9.8
    Critical

    CVE-2018-6585

    Last Modified: 16 Feb 2018

    SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-6584

    Last Modified: 16 Feb 2018

    SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-6583

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-6582

    Last Modified: 5 Feb 2018

    SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.

    Source:Ihsan Sencan
    Published:5 Feb 2018
    9.8
    Critical

    CVE-2018-6581

    Last Modified: 2 Feb 2018

    SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.

    Source:Ihsan Sencan
    Published:2 Feb 2018
    9.8
    Critical

    CVE-2018-6580

    Last Modified: 2 Feb 2018

    Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.

    Source:Ihsan Sencan
    Published:2 Feb 2018
    9.8
    Critical

    CVE-2018-6579

    Last Modified: 2 Feb 2018

    SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.

    Source:Ihsan Sencan
    Published:2 Feb 2018
    9.8
    Critical

    CVE-2018-6578

    Last Modified: 2 Feb 2018

    SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.

    Source:Ihsan Sencan
    Published:2 Feb 2018
    9.8
    Critical

    CVE-2018-6577

    Last Modified: 2 Feb 2018

    SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.

    Source:Ihsan Sencan
    Published:2 Feb 2018
    9.8
    Critical

    CVE-2018-6576

    Last Modified: 2 Feb 2018

    SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.

    Source:Ihsan Sencan
    Published:2 Feb 2018
    9.8
    Critical

    CVE-2018-6575

    Last Modified: 2 Feb 2018

    SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.

    Source:Ihsan Sencan
    Published:2 Feb 2018
    7.8
    High

    CVE-2018-6574

    Last Modified: 21 Nov 2024

    Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.

    Published:7 Feb 2018
    8.8
    High

    CVE-2018-6563

    Last Modified: 16 May 2018

    Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change contact information by leveraging lack of an anti-CSRF token.

    Source:Compass Security
    Published:20 Jun 2018
    9.8
    Critical

    CVE-2018-6546

    Last Modified: 17 Apr 2018

    plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes code at a user-defined (local or SMB) path as SYSTEM when the execute_installer parameter is used in an HTTP message. This occurs without properly authenticating the user.

    Source:Securifera
    Published:13 Apr 2018
    9.8
    Critical

    CVE-2018-6537

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9121.

    Published:2 Feb 2018
    4.8
    Medium

    CVE-2018-6518

    Last Modified: 21 Nov 2024

    Composr CMS 10.0.13 has XSS via the site_name parameter in a page=admin-setupwizard&type=step3 request to /adminzone/index.php.

    Published:26 Apr 2018
    9.8
    Critical

    CVE-2018-6481

    Last Modified: 21 Feb 2018

    A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9124.

    Source:Daniel Teixeira
    Published:27 Feb 2018
    7.5
    High

    CVE-2018-6479

    Last Modified: 21 Nov 2024

    An issue was discovered on Netwave IP Camera devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to the / URI.

    Published:31 Jan 2018
    7.5
    High

    CVE-2018-6460

    Last Modified: 15 Feb 2018

    Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter func=$_APPLOG.Rfunc and extract sensitive information about the machine, including whether the user is connected to a VPN, to which VPN he/she is connected, and what is their real IP address.

    Source:SecuriTeam
    Published:31 Jan 2018
    8.1
    High

    CVE-2018-6443

    Last Modified: 21 May 2019

    A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. A remote unauthenticated user who has access to Network Advisor client libraries and able to decrypt the Jboss credentials could gain access to the Jboss web console.

    Source:Jakub Palaczynski
    Published:22 Jan 2019
    9.8
    Critical

    CVE-2018-6411

    Last Modified: 30 May 2018

    An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.

    Source:Amine Taouirsa
    Published:26 May 2018
    9.8
    Critical

    CVE-2018-6410

    Last Modified: 30 May 2018

    An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.

    Source:Amine Taouirsa
    Published:26 May 2018
    5.3
    Medium

    CVE-2018-6409

    Last Modified: 30 May 2018

    An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.

    Source:Amine Taouirsa
    Published:26 May 2018
    7.5
    High

    CVE-2018-6407

    Last Modified: 21 Nov 2024

    An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to /hy-cgi/devices.cgi?cmd=searchlandevice. The crash completely freezes the device.

    Published:30 Jan 2018
    9.8
    Critical

    CVE-2018-6398

    Last Modified: 30 Jan 2018

    SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.

    Source:Ihsan Sencan
    Published:30 Jan 2018
    7.5
    High

    CVE-2018-6397

    Last Modified: 30 Jan 2018

    Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter.

    Source:Ihsan Sencan
    Published:30 Jan 2018
    9.8
    Critical

    CVE-2018-6396

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-6395

    Last Modified: 30 Jan 2018

    SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.

    Source:Ihsan Sencan
    Published:30 Jan 2018
    9.8
    Critical

    CVE-2018-6394

    Last Modified: 16 Feb 2018

    SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    7.5
    High

    CVE-2018-6389

    Last Modified: 5 Feb 2018

    In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.

    Source:Barak Tawily
    Published:6 Feb 2018
    8.8
    High

    CVE-2018-6388

    Last Modified: 15 Feb 2018

    iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping test arguments on the Diagnostics page.

    Source:SecuriTeam
    Published:29 Jan 2018
    8.8
    High

    CVE-2018-6383

    Last Modified: 4 Jun 2021

    Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbitrary PHP code by uploading a file, a different vulnerability than CVE-2017-18048.

    Source:Ron Jost
    Published:29 Jan 2018
    9.8
    Critical

    CVE-2018-6376

    Last Modified: 21 Nov 2024

    In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.

    Published:30 Jan 2018
    9.8
    Critical

    CVE-2018-6373

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-6372

    Last Modified: 16 Feb 2018

    SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-6370

    Last Modified: 16 Feb 2018

    SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-6368

    Last Modified: 16 Feb 2018

    SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-6367

    Last Modified: 29 Jan 2018

    SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php category parameter.

    Source:Ihsan Sencan
    Published:29 Jan 2018
    9.8
    Critical

    CVE-2018-6365

    Last Modified: 29 Jan 2018

    SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.

    Source:Ihsan Sencan
    Published:29 Jan 2018
    9.8
    Critical

    CVE-2018-6364

    Last Modified: 29 Jan 2018

    SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.

    Source:Ihsan Sencan
    Published:29 Jan 2018
    9.8
    Critical

    CVE-2018-6363

    Last Modified: 29 Jan 2018

    SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.

    Source:Ihsan Sencan
    Published:29 Jan 2018
    6.1
    Medium

    CVE-2018-6341

    Last Modified: 6 May 2025

    React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.

    Published:31 Dec 2018
    9.8
    Critical

    CVE-2018-6329

    Last Modified: 29 Nov 2018

    It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege escalation exploit on the target system and subsequently execute arbitrary commands.

    Source:Metasploit
    Published:14 Mar 2018
    9.8
    Critical

    CVE-2018-6328

    Last Modified: 8 Oct 2018

    It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.

    Source:Metasploit
    Published:14 Mar 2018
    7.8
    High

    CVE-2018-6323

    Last Modified: 15 Feb 2018

    The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigned integer overflow because bfd_size_type multiplication is not used. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

    Source:r4xis
    Published:25 Jan 2018
    9.1
    Critical

    CVE-2018-6317

    Last Modified: 5 Feb 2018

    The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remote attackers to read memory or cause a denial of service.

    Source:res1n
    Published:2 Feb 2018
    6.8
    Medium

    CVE-2018-6242

    Last Modified: 21 Nov 2024

    Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device to reboot into RCM could exploit the vulnerability to execute unverified code.

    Published:1 May 2018
    6.8
    Medium

    CVE-2018-6230

    Last Modified: 22 Feb 2018

    A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

    Source:Core Security
    Published:15 Mar 2018
    9.8
    Critical

    CVE-2018-6229

    Last Modified: 22 Feb 2018

    A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

    Source:Core Security
    Published:15 Mar 2018
    9.8
    Critical

    CVE-2018-6228

    Last Modified: 22 Feb 2018

    A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

    Source:Core Security
    Published:15 Mar 2018