2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-25437HIGH8.7WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated atta...
CVE-2018-25436CRITICAL9.3WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows...
CVE-2018-25435MEDIUM6.9ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions o...
CVE-2018-25434HIGH8.8WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25433HIGH8.8Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to e...
CVE-2018-25432HIGH8.6Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwri...
CVE-2018-25431HIGH7.1No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint tha...
CVE-2018-25430HIGH7.1Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL que...
CVE-2018-25429HIGH7.1Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL que...
CVE-2018-25428HIGH8.8Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL q...
CVE-2018-25427CRITICAL9.3Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary co...
CVE-2018-25426HIGH8.7WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malfo...
CVE-2018-25425HIGH8.8Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL que...
CVE-2018-25424HIGH8.8Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass ...
CVE-2018-25423MEDIUM6.9Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplyin...
CVE-2018-25422HIGH8.8MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2018-25421HIGH7.1Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files...
CVE-2018-25420HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25419HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25418HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25417HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25416HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25415HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25414HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25413HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now