2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-3768Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1000539. Reason: This candidate is a reservati...
CVE-2018-3767`memjs` versions <= 1.1.0 allocates and stores buffers on typed input, resulting in DoS and uninitialized memory usage.
CVE-2018-3766HIGH7.5Path traversal in buttle module versions <= 0.2.0 allows to read any file in the server.
CVE-2018-3764MEDIUM4.8In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a s...
CVE-2018-3763MEDIUM4.8In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could l...
CVE-2018-3762MEDIUM4.3Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowi...
CVE-2018-3761HIGH8.1Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing chec...
CVE-2018-8026This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in...
CVE-2018-13251In libming 0.4.8, there is an excessive memory allocation attempt in the readBytes function of the util/read.c file, rel...
CVE-2018-13250libming 0.4.8 has a NULL pointer dereference in the getString function of the decompile.c file, related to decompileSTRI...
CVE-2018-9185An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login cre...
CVE-2018-8928MEDIUM6.5Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remo...
CVE-2018-8038Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing t...
CVE-2018-10885MEDIUM6.5In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash ...
CVE-2018-13233The sell function of a smart contract implementation for GSI, an Ethereum token, has an integer overflow in which "amoun...
CVE-2018-13232The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has...
CVE-2018-13231The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterToken), an Ethereum token, ha...
CVE-2018-13230The sell function of a smart contract implementation for DestiNeed (DSN), an Ethereum token, has an integer overflow in ...
CVE-2018-13229The sell function of a smart contract implementation for RiptideCoin (RIPT), an Ethereum token, has an integer overflow ...
CVE-2018-13228The sell function of a smart contract implementation for Crowdnext (CNX), an Ethereum token, has an integer overflow in ...
CVE-2018-13227The sell function of a smart contract implementation for MoneyChainNet (MCN), an Ethereum token, has an integer overflow...
CVE-2018-13226The sell function of a smart contract implementation for YLCToken, an Ethereum token, has an integer overflow in which "...
CVE-2018-13225The sell function of a smart contract implementation for MyYLC, an Ethereum token, has an integer overflow in which "amo...
CVE-2018-13224The sell function of a smart contract implementation for Virtual Energy Units (VEU) (Contract Name: VEU_TokenERC20), an ...
CVE-2018-13223The sell function of a smart contract implementation for R Time Token v3 (RS) (Contract Name: RTokenMain), an Ethereum t...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now