2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25163 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri... |
| CVE-2018-25162 | HIGH | 7.1 | 0.4% | Mar 6, 2026 | 2-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executab... |
| CVE-2018-25161 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL ... |
| CVE-2018-25160 | MEDIUM | 6.5 | 0.4% | Feb 27, 2026 | HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code i... |
| CVE-2018-25158 | HIGH | 8.8 | 0.4% | Feb 20, 2026 | Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute... |
| CVE-2018-25157 | MEDIUM | 6.4 | 0.3% | Feb 11, 2026 | Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject maliciou... |
| CVE-2018-25132 | MEDIUM | 6.1 | 0.2% | Jan 23, 2026 | MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious ... |
| CVE-2018-25116 | MEDIUM | 6.1 | 0.3% | Jan 23, 2026 | MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for threa... |
| CVE-2018-25156 | MEDIUM | 5.1 | 0.2% | Dec 24, 2025 | Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative pa... |
| CVE-2018-25155 | MEDIUM | 5.1 | 0.2% | Dec 24, 2025 | Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative ... |
| CVE-2018-25154 | CRITICAL | 9.8 | 0.3% | Dec 24, 2025 | GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigg... |
| CVE-2018-25153 | — | — | — | Dec 24, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported issue does no... |
| CVE-2018-25152 | MEDIUM | 5.3 | 0.1% | Dec 24, 2025 | Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrat... |
| CVE-2018-25151 | MEDIUM | 5.1 | 0.1% | Dec 24, 2025 | Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to... |
| CVE-2018-25150 | MEDIUM | 5.3 | 0.1% | Dec 24, 2025 | Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create ad... |
| CVE-2018-25149 | MEDIUM | 6.5 | 0.2% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform admin... |
| CVE-2018-25148 | HIGH | 8.8 | 0.7% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interfa... |
| CVE-2018-25147 | CRITICAL | 9.3 | 0.3% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway opera... |
| CVE-2018-25146 | HIGH | 8.1 | 0.4% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and man... |
| CVE-2018-25145 | HIGH | 7.1 | 0.4% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers... |
| CVE-2018-25144 | HIGH | 8.7 | 0.4% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that... |
| CVE-2018-25143 | HIGH | 8.8 | 0.5% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SS... |
| CVE-2018-25142 | CRITICAL | 9.8 | 0.4% | Dec 24, 2025 | NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerabil... |
| CVE-2018-25141 | HIGH | 8.7 | 0.4% | Dec 24, 2025 | FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video ... |
| CVE-2018-25140 | CRITICAL | 9.3 | 0.3% | Dec 24, 2025 | FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementat... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now