2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17607 | — | — | 3.2% | Sep 28, 2018 | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (us... |
| CVE-2018-17605 | — | — | 2.2% | Sep 28, 2018 | An issue was discovered in the Asset Pipeline plugin before 3.0.4 for Grails. An attacker can perform directory traversa... |
| CVE-2018-17582 | — | — | 1.2% | Sep 28, 2018 | Tcpreplay v4.3.0 beta1 contains a heap-based buffer over-read. The get_next_packet() function in the send_packets.c file... |
| CVE-2018-17580 | — | — | 1.2% | Sep 28, 2018 | A heap-based buffer over-read exists in the function fast_edit_packet() in the file send_packets.c of Tcpreplay v4.3.0 b... |
| CVE-2018-17575 | — | — | 1.1% | Sep 28, 2018 | SWA SWA.JACAD 3.1.37 Build 024 has SQL Injection via the /academico/aluno/esqueci-minha-senha/ studentId parameter. |
| CVE-2018-17574 | — | — | 0.7% | Sep 28, 2018 | An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project. |
| CVE-2018-17573 | — | — | 3.4% | Sep 28, 2018 | The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configu... |
| CVE-2018-17571 | — | — | 0.7% | Sep 28, 2018 | Vanilla before 2.6.1 allows XSS via the email field of a profile. |
| CVE-2018-17567 | — | — | 2.2% | Sep 28, 2018 | Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specify... |
| CVE-2018-17397 | — | — | 3.2% | Sep 28, 2018 | SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter. |
| CVE-2018-17394 | — | — | 3.2% | Sep 28, 2018 | SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter. |
| CVE-2018-17391 | — | — | 3.2% | Sep 28, 2018 | SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter. |
| CVE-2018-17385 | — | — | 3.2% | Sep 28, 2018 | SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radiu... |
| CVE-2018-17384 | — | — | 3.3% | Sep 28, 2018 | SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter. |
| CVE-2018-17383 | — | — | 3.2% | Sep 28, 2018 | SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir para... |
| CVE-2018-17382 | — | — | 3.2% | Sep 28, 2018 | SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter. |
| CVE-2018-17380 | — | — | 3.3% | Sep 28, 2018 | SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_e... |
| CVE-2018-17379 | — | — | 3.3% | Sep 28, 2018 | SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order paramete... |
| CVE-2018-17378 | — | — | 3.3% | Sep 28, 2018 | SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order p... |
| CVE-2018-17377 | — | — | 3.2% | Sep 28, 2018 | SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter. |
| CVE-2018-17376 | — | — | 3.2% | Sep 28, 2018 | SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter... |
| CVE-2018-17375 | — | — | 3.3% | Sep 28, 2018 | SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter. |
| CVE-2018-17056 | — | — | 0.8% | Sep 28, 2018 | Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows re... |
| CVE-2018-17055 | — | — | 1.0% | Sep 28, 2018 | An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads. |
| CVE-2018-16587 | — | — | 1.8% | Sep 28, 2018 | In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker coul... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now