2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5993 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the Aist through 2.0 component for Joomla! via the id parameter in a view=showvacancy request. |
| CVE-2018-5992 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff r... |
| CVE-2018-5991 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats re... |
| CVE-2018-5990 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter. |
| CVE-2018-5987 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id paramete... |
| CVE-2018-5983 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request. |
| CVE-2018-5982 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= requ... |
| CVE-2018-5981 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter. |
| CVE-2018-5980 | — | — | 4.0% | Feb 17, 2018 | SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action. |
| CVE-2018-5975 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI. |
| CVE-2018-5974 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter. |
| CVE-2018-5971 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array paramet... |
| CVE-2018-5970 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries paramete... |
| CVE-2018-3609 | — | — | 21.8% | Feb 16, 2018 | A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could al... |
| CVE-2018-7188 | — | — | 0.5% | Feb 16, 2018 | An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges ... |
| CVE-2018-0516 | — | — | 0.9% | Feb 16, 2018 | Untrusted search path vulnerability in FLET'S v4 / v6 address selection tool allows an attacker to gain privileges via a... |
| CVE-2018-0515 | — | — | 0.9% | Feb 16, 2018 | Untrusted search path vulnerability in "FLET'S Azukeru Backup Tool" version 1.5.2.6 and earlier allows an attacker to ga... |
| CVE-2018-7186 | — | — | 3.5% | Feb 16, 2018 | Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allow... |
| CVE-2018-6944 | — | — | 1.2% | Feb 16, 2018 | core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerabili... |
| CVE-2018-6943 | — | — | 1.1% | Feb 16, 2018 | core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerabil... |
| CVE-2018-1000066 | — | — | — | Feb 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5380. Reason: This candidate is a reservation du... |
| CVE-2018-1000065 | — | — | — | Feb 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5381. Reason: This candidate is a reservation du... |
| CVE-2018-1000064 | — | — | — | Feb 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5378. Reason: This candidate is a reservation du... |
| CVE-2018-1000063 | — | — | — | Feb 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5379. Reason: This candidate is a reservation du... |
| CVE-2018-7176 | — | — | 2.4% | Feb 16, 2018 | FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add u... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now