2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-4917 | CRITICAL | 9.8 | 17.8% | May 19, 2018 | Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier hav... |
| CVE-2018-4873 | — | — | 1.3% | May 19, 2018 | Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Unquoted Search Path vulnera... |
| CVE-2018-1148 | — | — | 0.8% | May 18, 2018 | In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authen... |
| CVE-2018-1147 | — | — | 1.1% | May 18, 2018 | In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker cou... |
| CVE-2018-8867 | — | — | 3.5% | May 18, 2018 | In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 a... |
| CVE-2018-6562 | — | — | 0.7% | May 18, 2018 | totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user session... |
| CVE-2018-11256 | — | — | 1.4% | May 18, 2018 | An issue was discovered in PoDoFo 0.9.5. The function PdfDocument::Append() in PdfDocument.cpp in PoDoFo 0.9.5 allows re... |
| CVE-2018-11255 | — | — | 1.1% | May 18, 2018 | An issue was discovered in PoDoFo 0.9.5. The function PdfPage::GetPageNumber() in PdfPage.cpp in PoDoFo 0.9.5 allows rem... |
| CVE-2018-11254 | — | — | 1.1% | May 18, 2018 | An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of ... |
| CVE-2018-11251 | — | — | 2.1% | May 18, 2018 | In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, w... |
| CVE-2018-11248 | — | — | 2.1% | May 18, 2018 | util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in ... |
| CVE-2018-11245 | — | — | 0.9% | May 18, 2018 | app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes. |
| CVE-2018-1000400 | — | — | 2.1% | May 18, 2018 | Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handli... |
| CVE-2018-8015 | — | — | 3.5% | May 18, 2018 | In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java pa... |
| CVE-2018-11244 | — | — | 1.0% | May 18, 2018 | The BBE theme before 1.53 for WordPress allows a direct launch of an HTML editor. |
| CVE-2018-11243 | — | — | 2.5% | May 18, 2018 | PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), l... |
| CVE-2018-11237 | HIGH | 7.8 | 0.9% | May 18, 2018 | An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier m... |
| CVE-2018-11236 | — | — | 7.4% | May 18, 2018 | stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arg... |
| CVE-2018-5256 | HIGH | 7.5 | 1.7% | May 18, 2018 | CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes ... |
| CVE-2018-9250 | — | — | 31.5% | May 18, 2018 | interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL comm... |
| CVE-2018-10968 | — | — | 1.8% | May 18, 2018 | On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can use a default TELNET account to get unauth... |
| CVE-2018-10967 | — | — | 3.8% | May 18, 2018 | On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating ... |
| CVE-2018-8849 | MEDIUM | 4.6 | 0.3% | May 18, 2018 | Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card d... |
| CVE-2018-10307 | — | — | 0.9% | May 18, 2018 | error.php in ILIAS 5.2.x through 5.3.x before 5.3.4 allows XSS via the text of a PDO exception. |
| CVE-2018-10306 | — | — | 1.2% | May 18, 2018 | Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now