2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-13849edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequ...
CVE-2018-13848An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4_StszAtom::GetSampleSize in Core/Ap4StszAtom.cpp.
CVE-2018-13847An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4_StcoAtom::AdjustChunkOffsets in Core/Ap4StcoAtom.cpp.
CVE-2018-13846An issue has been found in Bento4 1.5.1-624. AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap...
CVE-2018-13845An issue has been found in HTSlib 1.8. It is a buffer over-read in sam_parse1 in sam.c.
CVE-2018-13843An issue has been found in HTSlib 1.8. It is a memory leak in bgzf_getline in bgzf.c. NOTE: the software maintainer's po...
CVE-2018-1331In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker wi...
CVE-2018-13833An issue was discovered in cmft through 2017-09-24. The cmft::rwReadFile function in image.cpp allows remote attackers t...
CVE-2018-10943An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3. Sending an arbit...
CVE-2018-9853Insecure access control in freeSSHd version 1.3.1 allows attackers to obtain the privileges of the freesshd.exe process ...
CVE-2018-13818Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor poi...
CVE-2018-1129A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having acces...
CVE-2018-1128It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attac...
CVE-2018-10861A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can d...
CVE-2018-13389The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the...
CVE-2018-13388The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject ...
CVE-2018-1337In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread...
CVE-2018-13797The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsaniti...
CVE-2018-12230An wrong logical check identified in the transferFrom function of a smart contract implementation for RemiCoin (RMC), an...
CVE-2018-13795Gravity before 0.5.1 does not support a maximum recursion depth.
CVE-2018-13793Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Upd...
CVE-2018-13791The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via...
CVE-2018-11450A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). ...
CVE-2018-1000623JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability...
CVE-2018-1000622The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Elemen...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now