2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6184 | — | — | 9.2% | Jan 24, 2018 | ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace. |
| CVE-2018-5988 | — | — | 19.5% | Jan 24, 2018 | SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php. |
| CVE-2018-5985 | — | — | 19.5% | Jan 24, 2018 | SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request. |
| CVE-2018-5984 | — | — | 2.7% | Jan 24, 2018 | SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the categor... |
| CVE-2018-5979 | — | — | 15.5% | Jan 24, 2018 | SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field. |
| CVE-2018-5978 | — | — | 2.7% | Jan 24, 2018 | SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field. |
| CVE-2018-5977 | — | — | 2.0% | Jan 24, 2018 | SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= r... |
| CVE-2018-5976 | — | — | 2.2% | Jan 24, 2018 | Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modi... |
| CVE-2018-5972 | — | — | 19.5% | Jan 24, 2018 | SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listin... |
| CVE-2018-5969 | — | — | 1.4% | Jan 24, 2018 | Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demons... |
| CVE-2018-5749 | — | — | 2.5% | Jan 23, 2018 | install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does no... |
| CVE-2018-5359 | — | — | 9.2% | Jan 23, 2018 | The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system... |
| CVE-2018-1000016 | — | — | — | Jan 23, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17383. Reason: This candidate is a reservation... |
| CVE-2018-1000015 | — | — | 1.1% | Jan 23, 2018 | On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Bui... |
| CVE-2018-1000014 | — | — | 0.8% | Jan 23, 2018 | Jenkins Translation Assistance Plugin 1.15 and earlier did not require form submissions to be submitted via POST, result... |
| CVE-2018-1000013 | — | — | 1.0% | Jan 23, 2018 | Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vu... |
| CVE-2018-1000012 | — | — | 1.0% | Jan 23, 2018 | Jenkins Warnings Plugin 4.64 and earlier processes XML external entities in files it parses as part of the build process... |
| CVE-2018-1000011 | — | — | 1.0% | Jan 23, 2018 | Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process... |
| CVE-2018-1000010 | — | — | 1.0% | Jan 23, 2018 | Jenkins DRY Plugin 2.49 and earlier processes XML external entities in files it parses as part of the build process, all... |
| CVE-2018-1000009 | — | — | 1.0% | Jan 23, 2018 | Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build proce... |
| CVE-2018-1000008 | — | — | 1.2% | Jan 23, 2018 | Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, all... |
| CVE-2018-6029 | — | — | 1.4% | Jan 23, 2018 | The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the con... |
| CVE-2018-6022 | — | — | 1.4% | Jan 23, 2018 | Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authen... |
| CVE-2018-6014 | — | — | 1.3% | Jan 23, 2018 | Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrie... |
| CVE-2018-6013 | — | — | 0.9% | Jan 23, 2018 | Cross-site scripting (XSS) in BigTree 4.2.19 allows any remote users to inject arbitrary web script or HTML via the dire... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now