2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-6184ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
CVE-2018-5988SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.
CVE-2018-5985SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.
CVE-2018-5984SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the categor...
CVE-2018-5979SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field.
CVE-2018-5978SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.
CVE-2018-5977SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= r...
CVE-2018-5976Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modi...
CVE-2018-5972SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listin...
CVE-2018-5969Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demons...
CVE-2018-5749install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does no...
CVE-2018-5359The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system...
CVE-2018-1000016Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17383. Reason: This candidate is a reservation...
CVE-2018-1000015On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Bui...
CVE-2018-1000014Jenkins Translation Assistance Plugin 1.15 and earlier did not require form submissions to be submitted via POST, result...
CVE-2018-1000013Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vu...
CVE-2018-1000012Jenkins Warnings Plugin 4.64 and earlier processes XML external entities in files it parses as part of the build process...
CVE-2018-1000011Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process...
CVE-2018-1000010Jenkins DRY Plugin 2.49 and earlier processes XML external entities in files it parses as part of the build process, all...
CVE-2018-1000009Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build proce...
CVE-2018-1000008Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, all...
CVE-2018-6029The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the con...
CVE-2018-6022Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authen...
CVE-2018-6014Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrie...
CVE-2018-6013Cross-site scripting (XSS) in BigTree 4.2.19 allows any remote users to inject arbitrary web script or HTML via the dire...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now