2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1409 | — | — | 0.4% | Feb 19, 2018 | IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the ... |
| CVE-2018-5381 | MEDIUM | 6.5 | 30.5% | Feb 19, 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in ... |
| CVE-2018-5380 | MEDIUM | 4.3 | 15.0% | Feb 19, 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for d... |
| CVE-2018-5379 | HIGH | 7.5 | 39.5% | Feb 19, 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE messa... |
| CVE-2018-5378 | HIGH | 7.1 | 74.4% | Feb 19, 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer... |
| CVE-2018-6024 | — | — | 3.2% | Feb 18, 2018 | SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter. |
| CVE-2018-7217 | — | — | 1.9% | Feb 18, 2018 | In Bravo Tejari Procurement Portal, uploaded files are not properly validated by the application either on the client or... |
| CVE-2018-7216 | — | — | 3.0% | Feb 18, 2018 | Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal al... |
| CVE-2018-7212 | — | — | 1.9% | Feb 18, 2018 | An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows.... |
| CVE-2018-7211 | — | — | 0.8% | Feb 18, 2018 | An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing ... |
| CVE-2018-7210 | — | — | 1.5% | Feb 18, 2018 | An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct req... |
| CVE-2018-7209 | — | — | 1.5% | Feb 18, 2018 | An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct req... |
| CVE-2018-7208 | — | — | 2.3% | Feb 18, 2018 | In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribute... |
| CVE-2018-7207 | — | — | — | Feb 18, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-7206 | HIGH | 8.8 | 1.8% | Feb 18, 2018 | An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When usi... |
| CVE-2018-7198 | — | — | 2.5% | Feb 18, 2018 | October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page. |
| CVE-2018-7197 | — | — | 1.4% | Feb 18, 2018 | An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthen... |
| CVE-2018-7180 | — | — | 2.9% | Feb 17, 2018 | SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter. |
| CVE-2018-7179 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter. |
| CVE-2018-7178 | — | — | 4.1% | Feb 17, 2018 | SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter. |
| CVE-2018-7177 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter. |
| CVE-2018-6585 | — | — | 2.8% | Feb 17, 2018 | SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or fi... |
| CVE-2018-6584 | — | — | 4.0% | Feb 17, 2018 | SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request. |
| CVE-2018-6583 | — | — | 20.2% | Feb 17, 2018 | SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request. |
| CVE-2018-6396 | — | — | 24.4% | Feb 17, 2018 | SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a l... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now