2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-25212HIGH7.8Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows...
CVE-2018-25211HIGH7.8Allok Video Splitter 3.1.1217 contains a buffer overflow vulnerability that allows local attackers to cause a denial of ...
CVE-2018-25210MEDIUM6.1WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows u...
CVE-2018-25209HIGH8.8OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers t...
CVE-2018-25208HIGH8.2qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information b...
CVE-2018-25207HIGH7.1Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated ...
CVE-2018-25206HIGH8.8KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_ite...
CVE-2018-25205HIGH8.8ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL comma...
CVE-2018-25204CRITICAL9.8Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication b...
CVE-2018-25203HIGH8.8Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate ...
CVE-2018-25202HIGH8.8SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting S...
CVE-2018-25201CRITICAL9.8School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows at...
CVE-2018-25195CRITICAL9.8Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticat...
CVE-2018-25185CRITICAL9.8Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate d...
CVE-2018-25183CRITICAL9.8Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authenti...
CVE-2018-25159CRITICAL9.8Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability th...
CVE-2018-25200HIGH8.8OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create adm...
CVE-2018-25199CRITICAL9.8OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL qu...
CVE-2018-25198MEDIUM6.9eToolz 3.4.8.0 contains a denial of service vulnerability that allows local attackers to crash the application by supply...
CVE-2018-25197HIGH8.8PlayJoom 0.10.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL q...
CVE-2018-25196HIGH8.8ServerZilla 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database que...
CVE-2018-25194HIGH8.8Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL quer...
CVE-2018-25193HIGH8.7Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by ...
CVE-2018-25192HIGH8.8GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authent...
CVE-2018-25191HIGH7.1Facturation System 1.0 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now