2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-15125Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive informatio...
CVE-2018-15124Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthentic...
CVE-2018-15123Insecure configuration storage in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows rem...
CVE-2018-14781MEDIUM5.3Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” opti...
CVE-2018-10636HIGH8.8CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabili...
CVE-2018-10634MEDIUM4.8Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently...
CVE-2018-10598CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cau...
CVE-2018-3782Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1002203. Reason: This candidate is a reservati...
CVE-2018-3781A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS r...
CVE-2018-3780A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XS...
CVE-2018-15145Multiple SQL injection vulnerabilities in portal/add_edit_event_user.php in versions of OpenEMR before 5.0.1.4 allow a r...
CVE-2018-15144SQL injection vulnerability in interface/de_identification_forms/find_drug_popup.php in versions of OpenEMR before 5.0.1...
CVE-2018-15143Multiple SQL injection vulnerabilities in portal/find_appt_popup_user.php in versions of OpenEMR before 5.0.1.4 allow a ...
CVE-2018-15142Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent...
CVE-2018-15141Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent...
CVE-2018-15140Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent...
CVE-2018-15139HIGH8.8Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote ...
CVE-2018-14878JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a ...
CVE-2018-14850Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain ...
CVE-2018-14849Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/pars...
CVE-2018-13417In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External E...
CVE-2018-13415In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External En...
CVE-2018-12587A cross-site scripting (XSS) vulnerability was found in valeuraddons German Spelling Dictionary v1.3 (an Opera Browser a...
CVE-2018-10864MEDIUM5.3An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A...
CVE-2018-10842Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10912. Reason: This candidate is a duplicate of ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now