The Lxr Project maintains a source-code indexing and cross-reference tool, a narrowly scoped utility deployed in development and build environments for code navigation and analysis. The vendor's vulnerability exposure centers on OS command injection weaknesses in the core lxr product, reflecting the tool's interaction with shell execution for file processing and indexing operations. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lxr Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0545CRITICAL LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors. | Apr 9, 2018 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lxr Project.
Media articles that mention a CVE ID that affects a product developed by Lxr Project — matched by CVE ID, not by vendor name.