2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000650 | — | — | 1.5% | Aug 20, 2018 | LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions t... |
| CVE-2018-1000649 | — | — | 2.8% | Aug 20, 2018 | LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability ... |
| CVE-2018-1000648 | — | — | 2.8% | Aug 20, 2018 | LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file le... |
| CVE-2018-1000647 | — | — | 1.5% | Aug 20, 2018 | LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import templ... |
| CVE-2018-1000646 | — | — | 3.3% | Aug 20, 2018 | LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import templat... |
| CVE-2018-1000645 | — | — | 1.4% | Aug 20, 2018 | LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of te... |
| CVE-2018-1000644 | — | — | 2.0% | Aug 20, 2018 | Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing... |
| CVE-2018-1000643 | — | — | — | Aug 20, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-1000642 | — | — | 0.9% | Aug 20, 2018 | FlightAirMap version <=v1.0-beta.21 contains a Cross Site Scripting (XSS) vulnerability in GET variable used within regi... |
| CVE-2018-1000641 | — | — | 2.5% | Aug 20, 2018 | YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered para... |
| CVE-2018-1000640 | — | — | 0.9% | Aug 20, 2018 | OpenCart-Overclocked version <=1.11.1 contains a Cross Site Scripting (XSS) vulnerability in User input entered unsaniti... |
| CVE-2018-1000638 | — | — | 2.2% | Aug 20, 2018 | MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={pa... |
| CVE-2018-1000637 | — | — | 1.7% | Aug 20, 2018 | zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential d... |
| CVE-2018-1000636 | — | — | 1.1% | Aug 20, 2018 | JerryScript version Tested on commit f86d7459d195c8ba58479d1861b0cc726c8b3793. Analysing history it seems that the issue... |
| CVE-2018-1000635 | — | — | 0.3% | Aug 20, 2018 | The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains a Information Exposure Through Sent Data vu... |
| CVE-2018-1000634 | — | — | 1.0% | Aug 20, 2018 | The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in... |
| CVE-2018-1000633 | — | — | 1.2% | Aug 20, 2018 | The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vuln... |
| CVE-2018-5243 | — | — | 1.8% | Aug 20, 2018 | The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of ... |
| CVE-2018-15594 | — | — | 0.6% | Aug 20, 2018 | arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier fo... |
| CVE-2018-15572 | — | — | 0.5% | Aug 20, 2018 | The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not alway... |
| CVE-2018-15570 | — | — | 0.5% | Aug 20, 2018 | In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter. |
| CVE-2018-15569 | — | — | 0.4% | Aug 20, 2018 | my little forum 2.4.12 allows CSRF for deletion of users. |
| CVE-2018-15568 | — | — | 0.5% | Aug 20, 2018 | tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html. |
| CVE-2018-15567 | — | — | 0.7% | Aug 20, 2018 | CMSUno before 1.5.3 has XSS via the title field. |
| CVE-2018-15566 | — | — | 0.7% | Aug 20, 2018 | tp5cms through 2017-05-25 has XSS via the admin.php/article/index.html q parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now