2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-25190MEDIUM6.5Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin...
CVE-2018-25189HIGH8.8Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows u...
CVE-2018-25188HIGH8.8Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrar...
CVE-2018-25187CRITICAL9.8Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database file...
CVE-2018-25186MEDIUM4.3Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credent...
CVE-2018-25184MEDIUM6.9Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitra...
CVE-2018-25182HIGH8.8Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute ...
CVE-2018-25181HIGH8.7Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary direct...
CVE-2018-25180HIGH7.1Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL querie...
CVE-2018-25179HIGH8.8Gumbo CMS 0.99 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL qu...
CVE-2018-25178HIGH8.7Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensi...
CVE-2018-25177MEDIUM6.9Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator...
CVE-2018-25176HIGH8.8Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ...
CVE-2018-25175HIGH8.8Alienor Web Libre 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary...
CVE-2018-25174MEDIUM6.9ABC ERP 0.6.4 contains a cross-site request forgery vulnerability that allows attackers to modify administrator credenti...
CVE-2018-25173HIGH8.8Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database informa...
CVE-2018-25172HIGH8.8Pedidos 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri...
CVE-2018-25171HIGH8.8EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by...
CVE-2018-25170HIGH8.8DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri...
CVE-2018-25169HIGH8.7AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malfor...
CVE-2018-25168MEDIUM5.3Precurio Intranet Portal 2.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers t...
CVE-2018-25167HIGH8.8Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthen...
CVE-2018-25166HIGH8.8Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2018-25165HIGH7.1Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitr...
CVE-2018-25164HIGH8.7EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now