2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1409IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the ...
CVE-2018-5381MEDIUM6.5The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in ...
CVE-2018-5380MEDIUM4.3The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for d...
CVE-2018-5379HIGH7.5The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE messa...
CVE-2018-5378HIGH7.1The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer...
CVE-2018-6024SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter.
CVE-2018-7217In Bravo Tejari Procurement Portal, uploaded files are not properly validated by the application either on the client or...
CVE-2018-7216Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal al...
CVE-2018-7212An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows....
CVE-2018-7211An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing ...
CVE-2018-7210An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct req...
CVE-2018-7209An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct req...
CVE-2018-7208In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribute...
CVE-2018-7207Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-7206HIGH8.8An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When usi...
CVE-2018-7198October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
CVE-2018-7197An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthen...
CVE-2018-7180SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter.
CVE-2018-7179SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter.
CVE-2018-7178SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter.
CVE-2018-7177SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter.
CVE-2018-6585SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or fi...
CVE-2018-6584SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.
CVE-2018-6583SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.
CVE-2018-6396SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a l...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now