2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25435 | MEDIUM | 6.9 | 0.2% | Jun 1, 2026 | ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions o... |
| CVE-2018-25423 | MEDIUM | 6.9 | 0.1% | May 30, 2026 | Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplyin... |
| CVE-2018-25397 | MEDIUM | 6.9 | 0.2% | May 29, 2026 | PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administra... |
| CVE-2018-25387 | MEDIUM | 6.9 | 0.2% | May 29, 2026 | HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords... |
| CVE-2018-25384 | MEDIUM | 5.1 | 0.2% | May 29, 2026 | Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious sc... |
| CVE-2018-25378 | MEDIUM | 6.9 | 0.1% | May 25, 2026 | Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supp... |
| CVE-2018-25370 | MEDIUM | 6.9 | 0.2% | May 25, 2026 | Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their perm... |
| CVE-2018-25369 | MEDIUM | 6.9 | 0.2% | May 25, 2026 | Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to cras... |
| CVE-2018-25367 | MEDIUM | 6.9 | 0.2% | May 25, 2026 | NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by sup... |
| CVE-2018-25363 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to del... |
| CVE-2018-25354 | MEDIUM | 5.3 | 0.1% | May 23, 2026 | Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user ... |
| CVE-2018-25349 | MEDIUM | 5.1 | 0.2% | May 23, 2026 | userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through... |
| CVE-2018-25343 | MEDIUM | 5.3 | 0.1% | May 23, 2026 | Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by trickin... |
| CVE-2018-25337 | MEDIUM | 5.3 | 0.2% | May 17, 2026 | Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized ... |
| CVE-2018-25336 | MEDIUM | 6.9 | 0.2% | May 17, 2026 | jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user acco... |
| CVE-2018-25334 | MEDIUM | 5.3 | 0.1% | May 17, 2026 | Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's informa... |
| CVE-2018-25331 | MEDIUM | 5.1 | 0.2% | May 17, 2026 | Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to i... |
| CVE-2018-25327 | MEDIUM | 6.9 | 0.1% | May 17, 2026 | Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform sta... |
| CVE-2018-25324 | MEDIUM | 6.9 | 0.5% | May 17, 2026 | Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticat... |
| CVE-2018-25321 | MEDIUM | 5.3 | 0.2% | May 17, 2026 | TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform u... |
| CVE-2018-25313 | MEDIUM | 6.9 | 0.1% | Apr 29, 2026 | SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers ... |
| CVE-2018-25310 | MEDIUM | 5.3 | 0.2% | Apr 29, 2026 | VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows au... |
| CVE-2018-25309 | MEDIUM | 5.1 | 0.3% | Apr 29, 2026 | MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malici... |
| CVE-2018-25306 | MEDIUM | 6.9 | 0.2% | Apr 29, 2026 | PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by process... |
| CVE-2018-25305 | MEDIUM | 6.9 | 0.1% | Apr 29, 2026 | librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service b... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now