2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000002 | LOW | 3.7 | 1.1% | Jan 22, 2018 | Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in ... |
| CVE-2018-5761 | — | — | 0.5% | Jan 22, 2018 | A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vu... |
| CVE-2018-1045 | — | — | 0.8% | Jan 22, 2018 | In Moodle 3.x, there is XSS via a calendar event name. |
| CVE-2018-1044 | — | — | 1.0% | Jan 22, 2018 | In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings. |
| CVE-2018-1043 | — | — | 1.4% | Jan 22, 2018 | In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames. |
| CVE-2018-1042 | — | — | 15.9% | Jan 22, 2018 | Moodle 3.x has Server Side Request Forgery in the filepicker. |
| CVE-2018-5968 | HIGH | 8.1 | 7.0% | Jan 22, 2018 | FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o... |
| CVE-2018-5962 | — | — | 2.7% | Jan 22, 2018 | index.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the id parameter to the phpini... |
| CVE-2018-5961 | — | — | 2.7% | Jan 22, 2018 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the `module` value of the `index.php` file. |
| CVE-2018-5960 | HIGH | 8.8 | 0.9% | Jan 22, 2018 | Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Catego... |
| CVE-2018-5958 | — | — | 0.3% | Jan 21, 2018 | In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or pos... |
| CVE-2018-5957 | — | — | 0.3% | Jan 21, 2018 | In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or pos... |
| CVE-2018-5956 | — | — | 0.3% | Jan 21, 2018 | In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or pos... |
| CVE-2018-5955 | — | — | 81.3% | Jan 21, 2018 | An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau... |
| CVE-2018-1362 | — | — | 0.6% | Jan 19, 2018 | IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 within Citizen Portal could allow an authenticated us... |
| CVE-2018-5786 | MEDIUM | 5.5 | 1.3% | Jan 19, 2018 | In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.... |
| CVE-2018-5785 | MEDIUM | 6.5 | 2.3% | Jan 19, 2018 | In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder funct... |
| CVE-2018-5784 | — | — | 3.0% | Jan 19, 2018 | In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote at... |
| CVE-2018-5783 | — | — | 1.1% | Jan 19, 2018 | In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecO... |
| CVE-2018-5776 | — | — | 2.5% | Jan 18, 2018 | WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement). |
| CVE-2018-5773 | — | — | 0.8% | Jan 18, 2018 | An issue was discovered in markdown2 (aka python-markdown2) through 2.3.5. The safe_mode feature, which is supposed to s... |
| CVE-2018-5772 | — | — | 1.9% | Jan 18, 2018 | In Exiv2 0.26, there is a segmentation fault caused by uncontrolled recursion in the Exiv2::Image::printIFDStructure fun... |
| CVE-2018-5766 | — | — | 2.5% | Jan 18, 2018 | In Libav through 12.2, there is an invalid memcpy in the av_packet_ref function of libavcodec/avpacket.c. Remote attacke... |
| CVE-2018-0115 | — | — | 0.5% | Jan 18, 2018 | A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series routers could allow an authent... |
| CVE-2018-0111 | — | — | 1.8% | Jan 18, 2018 | A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now