2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-2025MEDIUM4.4IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directo...
CVE-2018-10854MEDIUM5.4cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in Clou...
CVE-2018-9195MEDIUM5.9Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle wit...
CVE-2018-21031MEDIUM6.5Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server becaus...
CVE-2018-13257MEDIUM6.1The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spo...
CVE-2018-12207MEDIUM6.5Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may al...
CVE-2018-18819MEDIUM5.3A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0...
CVE-2018-18674MEDIUM6.1GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail conten...
CVE-2018-20853MEDIUM5.3An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plug...
CVE-2018-21030MEDIUM5.3Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, f...
CVE-2018-18678MEDIUM6.1GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board grou...
CVE-2018-10727MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component ...
CVE-2018-3300MEDIUM5.4Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Internal Operations)....
CVE-2018-2875MEDIUM5Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, ...
CVE-2018-5745MEDIUM4.9"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which ...
CVE-2018-18379MEDIUM6.1The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has ...
CVE-2018-11782MEDIUM6.5In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit ...
CVE-2018-9090MEDIUM6.1CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (a...
CVE-2018-17789MEDIUM6.5Prospecta Master Data Online (MDO) allows CSRF.
CVE-2018-11200MEDIUM6.1An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field.
CVE-2018-1847MEDIUM6.5IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) v2.0.0.0 through 2.0.0.5, v2.1.0.0 through 2.1.0.4, v2.1...
CVE-2018-21017MEDIUM6.5GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.
CVE-2018-21016MEDIUM6.5audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of servi...
CVE-2018-21015MEDIUM6.5AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL poi...
CVE-2018-21014MEDIUM5.4The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now