2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14035 | — | — | 1.2% | Jul 13, 2018 | An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5VM_memc... |
| CVE-2018-14034 | — | — | 1.2% | Jul 13, 2018 | An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5O_pline_reset i... |
| CVE-2018-14033 | — | — | 1.6% | Jul 13, 2018 | An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_layou... |
| CVE-2018-14032 | — | — | — | Jul 13, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11206. Reason: This candidate is a reservation ... |
| CVE-2018-14031 | — | — | 1.6% | Jul 13, 2018 | An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy ... |
| CVE-2018-14029 | — | — | 2.5% | Jul 13, 2018 | CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as dem... |
| CVE-2018-14017 | MEDIUM | 5.5 | 1.2% | Jul 12, 2018 | The r_bin_java_annotation_new function in shlr/java/class.c in radare2 2.7.0 allows remote attackers to cause a denial o... |
| CVE-2018-14016 | MEDIUM | 5.5 | 1.2% | Jul 12, 2018 | The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows remote attackers to cause a denial of ser... |
| CVE-2018-14015 | MEDIUM | 5.5 | 1.2% | Jul 12, 2018 | The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid re... |
| CVE-2018-14014 | — | — | 0.5% | Jul 12, 2018 | In waimai Super Cms 20150505, there is a CSRF vulnerability that can add an admin account via admin.php?m=Member&a=admin... |
| CVE-2018-14012 | — | — | 1.6% | Jul 12, 2018 | WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI. |
| CVE-2018-5529 | — | — | 0.5% | Jul 12, 2018 | The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged proces... |
| CVE-2018-13796 | — | — | 2.5% | Jul 12, 2018 | An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web pa... |
| CVE-2018-13458 | — | — | 4.5% | Jul 12, 2018 | qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to... |
| CVE-2018-13457 | — | — | 4.5% | Jul 12, 2018 | qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to... |
| CVE-2018-13441 | — | — | 1.3% | Jul 12, 2018 | qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows atta... |
| CVE-2018-12981 | MEDIUM | 5.4 | 5.2% | Jul 12, 2018 | An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit... |
| CVE-2018-12980 | HIGH | 8.8 | 30.1% | Jul 12, 2018 | An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit... |
| CVE-2018-12979 | MEDIUM | 6.5 | 7.9% | Jul 12, 2018 | An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions... |
| CVE-2018-14009 | CRITICAL | 9.8 | 38.4% | Jul 12, 2018 | Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689. |
| CVE-2018-12463 | CRITICAL | 9.8 | 13.8% | Jul 12, 2018 | An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows re... |
| CVE-2018-14006 | HIGH | 7.5 | 0.9% | Jul 12, 2018 | An integer overflow vulnerability exists in the function multipleTransfer of Neo Genesis Token (NGT), an Ethereum token ... |
| CVE-2018-14005 | HIGH | 7.5 | 0.9% | Jul 12, 2018 | An integer overflow vulnerability exists in the function transferAny of Malaysia coins (Xmc), an Ethereum token smart co... |
| CVE-2018-14004 | — | — | 0.9% | Jul 12, 2018 | An integer overflow vulnerability exists in the function transfer_tokens_after_ICO of GlobeCoin (GLB), an Ethereum token... |
| CVE-2018-14003 | HIGH | 7.5 | 1.2% | Jul 12, 2018 | An integer overflow vulnerability exists in the function batchTransfer of WeMediaChain (WMC), an Ethereum token smart co... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now