2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-25412CRITICAL9.3Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload maliciou...
CVE-2018-25411HIGH8.8MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execut...
CVE-2018-25410HIGH7.1SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queri...
CVE-2018-25409HIGH8.7SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious fi...
CVE-2018-25408HIGH8.7The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauth...
CVE-2018-25407HIGH8.8eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arb...
CVE-2018-25406HIGH8.8eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arb...
CVE-2018-25405HIGH8.8eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arb...
CVE-2018-25404HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25403HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25402HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25401HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25400HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25399HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25398HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25397MEDIUM6.9PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administra...
CVE-2018-25396HIGH8.7Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to re...
CVE-2018-25395HIGH8.8Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ...
CVE-2018-25394HIGH8.8Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ...
CVE-2018-25393HIGH7.1Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files b...
CVE-2018-25392HIGH7.1MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary ...
CVE-2018-25391HIGH8.7HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to dele...
CVE-2018-25390HIGH8.8HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie...
CVE-2018-25389HIGH8.8HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie...
CVE-2018-25388HIGH8.7HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious fil...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now