2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3768 | — | — | — | Jul 5, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1000539. Reason: This candidate is a reservati... |
| CVE-2018-3767 | — | — | 1.5% | Jul 5, 2018 | `memjs` versions <= 1.1.0 allocates and stores buffers on typed input, resulting in DoS and uninitialized memory usage. |
| CVE-2018-3766 | HIGH | 7.5 | 1.9% | Jul 5, 2018 | Path traversal in buttle module versions <= 0.2.0 allows to read any file in the server. |
| CVE-2018-3764 | MEDIUM | 4.8 | 0.6% | Jul 5, 2018 | In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a s... |
| CVE-2018-3763 | MEDIUM | 4.8 | 0.6% | Jul 5, 2018 | In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could l... |
| CVE-2018-3762 | MEDIUM | 4.3 | 0.9% | Jul 5, 2018 | Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowi... |
| CVE-2018-3761 | HIGH | 8.1 | 1.7% | Jul 5, 2018 | Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing chec... |
| CVE-2018-8026 | — | — | 9.0% | Jul 5, 2018 | This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in... |
| CVE-2018-13251 | — | — | 1.5% | Jul 5, 2018 | In libming 0.4.8, there is an excessive memory allocation attempt in the readBytes function of the util/read.c file, rel... |
| CVE-2018-13250 | — | — | 1.5% | Jul 5, 2018 | libming 0.4.8 has a NULL pointer dereference in the getString function of the decompile.c file, related to decompileSTRI... |
| CVE-2018-9185 | — | — | 2.1% | Jul 5, 2018 | An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login cre... |
| CVE-2018-8928 | MEDIUM | 6.5 | 0.8% | Jul 5, 2018 | Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remo... |
| CVE-2018-8038 | — | — | 10.7% | Jul 5, 2018 | Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing t... |
| CVE-2018-10885 | MEDIUM | 6.5 | 1.6% | Jul 5, 2018 | In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash ... |
| CVE-2018-13233 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for GSI, an Ethereum token, has an integer overflow in which "amoun... |
| CVE-2018-13232 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has... |
| CVE-2018-13231 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterToken), an Ethereum token, ha... |
| CVE-2018-13230 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for DestiNeed (DSN), an Ethereum token, has an integer overflow in ... |
| CVE-2018-13229 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for RiptideCoin (RIPT), an Ethereum token, has an integer overflow ... |
| CVE-2018-13228 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for Crowdnext (CNX), an Ethereum token, has an integer overflow in ... |
| CVE-2018-13227 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for MoneyChainNet (MCN), an Ethereum token, has an integer overflow... |
| CVE-2018-13226 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for YLCToken, an Ethereum token, has an integer overflow in which "... |
| CVE-2018-13225 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for MyYLC, an Ethereum token, has an integer overflow in which "amo... |
| CVE-2018-13224 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for Virtual Energy Units (VEU) (Contract Name: VEU_TokenERC20), an ... |
| CVE-2018-13223 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for R Time Token v3 (RS) (Contract Name: RTokenMain), an Ethereum t... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now