2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25212 | HIGH | 7.8 | 0.2% | Mar 26, 2026 | Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows... |
| CVE-2018-25211 | HIGH | 7.8 | 0.3% | Mar 26, 2026 | Allok Video Splitter 3.1.1217 contains a buffer overflow vulnerability that allows local attackers to cause a denial of ... |
| CVE-2018-25210 | MEDIUM | 6.1 | 0.3% | Mar 26, 2026 | WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows u... |
| CVE-2018-25209 | HIGH | 8.8 | 0.3% | Mar 26, 2026 | OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers t... |
| CVE-2018-25208 | HIGH | 8.2 | 0.3% | Mar 26, 2026 | qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information b... |
| CVE-2018-25207 | HIGH | 7.1 | 0.3% | Mar 26, 2026 | Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated ... |
| CVE-2018-25206 | HIGH | 8.8 | 0.2% | Mar 26, 2026 | KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_ite... |
| CVE-2018-25205 | HIGH | 8.8 | 0.3% | Mar 26, 2026 | ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL comma... |
| CVE-2018-25204 | CRITICAL | 9.8 | 0.5% | Mar 26, 2026 | Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication b... |
| CVE-2018-25203 | HIGH | 8.8 | 0.3% | Mar 26, 2026 | Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate ... |
| CVE-2018-25202 | HIGH | 8.8 | 0.2% | Mar 26, 2026 | SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting S... |
| CVE-2018-25201 | CRITICAL | 9.8 | 0.5% | Mar 26, 2026 | School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows at... |
| CVE-2018-25195 | CRITICAL | 9.8 | 0.5% | Mar 26, 2026 | Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticat... |
| CVE-2018-25185 | CRITICAL | 9.8 | 0.5% | Mar 26, 2026 | Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate d... |
| CVE-2018-25183 | CRITICAL | 9.8 | 0.5% | Mar 26, 2026 | Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authenti... |
| CVE-2018-25159 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability th... |
| CVE-2018-25200 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create adm... |
| CVE-2018-25199 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL qu... |
| CVE-2018-25198 | MEDIUM | 6.9 | 0.1% | Mar 6, 2026 | eToolz 3.4.8.0 contains a denial of service vulnerability that allows local attackers to crash the application by supply... |
| CVE-2018-25197 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | PlayJoom 0.10.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL q... |
| CVE-2018-25196 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | ServerZilla 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database que... |
| CVE-2018-25194 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL quer... |
| CVE-2018-25193 | HIGH | 8.7 | 0.3% | Mar 6, 2026 | Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by ... |
| CVE-2018-25192 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authent... |
| CVE-2018-25191 | HIGH | 7.1 | 0.2% | Mar 6, 2026 | Facturation System 1.0 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now