2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-25407HIGH8.8eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arb...
CVE-2018-25406HIGH8.8eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arb...
CVE-2018-25405HIGH8.8eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arb...
CVE-2018-25404HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25403HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25402HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25401HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25400HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25399HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25398HIGH8.8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2018-25396HIGH8.7Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to re...
CVE-2018-25395HIGH8.8Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ...
CVE-2018-25394HIGH8.8Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ...
CVE-2018-25393HIGH7.1Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files b...
CVE-2018-25392HIGH7.1MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary ...
CVE-2018-25391HIGH8.7HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to dele...
CVE-2018-25390HIGH8.8HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie...
CVE-2018-25389HIGH8.8HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie...
CVE-2018-25388HIGH8.7HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious fil...
CVE-2018-25386HIGH8.8HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate datab...
CVE-2018-25385HIGH8.8E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute...
CVE-2018-25383HIGH8.6Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local att...
CVE-2018-25382HIGH8.8Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information...
CVE-2018-25381HIGH7.1Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute...
CVE-2018-25380HIGH7.1Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now