2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-1102A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of ta...
CVE-2018-5234The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic...
CVE-2018-9310An issue was discovered in MagniComp SysInfo before 10-H82 if setuid root (the default). This vulnerability allows any l...
CVE-2018-10573interface/fax/fax_dispatch.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restr...
CVE-2018-10572interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access re...
CVE-2018-10571Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject a...
CVE-2018-10570Frog CMS 0.9.5 has XSS in /install/index.php via the ['config']['admin_username'] field.
CVE-2018-7891The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0....
CVE-2018-7901RCS module in Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129, BLA-AL00B smart phones with s...
CVE-2018-1430IBM API Connect 5.0.0.0 through 5.0.8.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2018-1389IBM API Connect 5.0.0.0 through 5.0.8.2 is impacted by generated LoopBack APIs for a Model using the BelongsTo/HasMany r...
CVE-2018-0711Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier v...
CVE-2018-10550In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants th...
CVE-2018-10554An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via...
CVE-2018-10553An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, a...
CVE-2018-10549An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_rea...
CVE-2018-10548An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap...
CVE-2018-10547An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7....
CVE-2018-10546An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infin...
CVE-2018-10545An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable...
CVE-2018-9845Etherpad Lite before 1.6.4 is exploitable for admin access.
CVE-2018-10540An issue was discovered in WavPack 5.1.0 and earlier for W64 input. Out-of-bounds writes can occur because ParseWave64He...
CVE-2018-10539An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input. Out-of-bounds writes can occur because ParseDsdif...
CVE-2018-10538An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHead...
CVE-2018-10537An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now