2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25436 | CRITICAL | 9.8 | 0.7% | Jun 15, 2026 | WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows... |
| CVE-2018-25427 | CRITICAL | 9.8 | 0.9% | Jun 1, 2026 | Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary co... |
| CVE-2018-25412 | CRITICAL | 9.8 | 0.8% | May 30, 2026 | Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload maliciou... |
| CVE-2018-25357 | CRITICAL | 9.8 | 1.7% | May 23, 2026 | Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute a... |
| CVE-2018-25350 | CRITICAL | 9.8 | 0.4% | May 23, 2026 | userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid u... |
| CVE-2018-25335 | CRITICAL | 9.8 | 0.5% | May 17, 2026 | WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers... |
| CVE-2018-25332 | CRITICAL | 9.8 | 0.6% | May 17, 2026 | GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitr... |
| CVE-2018-25320 | CRITICAL | 9.8 | 0.6% | May 17, 2026 | ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers t... |
| CVE-2018-25318 | CRITICAL | 9.8 | 0.7% | Apr 29, 2026 | Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to... |
| CVE-2018-25317 | CRITICAL | 9.8 | 0.7% | Apr 29, 2026 | Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows... |
| CVE-2018-25316 | CRITICAL | 9.8 | 0.7% | Apr 29, 2026 | Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify... |
| CVE-2018-25272 | CRITICAL | 9.8 | 0.4% | Apr 22, 2026 | ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and exec... |
| CVE-2018-25270 | CRITICAL | 9.8 | 0.9% | Apr 22, 2026 | ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrar... |
| CVE-2018-25254 | CRITICAL | 9.8 | 0.9% | Apr 4, 2026 | NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to ... |
| CVE-2018-25236 | CRITICAL | 9.8 | 0.5% | Apr 3, 2026 | Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authenticatio... |
| CVE-2018-25237 | CRITICAL | 9.8 | 0.8% | Apr 3, 2026 | Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interfac... |
| CVE-2018-25223 | CRITICAL | 9.8 | 0.9% | Mar 28, 2026 | Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary cod... |
| CVE-2018-25221 | CRITICAL | 9.8 | 0.8% | Mar 28, 2026 | EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execu... |
| CVE-2018-25220 | CRITICAL | 9.8 | 0.6% | Mar 28, 2026 | Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supp... |
| CVE-2018-25204 | CRITICAL | 9.8 | 0.5% | Mar 26, 2026 | Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication b... |
| CVE-2018-25201 | CRITICAL | 9.8 | 0.5% | Mar 26, 2026 | School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows at... |
| CVE-2018-25195 | CRITICAL | 9.8 | 0.5% | Mar 26, 2026 | Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticat... |
| CVE-2018-25185 | CRITICAL | 9.8 | 0.5% | Mar 26, 2026 | Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate d... |
| CVE-2018-25183 | CRITICAL | 9.8 | 0.5% | Mar 26, 2026 | Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authenti... |
| CVE-2018-25159 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability th... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now