2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-14002An integer overflow vulnerability exists in the function distribute of MP3 Coin (MP3), an Ethereum token smart contract....
CVE-2018-14001An integer overflow vulnerability exists in the function batchTransfer of SHARKTECH (SKT), an Ethereum token smart contr...
CVE-2018-13836An integer overflow vulnerability exists in the function multiTransfer of Rocket Coin (XRC), an Ethereum token smart con...
CVE-2018-12540In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returne...
CVE-2018-8024In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointin...
CVE-2018-1334In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different l...
CVE-2018-13999Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administ...
CVE-2018-13998ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.
CVE-2018-13997Genann through 2018-07-08 has a SEGV in genann_run in genann.c.
CVE-2018-13996Genann through 2018-07-08 has a stack-based buffer over-read in genann_train in genann.c.
CVE-2018-10895CRITICAL9.3qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute...
CVE-2018-11049RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled searc...
CVE-2018-11045Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a st...
CVE-2018-0042Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnera...
CVE-2018-0041CRITICAL9.8Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone ser...
CVE-2018-0040CRITICAL9.8Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys...
CVE-2018-0039MEDIUM6.5Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with har...
CVE-2018-0038Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with h...
CVE-2018-0037CRITICAL9.8Junos OS routing protocol daemon (RPD) process may crash and restart or may lead to remote code execution while processi...
CVE-2018-0035MEDIUM4.4QFX5200 and QFX10002 devices that have been shipped with Junos OS 15.1X53-D21, 15.1X53-D30, 15.1X53-D31, 15.1X53-D32, 15...
CVE-2018-0034MEDIUM5.3A Denial of Service vulnerability exists in the Juniper Networks Junos OS JDHCPD daemon which allows an attacker to core...
CVE-2018-0032HIGH7.5The receipt of a crafted BGP UPDATE can lead to a routing process daemon (RPD) crash and restart. Repeated receipt of th...
CVE-2018-0031MEDIUM5.3Receipt of specially crafted UDP/IP packets over MPLS may be able to bypass a stateless firewall filter. The crafted UDP...
CVE-2018-0030HIGH7.5Receipt of a specific MPLS packet may cause MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) line cards or PTX1K to crash and restart...
CVE-2018-0029MEDIUM5.7While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interfac...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now