2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25199 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL qu... |
| CVE-2018-25187 | CRITICAL | 9.8 | 0.3% | Mar 6, 2026 | Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database file... |
| CVE-2018-25154 | CRITICAL | 9.8 | 0.3% | Dec 24, 2025 | GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigg... |
| CVE-2018-25147 | CRITICAL | 9.3 | 0.3% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway opera... |
| CVE-2018-25142 | CRITICAL | 9.8 | 0.4% | Dec 24, 2025 | NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerabil... |
| CVE-2018-25140 | CRITICAL | 9.3 | 0.3% | Dec 24, 2025 | FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementat... |
| CVE-2018-25138 | CRITICAL | 9.8 | 0.5% | Dec 24, 2025 | FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal ... |
| CVE-2018-25135 | CRITICAL | 9.8 | 0.6% | Dec 24, 2025 | Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by... |
| CVE-2018-25134 | CRITICAL | 9.8 | 0.6% | Dec 24, 2025 | Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that ... |
| CVE-2018-25128 | CRITICAL | 9.3 | 0.4% | Dec 24, 2025 | SOCA Access Control System 180612 contains multiple SQL injection vulnerabilities that allow attackers to manipulate dat... |
| CVE-2018-25126 | CRITICAL | 9.3 | 3.7% | Nov 24, 2025 | Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains ... |
| CVE-2018-25120 | CRITICAL | 9.8 | 9.8% | Oct 29, 2025 | D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulner... |
| CVE-2018-25118 | CRITICAL | 10 | 1.3% | Oct 20, 2025 | GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability v... |
| CVE-2018-25117 | CRITICAL | 9.3 | 0.4% | Oct 15, 2025 | VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a... |
| CVE-2018-25115 | CRITICAL | 9.8 | 8.7% | Aug 27, 2025 | Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware... |
| CVE-2018-25114 | CRITICAL | 9.3 | 2.8% | Jul 23, 2025 | A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default c... |
| CVE-2018-4301 | CRITICAL | 9.8 | 0.5% | Jan 8, 2025 | This issue is fixed in SCSSU-201801. A potential stack based buffer overflow existed in GemaltoKeyHandle.cpp. |
| CVE-2018-9388 | CRITICAL | 9.8 | 0.2% | Dec 5, 2024 | In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing... |
| CVE-2018-9430 | CRITICAL | 9.8 | 0.4% | Dec 2, 2024 | In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lea... |
| CVE-2018-9418 | CRITICAL | 9.8 | 0.3% | Dec 2, 2024 | In handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. T... |
| CVE-2018-9479 | CRITICAL | 9.8 | 0.4% | Nov 20, 2024 | In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to... |
| CVE-2018-9478 | CRITICAL | 9.8 | 0.4% | Nov 20, 2024 | In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to... |
| CVE-2018-9467 | CRITICAL | 9.8 | 0.3% | Nov 20, 2024 | In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could le... |
| CVE-2018-25105 | CRITICAL | 9.8 | 0.8% | Oct 16, 2024 | The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /i... |
| CVE-2018-25099 | CRITICAL | 9.8 | 0.5% | Mar 18, 2024 | In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now