2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000031 | — | — | 1.3% | Feb 9, 2018 | A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of ser... |
| CVE-2018-1000029 | — | — | 0.6% | Feb 9, 2018 | mcholste Enterprise Log Search and Archive (ELSA) version revision 1205, commit 2cc17f1 and earlier contains a Cross Sit... |
| CVE-2018-1000028 | — | — | 1.4% | Feb 9, 2018 | Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Contr... |
| CVE-2018-1000027 | — | — | 13.1% | Feb 9, 2018 | The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereferen... |
| CVE-2018-1000025 | — | — | 1.3% | Feb 9, 2018 | Jerome Gamez Firebase Admin SDK for PHP version from 3.2.0 to 3.8.0 contains a Incorrect Access Control vulnerability in... |
| CVE-2018-1000024 | — | — | 8.1% | Feb 9, 2018 | The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer... |
| CVE-2018-1000023 | — | — | 1.2% | Feb 9, 2018 | Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transactio... |
| CVE-2018-1000022 | — | — | 1.8% | Feb 9, 2018 | Electrum Technologies GmbH Electrum Bitcoin Wallet version prior to version 3.0.5 contains a Missing Authorization vulne... |
| CVE-2018-1000020 | — | — | 0.7% | Feb 9, 2018 | OpenEMR version 5.0.0 contains a Cross Site Scripting (XSS) vulnerability in open-flash-chart.swf and _posteddata.php th... |
| CVE-2018-1000019 | — | — | 3.8% | Feb 9, 2018 | OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command in... |
| CVE-2018-5307 | — | — | 1.2% | Feb 9, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x before 2.14.6 al... |
| CVE-2018-5306 | — | — | 1.1% | Feb 9, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x before 3.8 allow... |
| CVE-2018-3607 | — | — | 14.7% | Feb 9, 2018 | XXXTreeNode method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could al... |
| CVE-2018-3606 | — | — | 49.4% | Feb 9, 2018 | XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution (RCE) vulnerabilities... |
| CVE-2018-3605 | — | — | 20.2% | Feb 9, 2018 | TopXXX, ViolationXXX, and IncidentXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Co... |
| CVE-2018-3604 | — | — | 68.6% | Feb 9, 2018 | GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a... |
| CVE-2018-3603 | — | — | 8.3% | Feb 9, 2018 | A CGGIServlet SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a r... |
| CVE-2018-3602 | — | — | 8.3% | Feb 9, 2018 | An AdHocQuery_Processor SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could... |
| CVE-2018-3601 | — | — | 4.3% | Feb 9, 2018 | A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attack... |
| CVE-2018-3600 | — | — | 1.7% | Feb 9, 2018 | A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a... |
| CVE-2018-6508 | — | — | 1.9% | Feb 9, 2018 | Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string wa... |
| CVE-2018-1307 | — | — | 1.7% | Feb 9, 2018 | In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML docume... |
| CVE-2018-6878 | — | — | 0.6% | Feb 9, 2018 | Cross Site Scripting (XSS) exists in the review section in PHP Scripts Mall Hot Scripts Clone Script Classified 3.1 via ... |
| CVE-2018-6876 | — | — | 2.5% | Feb 9, 2018 | The OLEProperty class in ole/oleprop.cpp in libfpx 1.3.1-10, as used in ImageMagick 7.0.7-22 Q16 and other products, all... |
| CVE-2018-1401 | — | — | 1.1% | Feb 9, 2018 | IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now