2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-13031DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account.
CVE-2018-12739In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.
CVE-2018-12571uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to tr...
CVE-2018-12520HIGH8.1An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seede...
CVE-2018-12113Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code e...
CVE-2018-12103An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta...
CVE-2018-10988An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at bo...
CVE-2018-10987An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated re...
CVE-2018-7944Huawei smart phones Emily-AL00A with software 8.1.0.106(SP2C00) and 8.1.0.107(SP5C00) have a Factory Reset Protection (F...
CVE-2018-13328HIGH7.5The transfer, transferFrom, and mint functions of a smart contract implementation for PFGc, an Ethereum token, have an i...
CVE-2018-13327HIGH7.5The transfer and transferFrom functions of a smart contract implementation for ChuCunLingAIGO (CCLAG), an Ethereum token...
CVE-2018-13326HIGH7.5The transfer and transferFrom functions of a smart contract implementation for Bittelux (BTX), an Ethereum token, have a...
CVE-2018-13325The _sell function of a smart contract implementation for GROWCHAIN (GROW), an Ethereum token, has an integer overflow.
CVE-2018-12976In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being ...
CVE-2018-12910The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty...
CVE-2018-12691Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS...
CVE-2018-12021Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. Wh...
CVE-2018-13305In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function ...
CVE-2018-13304In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_prof...
CVE-2018-13303In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in li...
CVE-2018-13302In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independen...
CVE-2018-13301In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header functio...
CVE-2018-13300In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the ha...
CVE-2018-13252Entrust Datacard Syntera CS 5.x has XSS via the name field of "Domain or Computer Name" in the login page.
CVE-2018-3769MEDIUM6.1ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now