2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-10890MEDIUM4.3A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categori...
CVE-2018-10889MEDIUM4.3A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports...
CVE-2018-1331In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker wi...
CVE-2018-5553CRITICAL9.8The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and runn...
CVE-2018-1566HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ...
CVE-2018-1549MEDIUM5.4IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. ...
CVE-2018-1523MEDIUM5.4IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulner...
CVE-2018-1492MEDIUM4.3IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the ...
CVE-2018-1487HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared librarie...
CVE-2018-1458HIGH7.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to e...
CVE-2018-1423MEDIUM4.3IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in fur...
CVE-2018-1396MEDIUM5.4IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulner...
CVE-2018-1521MEDIUM5.4IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerabi...
CVE-2018-1408MEDIUM5.4IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerabi...
CVE-2018-1407MEDIUM5.4IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerabi...
CVE-2018-13833An issue was discovered in cmft through 2017-09-24. The cmft::rwReadFile function in image.cpp allows remote attackers t...
CVE-2018-10943An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3. Sending an arbit...
CVE-2018-9853Insecure access control in freeSSHd version 1.3.1 allows attackers to obtain the privileges of the freesshd.exe process ...
CVE-2018-13818Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor poi...
CVE-2018-1129A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having acces...
CVE-2018-1128It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attac...
CVE-2018-10888MEDIUM6.5A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead...
CVE-2018-10887HIGH8.1A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta...
CVE-2018-10861A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can d...
CVE-2018-13389The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now