2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25387 | MEDIUM | 6.9 | 0.2% | May 29, 2026 | HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords... |
| CVE-2018-25386 | HIGH | 8.8 | 0.3% | May 29, 2026 | HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate datab... |
| CVE-2018-25385 | HIGH | 8.8 | 0.3% | May 29, 2026 | E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute... |
| CVE-2018-25384 | MEDIUM | 5.4 | 0.2% | May 29, 2026 | Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious sc... |
| CVE-2018-25383 | HIGH | 8.6 | 0.2% | May 29, 2026 | Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local att... |
| CVE-2018-25382 | HIGH | 8.8 | 0.3% | May 29, 2026 | Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information... |
| CVE-2018-25381 | HIGH | 7.1 | 0.3% | May 25, 2026 | Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute... |
| CVE-2018-25380 | HIGH | 7.1 | 0.3% | May 25, 2026 | Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute... |
| CVE-2018-25379 | HIGH | 8.8 | 0.4% | May 25, 2026 | Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthen... |
| CVE-2018-25378 | MEDIUM | 6.9 | 0.1% | May 25, 2026 | Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supp... |
| CVE-2018-25377 | HIGH | 8.6 | 0.2% | May 25, 2026 | Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows ... |
| CVE-2018-25376 | HIGH | 8.6 | 0.2% | May 25, 2026 | Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local ... |
| CVE-2018-25375 | HIGH | 8.6 | 0.2% | May 25, 2026 | SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local... |
| CVE-2018-25374 | HIGH | 8.7 | 0.8% | May 25, 2026 | Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated a... |
| CVE-2018-25373 | HIGH | 8.6 | 0.2% | May 25, 2026 | SocuSoft DVD Photo Slideshow Professional 8.07 contains a stack-based buffer overflow vulnerability in the registration ... |
| CVE-2018-25372 | HIGH | 8.8 | 0.3% | May 25, 2026 | MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to ex... |
| CVE-2018-25371 | HIGH | 8.8 | 0.3% | May 25, 2026 | mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipul... |
| CVE-2018-25370 | MEDIUM | 6.9 | 0.2% | May 25, 2026 | Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their perm... |
| CVE-2018-25369 | MEDIUM | 6.9 | 0.2% | May 25, 2026 | Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to cras... |
| CVE-2018-25368 | HIGH | 8.7 | 0.4% | May 25, 2026 | Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the applicati... |
| CVE-2018-25367 | MEDIUM | 6.9 | 0.2% | May 25, 2026 | NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by sup... |
| CVE-2018-25366 | HIGH | 8.6 | 0.2% | May 25, 2026 | CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecti... |
| CVE-2018-25365 | HIGH | 8.7 | 0.8% | May 25, 2026 | PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary fil... |
| CVE-2018-25364 | HIGH | 8.8 | 0.3% | May 25, 2026 | Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL qu... |
| CVE-2018-25363 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to del... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now