2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0862 | — | — | 19.0% | Jan 22, 2018 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro... |
| CVE-2018-0849 | — | — | 19.0% | Jan 22, 2018 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro... |
| CVE-2018-0848 | — | — | 20.9% | Jan 22, 2018 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro... |
| CVE-2018-0845 | — | — | 20.1% | Jan 22, 2018 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro... |
| CVE-2018-6010 | — | — | 2.9% | Jan 22, 2018 | In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messa... |
| CVE-2018-6009 | — | — | 0.6% | Jan 22, 2018 | In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a... |
| CVE-2018-6002 | — | — | 0.8% | Jan 22, 2018 | The Soundy Background Music plugin 3.9 and below for WordPress has Cross-Site Scripting via soundy-background-music\temp... |
| CVE-2018-6001 | — | — | 0.8% | Jan 22, 2018 | The Soundy Audio Playlist plugin 4.6 and below for WordPress has Cross-Site Scripting via soundy-audio-playlist\template... |
| CVE-2018-6000 | — | — | 84.5% | Jan 22, 2018 | An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn... |
| CVE-2018-5999 | — | — | 87.4% | Jan 22, 2018 | An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro... |
| CVE-2018-1000003 | — | — | 1.3% | Jan 22, 2018 | Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-mi... |
| CVE-2018-5761 | — | — | 0.5% | Jan 22, 2018 | A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vu... |
| CVE-2018-1045 | — | — | 0.8% | Jan 22, 2018 | In Moodle 3.x, there is XSS via a calendar event name. |
| CVE-2018-1044 | — | — | 1.0% | Jan 22, 2018 | In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings. |
| CVE-2018-1043 | — | — | 1.4% | Jan 22, 2018 | In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames. |
| CVE-2018-1042 | — | — | 15.9% | Jan 22, 2018 | Moodle 3.x has Server Side Request Forgery in the filepicker. |
| CVE-2018-5962 | — | — | 2.7% | Jan 22, 2018 | index.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the id parameter to the phpini... |
| CVE-2018-5961 | — | — | 2.7% | Jan 22, 2018 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the `module` value of the `index.php` file. |
| CVE-2018-5958 | — | — | 0.3% | Jan 21, 2018 | In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or pos... |
| CVE-2018-5957 | — | — | 0.3% | Jan 21, 2018 | In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or pos... |
| CVE-2018-5956 | — | — | 0.3% | Jan 21, 2018 | In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or pos... |
| CVE-2018-5955 | — | — | 81.3% | Jan 21, 2018 | An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau... |
| CVE-2018-1362 | — | — | 0.6% | Jan 19, 2018 | IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 within Citizen Portal could allow an authenticated us... |
| CVE-2018-5784 | — | — | 3.0% | Jan 19, 2018 | In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote at... |
| CVE-2018-5783 | — | — | 1.1% | Jan 19, 2018 | In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecO... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now