2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13849 | — | — | 2.3% | Jul 10, 2018 | edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequ... |
| CVE-2018-13848 | — | — | 1.4% | Jul 10, 2018 | An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4_StszAtom::GetSampleSize in Core/Ap4StszAtom.cpp. |
| CVE-2018-13847 | — | — | 1.5% | Jul 10, 2018 | An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4_StcoAtom::AdjustChunkOffsets in Core/Ap4StcoAtom.cpp. |
| CVE-2018-13846 | — | — | 1.7% | Jul 10, 2018 | An issue has been found in Bento4 1.5.1-624. AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap... |
| CVE-2018-13845 | — | — | 1.6% | Jul 10, 2018 | An issue has been found in HTSlib 1.8. It is a buffer over-read in sam_parse1 in sam.c. |
| CVE-2018-13843 | — | — | 1.5% | Jul 10, 2018 | An issue has been found in HTSlib 1.8. It is a memory leak in bgzf_getline in bgzf.c. NOTE: the software maintainer's po... |
| CVE-2018-1331 | — | — | 4.5% | Jul 10, 2018 | In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker wi... |
| CVE-2018-13833 | — | — | 1.6% | Jul 10, 2018 | An issue was discovered in cmft through 2017-09-24. The cmft::rwReadFile function in image.cpp allows remote attackers t... |
| CVE-2018-10943 | — | — | 1.1% | Jul 10, 2018 | An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3. Sending an arbit... |
| CVE-2018-9853 | — | — | 1.3% | Jul 10, 2018 | Insecure access control in freeSSHd version 1.3.1 allows attackers to obtain the privileges of the freesshd.exe process ... |
| CVE-2018-13818 | — | — | 7.0% | Jul 10, 2018 | Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor poi... |
| CVE-2018-1129 | — | — | 1.9% | Jul 10, 2018 | A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having acces... |
| CVE-2018-1128 | — | — | 1.4% | Jul 10, 2018 | It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attac... |
| CVE-2018-10861 | — | — | 3.2% | Jul 10, 2018 | A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can d... |
| CVE-2018-13389 | — | — | 1.0% | Jul 10, 2018 | The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the... |
| CVE-2018-13388 | — | — | 0.9% | Jul 10, 2018 | The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject ... |
| CVE-2018-1337 | — | — | 5.3% | Jul 10, 2018 | In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread... |
| CVE-2018-13797 | — | — | 6.7% | Jul 10, 2018 | The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsaniti... |
| CVE-2018-12230 | — | — | 0.9% | Jul 10, 2018 | An wrong logical check identified in the transferFrom function of a smart contract implementation for RemiCoin (RMC), an... |
| CVE-2018-13795 | — | — | 1.5% | Jul 9, 2018 | Gravity before 0.5.1 does not support a maximum recursion depth. |
| CVE-2018-13793 | — | — | 0.5% | Jul 9, 2018 | Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Upd... |
| CVE-2018-13791 | — | — | 1.1% | Jul 9, 2018 | The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via... |
| CVE-2018-11450 | — | — | 0.8% | Jul 9, 2018 | A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). ... |
| CVE-2018-1000623 | — | — | 2.8% | Jul 9, 2018 | JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability... |
| CVE-2018-1000622 | — | — | 1.8% | Jul 9, 2018 | The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Elemen... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now