2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-5735HIGH7.5The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions...
CVE-2018-19151HIGH7.5qtum through 0.16 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends in...
CVE-2018-18931HIGH8.8An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104. Due to insecure default permi...
CVE-2018-18930HIGH8.8The Tightrope Media Carousel digital signage product 7.0.4.104 contains an arbitrary file upload vulnerability in the Ma...
CVE-2018-18929HIGH8.8The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator ...
CVE-2018-10727MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component ...
CVE-2018-3630Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2018-7368Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-3418. Reason: This candidate is a reservation du...
CVE-2018-7367Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-3417. Reason: This candidate is a reservation du...
CVE-2018-3300MEDIUM5.4Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Internal Operations)....
CVE-2018-2875MEDIUM5Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, ...
CVE-2018-21028HIGH7.5Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
CVE-2018-21027CRITICAL9.8Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled...
CVE-2018-20582HIGH8.8The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery.
CVE-2018-5745MEDIUM4.9"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which ...
CVE-2018-5744HIGH7.5A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affe...
CVE-2018-5743HIGH7.5By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of al...
CVE-2018-5732HIGH7.5Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masqu...
CVE-2018-21024CRITICAL9.8licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.
CVE-2018-21025CRITICAL9.8In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrec...
CVE-2018-21023HIGH8.8getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parame...
CVE-2018-21022HIGH8.8makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parame...
CVE-2018-21021HIGH8.8img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.
CVE-2018-21020HIGH7.5In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows att...
CVE-2018-18379MEDIUM6.1The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now