2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25190 | MEDIUM | 6.5 | 0.1% | Mar 6, 2026 | Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin... |
| CVE-2018-25189 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows u... |
| CVE-2018-25188 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrar... |
| CVE-2018-25187 | CRITICAL | 9.8 | 0.3% | Mar 6, 2026 | Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database file... |
| CVE-2018-25186 | MEDIUM | 4.3 | 0.1% | Mar 6, 2026 | Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credent... |
| CVE-2018-25184 | MEDIUM | 6.9 | 0.8% | Mar 6, 2026 | Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitra... |
| CVE-2018-25182 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute ... |
| CVE-2018-25181 | HIGH | 8.7 | 0.6% | Mar 6, 2026 | Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary direct... |
| CVE-2018-25180 | HIGH | 7.1 | 0.2% | Mar 6, 2026 | Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL querie... |
| CVE-2018-25179 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Gumbo CMS 0.99 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL qu... |
| CVE-2018-25178 | HIGH | 8.7 | 0.6% | Mar 6, 2026 | Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensi... |
| CVE-2018-25177 | MEDIUM | 6.9 | 0.1% | Mar 6, 2026 | Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator... |
| CVE-2018-25176 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ... |
| CVE-2018-25175 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | Alienor Web Libre 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary... |
| CVE-2018-25174 | MEDIUM | 6.9 | 0.1% | Mar 6, 2026 | ABC ERP 0.6.4 contains a cross-site request forgery vulnerability that allows attackers to modify administrator credenti... |
| CVE-2018-25173 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database informa... |
| CVE-2018-25172 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | Pedidos 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri... |
| CVE-2018-25171 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by... |
| CVE-2018-25170 | HIGH | 8.8 | 0.1% | Mar 6, 2026 | DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri... |
| CVE-2018-25169 | HIGH | 8.7 | 0.3% | Mar 6, 2026 | AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malfor... |
| CVE-2018-25168 | MEDIUM | 5.3 | 0.2% | Mar 6, 2026 | Precurio Intranet Portal 2.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers t... |
| CVE-2018-25167 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthen... |
| CVE-2018-25166 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit... |
| CVE-2018-25165 | HIGH | 7.1 | 0.2% | Mar 6, 2026 | Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitr... |
| CVE-2018-25164 | HIGH | 8.7 | 0.3% | Mar 6, 2026 | EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now