the function distribute of MP3 Coin (MP3), an Ethereum token smart contract.... |
| CVE-2018-14001 | — | — | 1.2% | Jul 12, 2018 | An integer overflow vulnerability exists in the function batchTransfer of SHARKTECH (SKT), an Ethereum token smart contr... |
| CVE-2018-13836 | — | — | 1.2% | Jul 12, 2018 | An integer overflow vulnerability exists in the function multiTransfer of Rocket Coin (XRC), an Ethereum token smart con... |
| CVE-2018-12540 | — | — | 2.0% | Jul 12, 2018 | In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returne... |
| CVE-2018-8024 | — | — | 5.0% | Jul 12, 2018 | In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointin... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now