2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1000002LOW3.7Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in ...
CVE-2018-5761A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vu...
CVE-2018-1045In Moodle 3.x, there is XSS via a calendar event name.
CVE-2018-1044In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.
CVE-2018-1043In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.
CVE-2018-1042Moodle 3.x has Server Side Request Forgery in the filepicker.
CVE-2018-5968HIGH8.1FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o...
CVE-2018-5962index.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the id parameter to the phpini...
CVE-2018-5961CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the `module` value of the `index.php` file.
CVE-2018-5960HIGH8.8Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Catego...
CVE-2018-5958In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or pos...
CVE-2018-5957In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or pos...
CVE-2018-5956In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or pos...
CVE-2018-5955An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau...
CVE-2018-1362IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 within Citizen Portal could allow an authenticated us...
CVE-2018-5786MEDIUM5.5In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip....
CVE-2018-5785MEDIUM6.5In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder funct...
CVE-2018-5784In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote at...
CVE-2018-5783In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecO...
CVE-2018-5776WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).
CVE-2018-5773An issue was discovered in markdown2 (aka python-markdown2) through 2.3.5. The safe_mode feature, which is supposed to s...
CVE-2018-5772In Exiv2 0.26, there is a segmentation fault caused by uncontrolled recursion in the Exiv2::Image::printIFDStructure fun...
CVE-2018-5766In Libav through 12.2, there is an invalid memcpy in the av_packet_ref function of libavcodec/avpacket.c. Remote attacke...
CVE-2018-0115A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series routers could allow an authent...
CVE-2018-0111A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now