2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-25163HIGH8.8BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri...
CVE-2018-25162HIGH7.12-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executab...
CVE-2018-25161HIGH8.8Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL ...
CVE-2018-25160MEDIUM6.5HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code i...
CVE-2018-25158HIGH8.8Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute...
CVE-2018-25157MEDIUM6.4Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject maliciou...
CVE-2018-25132MEDIUM6.1MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious ...
CVE-2018-25116MEDIUM6.1MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for threa...
CVE-2018-25156MEDIUM5.1Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative pa...
CVE-2018-25155MEDIUM5.1Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative ...
CVE-2018-25154CRITICAL9.8GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigg...
CVE-2018-25153Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported issue does no...
CVE-2018-25152MEDIUM5.3Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrat...
CVE-2018-25151MEDIUM5.1Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to...
CVE-2018-25150MEDIUM5.3Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create ad...
CVE-2018-25149MEDIUM6.5Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform admin...
CVE-2018-25148HIGH8.8Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interfa...
CVE-2018-25147CRITICAL9.3Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway opera...
CVE-2018-25146HIGH8.1Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and man...
CVE-2018-25145HIGH7.1Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers...
CVE-2018-25144HIGH8.7Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that...
CVE-2018-25143HIGH8.8Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SS...
CVE-2018-25142CRITICAL9.8NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerabil...
CVE-2018-25141HIGH8.7FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video ...
CVE-2018-25140CRITICAL9.3FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementat...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now