2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13031 | — | — | 1.1% | Jul 5, 2018 | DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account. |
| CVE-2018-12739 | — | — | 2.4% | Jul 5, 2018 | In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266. |
| CVE-2018-12571 | — | — | 30.3% | Jul 5, 2018 | uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to tr... |
| CVE-2018-12520 | HIGH | 8.1 | 10.7% | Jul 5, 2018 | An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seede... |
| CVE-2018-12113 | — | — | 7.0% | Jul 5, 2018 | Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code e... |
| CVE-2018-12103 | — | — | 0.5% | Jul 5, 2018 | An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta... |
| CVE-2018-10988 | — | — | 0.2% | Jul 5, 2018 | An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at bo... |
| CVE-2018-10987 | — | — | 3.0% | Jul 5, 2018 | An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated re... |
| CVE-2018-7944 | — | — | 0.3% | Jul 5, 2018 | Huawei smart phones Emily-AL00A with software 8.1.0.106(SP2C00) and 8.1.0.107(SP5C00) have a Factory Reset Protection (F... |
| CVE-2018-13328 | HIGH | 7.5 | 0.9% | Jul 5, 2018 | The transfer, transferFrom, and mint functions of a smart contract implementation for PFGc, an Ethereum token, have an i... |
| CVE-2018-13327 | HIGH | 7.5 | 1.2% | Jul 5, 2018 | The transfer and transferFrom functions of a smart contract implementation for ChuCunLingAIGO (CCLAG), an Ethereum token... |
| CVE-2018-13326 | HIGH | 7.5 | 1.2% | Jul 5, 2018 | The transfer and transferFrom functions of a smart contract implementation for Bittelux (BTX), an Ethereum token, have a... |
| CVE-2018-13325 | — | — | 0.9% | Jul 5, 2018 | The _sell function of a smart contract implementation for GROWCHAIN (GROW), an Ethereum token, has an integer overflow. |
| CVE-2018-12976 | — | — | 4.5% | Jul 5, 2018 | In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being ... |
| CVE-2018-12910 | — | — | 4.2% | Jul 5, 2018 | The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty... |
| CVE-2018-12691 | — | — | 0.7% | Jul 5, 2018 | Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS... |
| CVE-2018-12021 | — | — | 1.6% | Jul 5, 2018 | Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. Wh... |
| CVE-2018-13305 | — | — | 1.4% | Jul 5, 2018 | In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function ... |
| CVE-2018-13304 | — | — | 1.1% | Jul 5, 2018 | In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_prof... |
| CVE-2018-13303 | — | — | 1.4% | Jul 5, 2018 | In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in li... |
| CVE-2018-13302 | — | — | 2.2% | Jul 5, 2018 | In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independen... |
| CVE-2018-13301 | — | — | 1.4% | Jul 5, 2018 | In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header functio... |
| CVE-2018-13300 | — | — | 2.3% | Jul 5, 2018 | In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the ha... |
| CVE-2018-13252 | — | — | 0.7% | Jul 5, 2018 | Entrust Datacard Syntera CS 5.x has XSS via the name field of "Domain or Computer Name" in the login page. |
| CVE-2018-3769 | MEDIUM | 6.1 | 1.4% | Jul 5, 2018 | ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now