2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-14089An issue was discovered in a smart contract implementation for Virgo_ZodiacToken, an Ethereum token. In this contract, '...
CVE-2018-14088An issue was discovered in a smart contract implementation for STeX White List (STE(WL)), an Ethereum token. The contrac...
CVE-2018-14087CRITICAL9.8An issue was discovered in a smart contract implementation for EUC (EUC), an Ethereum token. The contract has an integer...
CVE-2018-14086CRITICAL9.8An issue was discovered in a smart contract implementation for SingaporeCoinOrigin (SCO), an Ethereum token. The contrac...
CVE-2018-14085An issue was discovered in a smart contract implementation for UserWallet 0x0a7bca9FB7AfF26c6ED8029BB6f0F5D291587c42, an...
CVE-2018-14084CRITICAL9.8An issue was discovered in a smart contract implementation for MKCB, an Ethereum token. If the owner sets the value of s...
CVE-2018-14073libsixel 1.8.1 has a memory leak in sixel_allocator_new in allocator.c.
CVE-2018-14072libsixel 1.8.1 has a memory leak in sixel_decoder_decode in decoder.c, image_buffer_resize in fromsixel.c, and sixel_dec...
CVE-2018-14069An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add a user account via admin.php?m=Admin...
CVE-2018-14068An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add an admin account via admin.php?m=Adm...
CVE-2018-14066The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phone...
CVE-2018-14065XMLReader.php in PHPOffice Common before 0.2.9 allows XXE.
CVE-2018-14064The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../.....
CVE-2018-14063The increaseApproval function of a smart contract implementation for Tracto (TRCT), an Ethereum ERC20 token, has an inte...
CVE-2018-14060OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D befo...
CVE-2018-14010OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.1...
CVE-2018-14056ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intende...
CVE-2018-14055ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to es...
CVE-2018-10875HIGH7.8A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it poin...
CVE-2018-8847CRITICAL9.8Eaton 9000X DriveA versions 2.0.29 and prior has a stack-based buffer overflow vulnerability, which may allow remote cod...
CVE-2018-10631MEDIUM6.3The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical...
CVE-2018-1000211Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorize...
CVE-2018-1000210YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior o...
CVE-2018-1000209Sensu, Inc. Sensu Core version Before version 1.4.2-3 contains a Insecure Permissions vulnerability in Sensu Core on Win...
CVE-2018-1000208MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now