2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1102 | — | — | 2.4% | Apr 30, 2018 | A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of ta... |
| CVE-2018-5234 | — | — | 16.7% | Apr 30, 2018 | The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic... |
| CVE-2018-9310 | — | — | 0.3% | Apr 30, 2018 | An issue was discovered in MagniComp SysInfo before 10-H82 if setuid root (the default). This vulnerability allows any l... |
| CVE-2018-10573 | — | — | 2.7% | Apr 30, 2018 | interface/fax/fax_dispatch.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restr... |
| CVE-2018-10572 | — | — | 1.9% | Apr 30, 2018 | interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access re... |
| CVE-2018-10571 | — | — | 1.5% | Apr 30, 2018 | Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject a... |
| CVE-2018-10570 | — | — | 0.5% | Apr 30, 2018 | Frog CMS 0.9.5 has XSS in /install/index.php via the ['config']['admin_username'] field. |
| CVE-2018-7891 | — | — | 4.2% | Apr 30, 2018 | The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0.... |
| CVE-2018-7901 | — | — | 0.5% | Apr 30, 2018 | RCS module in Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129, BLA-AL00B smart phones with s... |
| CVE-2018-1430 | — | — | 1.0% | Apr 30, 2018 | IBM API Connect 5.0.0.0 through 5.0.8.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2018-1389 | — | — | 1.5% | Apr 30, 2018 | IBM API Connect 5.0.0.0 through 5.0.8.2 is impacted by generated LoopBack APIs for a Model using the BelongsTo/HasMany r... |
| CVE-2018-0711 | — | — | 0.9% | Apr 30, 2018 | Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier v... |
| CVE-2018-10550 | — | — | 1.3% | Apr 30, 2018 | In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants th... |
| CVE-2018-10554 | — | — | 2.7% | Apr 30, 2018 | An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via... |
| CVE-2018-10553 | — | — | 39.5% | Apr 30, 2018 | An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, a... |
| CVE-2018-10549 | — | — | 7.2% | Apr 29, 2018 | An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_rea... |
| CVE-2018-10548 | — | — | 8.8% | Apr 29, 2018 | An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap... |
| CVE-2018-10547 | — | — | 3.6% | Apr 29, 2018 | An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.... |
| CVE-2018-10546 | — | — | 10.6% | Apr 29, 2018 | An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infin... |
| CVE-2018-10545 | — | — | 0.8% | Apr 29, 2018 | An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable... |
| CVE-2018-9845 | — | — | 13.1% | Apr 29, 2018 | Etherpad Lite before 1.6.4 is exploitable for admin access. |
| CVE-2018-10540 | — | — | 1.7% | Apr 29, 2018 | An issue was discovered in WavPack 5.1.0 and earlier for W64 input. Out-of-bounds writes can occur because ParseWave64He... |
| CVE-2018-10539 | — | — | 1.7% | Apr 29, 2018 | An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input. Out-of-bounds writes can occur because ParseDsdif... |
| CVE-2018-10538 | — | — | 1.6% | Apr 29, 2018 | An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHead... |
| CVE-2018-10537 | — | — | 2.1% | Apr 29, 2018 | An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now