2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13466 | — | — | 1.1% | Jul 9, 2018 | The mintToken function of a smart contract implementation for Crystals, an Ethereum token, has an integer overflow that ... |
| CVE-2018-13465 | — | — | 1.1% | Jul 9, 2018 | The mintToken function of a smart contract implementation for PaulyCoin, an Ethereum token, has an integer overflow that... |
| CVE-2018-13464 | — | — | 1.1% | Jul 9, 2018 | The mintToken function of a smart contract implementation for t_swap, an Ethereum token, has an integer overflow that al... |
| CVE-2018-13463 | — | — | 1.0% | Jul 9, 2018 | The mintToken function of a smart contract implementation for T-Swap-Token (T-S-T), an Ethereum token, has an integer ov... |
| CVE-2018-13462 | — | — | 1.1% | Jul 9, 2018 | The mintToken function of a smart contract implementation for MoonToken, an Ethereum token, has an integer overflow that... |
| CVE-2018-13450 | — | — | 1.9% | Jul 8, 2018 | SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arb... |
| CVE-2018-13449 | — | — | 1.9% | Jul 8, 2018 | SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arb... |
| CVE-2018-13448 | — | — | 1.9% | Jul 8, 2018 | SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arb... |
| CVE-2018-13447 | — | — | 1.9% | Jul 8, 2018 | SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arb... |
| CVE-2018-13445 | — | — | 0.5% | Jul 8, 2018 | An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add a user account via adm1n/admin_manage... |
| CVE-2018-13444 | — | — | 0.5% | Jul 8, 2018 | An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add an admin account via adm1n/admin_mana... |
| CVE-2018-13440 | — | — | 3.1% | Jul 8, 2018 | The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.c... |
| CVE-2018-13439 | — | — | 1.9% | Jul 8, 2018 | WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL. |
| CVE-2018-13433 | — | — | 0.9% | Jul 8, 2018 | Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG ele... |
| CVE-2018-13423 | — | — | 0.9% | Jul 7, 2018 | admin/themes/default/items/tag-form.php in Omeka before 2.6.1 allows XSS by adding or editing a tag. |
| CVE-2018-13422 | — | — | 0.8% | Jul 7, 2018 | TCExam before 14.1.2 has XSS via an ff_ or xl_ field. |
| CVE-2018-13421 | — | — | 1.8% | Jul 7, 2018 | Fast C++ CSV Parser (aka fast-cpp-csv-parser) before 2018-07-06 has a heap-based buffer over-read in io::trim_chars in c... |
| CVE-2018-13420 | — | — | 1.5% | Jul 7, 2018 | Google gperftools 2.7 has a memory leak in malloc_extension.cc, related to MallocExtension::Register and InitModule. NOT... |
| CVE-2018-13419 | — | — | 1.3% | Jul 7, 2018 | An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by snd... |
| CVE-2018-11351 | — | — | 1.2% | Jul 7, 2018 | script.php in Jirafeau before 3.4.1 is affected by two stored Cross-Site Scripting (XSS) vulnerabilities. These are stor... |
| CVE-2018-11350 | — | — | 0.7% | Jul 7, 2018 | An issue was discovered in Jirafeau before 3.4.1. The file "search by name" form is affected by one Cross-Site Scripting... |
| CVE-2018-11349 | — | — | 0.5% | Jul 7, 2018 | The administration panel of Jirafeau before 3.4.1 is vulnerable to three CSRF attacks on search functionalities: search_... |
| CVE-2018-5907 | — | — | 0.2% | Jul 6, 2018 | Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that lead... |
| CVE-2018-5886 | — | — | 0.6% | Jul 6, 2018 | A pointer in an ADSPRPC command is not properly validated in all Android releases from CAF using the Linux kernel (Andro... |
| CVE-2018-5872 | — | — | 0.5% | Jul 6, 2018 | While parsing over-the-air information elements in all Android releases from CAF using the Linux kernel (Android for MSM... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now