2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13388 | — | — | 0.9% | Jul 10, 2018 | The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject ... |
| CVE-2018-1337 | — | — | 5.3% | Jul 10, 2018 | In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread... |
| CVE-2018-13797 | — | — | 6.7% | Jul 10, 2018 | The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsaniti... |
| CVE-2018-12230 | — | — | 0.9% | Jul 10, 2018 | An wrong logical check identified in the transferFrom function of a smart contract implementation for RemiCoin (RMC), an... |
| CVE-2018-13795 | — | — | 1.5% | Jul 9, 2018 | Gravity before 0.5.1 does not support a maximum recursion depth. |
| CVE-2018-13794 | CRITICAL | 9.8 | 1.5% | Jul 9, 2018 | A heap-based buffer overflow exists in stbi__bmp_load_cont in stb_image.h in catimg 2.4.0. |
| CVE-2018-13793 | — | — | 0.5% | Jul 9, 2018 | Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Upd... |
| CVE-2018-13791 | — | — | 1.1% | Jul 9, 2018 | The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via... |
| CVE-2018-6967 | HIGH | 8.1 | 2.3% | Jul 9, 2018 | VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain... |
| CVE-2018-6966 | HIGH | 8.1 | 2.3% | Jul 9, 2018 | VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain... |
| CVE-2018-6965 | HIGH | 8.1 | 3.0% | Jul 9, 2018 | VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain... |
| CVE-2018-13790 | HIGH | 7.2 | 1.0% | Jul 9, 2018 | A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to at... |
| CVE-2018-11450 | — | — | 0.8% | Jul 9, 2018 | A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). ... |
| CVE-2018-1000623 | — | — | 2.8% | Jul 9, 2018 | JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability... |
| CVE-2018-1000622 | — | — | 1.8% | Jul 9, 2018 | The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Elemen... |
| CVE-2018-1000621 | — | — | 2.6% | Jul 9, 2018 | Mycroft AI mycroft-core version 18.2.8b and earlier contains a Incorrect Access Control vulnerability in Websocket confi... |
| CVE-2018-1000620 | CRITICAL | 9.8 | 1.7% | Jul 9, 2018 | Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() met... |
| CVE-2018-1000619 | — | — | 2.3% | Jul 9, 2018 | Ovidentia version 8.4.3 and earlier contains a Unsanitized User Input vulnerability in utilit.php, bab_getAddonFilePathf... |
| CVE-2018-1000618 | — | — | 1.5% | Jul 9, 2018 | EOSIO/eos eos version after commit f1545dd0ae2b77580c2236fdb70ae7138d2c7168 contains a stack overflow vulnerability in a... |
| CVE-2018-1000617 | — | — | 1.8% | Jul 9, 2018 | Atlassian Floodlight Atlassian Floodlight Controller version 1.2 and earlier versions contains a Denial of Service vulne... |
| CVE-2018-1000616 | — | — | 1.4% | Jul 9, 2018 | ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utili... |
| CVE-2018-1000615 | — | — | 1.2% | Jul 9, 2018 | ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB comp... |
| CVE-2018-1000614 | — | — | 1.6% | Jul 9, 2018 | ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/... |
| CVE-2018-1000613 | CRITICAL | 9.8 | 4.8% | Jul 9, 2018 | Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contain... |
| CVE-2018-1000611 | — | — | 0.8% | Jul 9, 2018 | SURFnet OpenConext EngineBlock version 5.7.0 to 5.7.3 contains a Cross Site Scripting (XSS) vulnerability that can resul... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now