2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25139 | HIGH | 8.7 | 0.4% | Dec 24, 2025 | FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live vi... |
| CVE-2018-25138 | CRITICAL | 9.8 | 0.5% | Dec 24, 2025 | FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal ... |
| CVE-2018-25137 | HIGH | 8.7 | 0.4% | Dec 24, 2025 | FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows att... |
| CVE-2018-25136 | HIGH | 8.7 | 0.4% | Dec 24, 2025 | FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live ... |
| CVE-2018-25135 | CRITICAL | 9.8 | 0.6% | Dec 24, 2025 | Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by... |
| CVE-2018-25134 | CRITICAL | 9.8 | 0.6% | Dec 24, 2025 | Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that ... |
| CVE-2018-25133 | MEDIUM | 5.1 | 0.1% | Dec 24, 2025 | Synaccess netBooter NP-0801DU 7.4 contains a cross-site request forgery vulnerability that allows attackers to perform a... |
| CVE-2018-25131 | HIGH | 7.2 | 0.2% | Dec 24, 2025 | Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a stored cross-site scripting vulnerability in the configura... |
| CVE-2018-25130 | MEDIUM | 6.8 | 0.1% | Dec 24, 2025 | Beward Intercom 2.3.1 contains a credentials disclosure vulnerability that allows local attackers to access plain-text a... |
| CVE-2018-25129 | HIGH | 7.5 | 0.3% | Dec 24, 2025 | SOCA Access Control System 180612 contains multiple insecure direct object reference vulnerabilities that allow attacker... |
| CVE-2018-25128 | CRITICAL | 9.3 | 0.4% | Dec 24, 2025 | SOCA Access Control System 180612 contains multiple SQL injection vulnerabilities that allow attackers to manipulate dat... |
| CVE-2018-25127 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | SOCA Access Control System 180612 contains a cross-site request forgery vulnerability that allows attackers to perform a... |
| CVE-2018-25126 | CRITICAL | 9.3 | 3.7% | Nov 24, 2025 | Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains ... |
| CVE-2018-25125 | HIGH | 8.7 | 0.4% | Nov 14, 2025 | Netis ADSL Router DL4322D firmware RTK 2.1.1 contains a buffer overflow vulnerability in the embedded FTP service that a... |
| CVE-2018-25124 | HIGH | 8.7 | 0.8% | Nov 10, 2025 | PacsOne Server version 6.6.2 (prior versions are likely affected) contains a directory traversal vulnerability within th... |
| CVE-2018-25123 | HIGH | 7.8 | 0.3% | Oct 30, 2025 | Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-rela... |
| CVE-2018-25122 | HIGH | 8.8 | 1.5% | Oct 30, 2025 | Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The dow... |
| CVE-2018-25121 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface.... |
| CVE-2018-25119 | MEDIUM | 6.1 | 0.5% | Oct 30, 2025 | Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Ins... |
| CVE-2018-25120 | CRITICAL | 9.8 | 9.8% | Oct 29, 2025 | D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulner... |
| CVE-2018-25118 | CRITICAL | 10 | 1.3% | Oct 20, 2025 | GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability v... |
| CVE-2018-25117 | CRITICAL | 9.3 | 0.4% | Oct 15, 2025 | VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a... |
| CVE-2018-25115 | CRITICAL | 9.8 | 8.7% | Aug 27, 2025 | Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware... |
| CVE-2018-25114 | CRITICAL | 9.3 | 2.8% | Jul 23, 2025 | A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default c... |
| CVE-2018-25113 | HIGH | 8.7 | 1.2% | Jul 23, 2025 | An unauthenticated path traversal vulnerability exists in Dicoogle PACS Web Server version 2.5.0 and possibly earlier. T... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now