2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15151 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1... |
| CVE-2018-15150 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR be... |
| CVE-2018-15149 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/forms/eye_mag/php/Anything_simple.php from library/forms.inc in versions of Ope... |
| CVE-2018-15148 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/patient_file/encounter/search_code.php in versions of OpenEMR before 5.0.1.4 al... |
| CVE-2018-15147 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/forms_admin/forms_admin.php from library/registry.inc in versions of OpenEMR be... |
| CVE-2018-15146 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/de_identification_forms/find_immunization_popup.php in versions of OpenEMR befo... |
| CVE-2018-15138 | — | — | 12.9% | Aug 15, 2018 | Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs. |
| CVE-2018-12056 | — | — | 1.7% | Aug 15, 2018 | The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random... |
| CVE-2018-11687 | — | — | 1.3% | Aug 15, 2018 | An integer overflow in the distributeBTR function of a smart contract implementation for Bitcoin Red (BTCR), an Ethereum... |
| CVE-2018-10917 | MEDIUM | 6.8 | 1.1% | Aug 15, 2018 | pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repos... |
| CVE-2018-10369 | — | — | 1.9% | Aug 15, 2018 | A Cross-site scripting (XSS) vulnerability was discovered on Intelbras Win 240 V1.1.0 devices. An attacker can change th... |
| CVE-2018-0952 | — | — | 6.2% | Aug 15, 2018 | An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary... |
| CVE-2018-1455 | MEDIUM | 4.3 | 0.8% | Aug 15, 2018 | IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which coul... |
| CVE-2018-6973 | — | — | 0.5% | Aug 15, 2018 | VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in ... |
| CVE-2018-13394 | — | — | 0.8% | Aug 15, 2018 | The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Ques... |
| CVE-2018-13393 | — | — | 0.8% | Aug 15, 2018 | The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confl... |
| CVE-2018-3938 | CRITICAL | 9.1 | 3.3% | Aug 14, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPEL... |
| CVE-2018-3937 | CRITICAL | 9.1 | 9.6% | Aug 14, 2018 | An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series... |
| CVE-2018-3646 | MEDIUM | 5.6 | 8.1% | Aug 14, 2018 | Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure ... |
| CVE-2018-3620 | MEDIUM | 5.6 | 5.6% | Aug 14, 2018 | Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure ... |
| CVE-2018-3615 | HIGH | 7.3 | 6.3% | Aug 14, 2018 | Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow u... |
| CVE-2018-12539 | — | — | 0.5% | Aug 14, 2018 | In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Ec... |
| CVE-2018-12537 | — | — | 2.5% | Aug 14, 2018 | In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter car... |
| CVE-2018-14922 | — | — | 2.0% | Aug 14, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web ... |
| CVE-2018-14888 | — | — | 3.7% | Aug 14, 2018 | inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or threa... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now