2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20234 | — | — | 6.0% | Mar 8, 2019 | There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 vi... |
| CVE-2018-20710 | — | — | — | Mar 7, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-6285. Reason: This candidate is a duplicate of C... |
| CVE-2018-18449 | — | — | 0.7% | Mar 7, 2019 | EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar ... |
| CVE-2018-17429 | — | — | 0.6% | Mar 7, 2019 | /console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account. |
| CVE-2018-17426 | — | — | 0.7% | Mar 7, 2019 | WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI. |
| CVE-2018-17425 | — | — | 0.7% | Mar 7, 2019 | WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.... |
| CVE-2018-17422 | — | — | 3.6% | Mar 7, 2019 | dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/... |
| CVE-2018-17421 | — | — | 0.9% | Mar 7, 2019 | An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathnam... |
| CVE-2018-17420 | — | — | 1.4% | Mar 7, 2019 | An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via ... |
| CVE-2018-17418 | — | — | 3.1% | Mar 7, 2019 | Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated... |
| CVE-2018-17416 | — | — | 1.4% | Mar 7, 2019 | A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter. |
| CVE-2018-17415 | — | — | 1.3% | Mar 7, 2019 | zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter. |
| CVE-2018-17414 | — | — | 1.3% | Mar 7, 2019 | zzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter. |
| CVE-2018-17413 | — | — | 0.8% | Mar 7, 2019 | XSS exists in zzcms v8.3 via the /uploadimg_form.php noshuiyin parameter. |
| CVE-2018-17412 | — | — | 1.5% | Mar 7, 2019 | zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header. |
| CVE-2018-16809 | — | — | 2.2% | Mar 7, 2019 | An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injec... |
| CVE-2018-16808 | — | — | 1.0% | Mar 7, 2019 | An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports ... |
| CVE-2018-16804 | — | — | 0.8% | Mar 7, 2019 | An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request. |
| CVE-2018-14499 | — | — | 0.8% | Mar 7, 2019 | An issue was found in HYBBS through 2016-03-08. There is an XSS vulnerablity via an article title to post.html. |
| CVE-2018-14498 | — | — | 3.1% | Mar 7, 2019 | get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of ... |
| CVE-2018-14038 | — | — | — | Mar 7, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-7642. Reason: This candidate is a reservation du... |
| CVE-2018-11783 | — | — | 1.9% | Mar 7, 2019 | sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configur... |
| CVE-2018-11793 | — | — | 5.0% | Mar 5, 2019 | When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to ... |
| CVE-2018-7986 | — | — | — | Mar 5, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-7985 | — | — | — | Mar 5, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now