2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7216 | — | — | 3.0% | Feb 18, 2018 | Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal al... |
| CVE-2018-7212 | — | — | 1.9% | Feb 18, 2018 | An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows.... |
| CVE-2018-7211 | — | — | 0.8% | Feb 18, 2018 | An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing ... |
| CVE-2018-7210 | — | — | 1.5% | Feb 18, 2018 | An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct req... |
| CVE-2018-7209 | — | — | 1.5% | Feb 18, 2018 | An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct req... |
| CVE-2018-7208 | — | — | 2.3% | Feb 18, 2018 | In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribute... |
| CVE-2018-7207 | — | — | — | Feb 18, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-7198 | — | — | 2.5% | Feb 18, 2018 | October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page. |
| CVE-2018-7197 | — | — | 1.4% | Feb 18, 2018 | An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthen... |
| CVE-2018-7180 | — | — | 2.9% | Feb 17, 2018 | SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter. |
| CVE-2018-7179 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter. |
| CVE-2018-7178 | — | — | 4.1% | Feb 17, 2018 | SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter. |
| CVE-2018-7177 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter. |
| CVE-2018-6585 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or fi... |
| CVE-2018-6584 | — | — | 4.0% | Feb 17, 2018 | SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request. |
| CVE-2018-6583 | — | — | 20.2% | Feb 17, 2018 | SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request. |
| CVE-2018-6396 | — | — | 24.4% | Feb 17, 2018 | SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a l... |
| CVE-2018-6394 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action. |
| CVE-2018-6372 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter. |
| CVE-2018-6370 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under... |
| CVE-2018-6368 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed acti... |
| CVE-2018-6006 | — | — | 20.2% | Feb 17, 2018 | SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter. |
| CVE-2018-6005 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter. |
| CVE-2018-6004 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter. |
| CVE-2018-5994 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or t... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now