2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-13466The mintToken function of a smart contract implementation for Crystals, an Ethereum token, has an integer overflow that ...
CVE-2018-13465The mintToken function of a smart contract implementation for PaulyCoin, an Ethereum token, has an integer overflow that...
CVE-2018-13464The mintToken function of a smart contract implementation for t_swap, an Ethereum token, has an integer overflow that al...
CVE-2018-13463The mintToken function of a smart contract implementation for T-Swap-Token (T-S-T), an Ethereum token, has an integer ov...
CVE-2018-13462The mintToken function of a smart contract implementation for MoonToken, an Ethereum token, has an integer overflow that...
CVE-2018-13450SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arb...
CVE-2018-13449SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arb...
CVE-2018-13448SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arb...
CVE-2018-13447SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arb...
CVE-2018-13445An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add a user account via adm1n/admin_manage...
CVE-2018-13444An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add an admin account via adm1n/admin_mana...
CVE-2018-13440The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.c...
CVE-2018-13439WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.
CVE-2018-13433Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG ele...
CVE-2018-13423admin/themes/default/items/tag-form.php in Omeka before 2.6.1 allows XSS by adding or editing a tag.
CVE-2018-13422TCExam before 14.1.2 has XSS via an ff_ or xl_ field.
CVE-2018-13421Fast C++ CSV Parser (aka fast-cpp-csv-parser) before 2018-07-06 has a heap-based buffer over-read in io::trim_chars in c...
CVE-2018-13420Google gperftools 2.7 has a memory leak in malloc_extension.cc, related to MallocExtension::Register and InitModule. NOT...
CVE-2018-13419An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by snd...
CVE-2018-11351script.php in Jirafeau before 3.4.1 is affected by two stored Cross-Site Scripting (XSS) vulnerabilities. These are stor...
CVE-2018-11350An issue was discovered in Jirafeau before 3.4.1. The file "search by name" form is affected by one Cross-Site Scripting...
CVE-2018-11349The administration panel of Jirafeau before 3.4.1 is vulnerable to three CSRF attacks on search functionalities: search_...
CVE-2018-5907Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that lead...
CVE-2018-5886A pointer in an ADSPRPC command is not properly validated in all Android releases from CAF using the Linux kernel (Andro...
CVE-2018-5872While parsing over-the-air information elements in all Android releases from CAF using the Linux kernel (Android for MSM...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now