2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-25362HIGH8.8Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database querie...
CVE-2018-25361HIGH7Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove pass...
CVE-2018-25360HIGH8.6AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field th...
CVE-2018-25359HIGH8.6Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege use...
CVE-2018-25358HIGH8.7D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve se...
CVE-2018-25357CRITICAL9.8Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute a...
CVE-2018-25356HIGH8.6SIPp 3.6 and earlier contains a local buffer overflow vulnerability in command-line argument handling that allows local ...
CVE-2018-25355HIGH8.6Audiograbber 1.83 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by expl...
CVE-2018-25354MEDIUM5.3Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user ...
CVE-2018-25353HIGH8.8Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated use...
CVE-2018-25352HIGH7.1WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows ...
CVE-2018-25351HIGH8.8Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attacker...
CVE-2018-25350CRITICAL9.8userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid u...
CVE-2018-25349MEDIUM6.1userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through...
CVE-2018-25348HIGH8.8Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipu...
CVE-2018-25347HIGH7.1WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to...
CVE-2018-25346HIGH7.1WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers ...
CVE-2018-25345HIGH8.610-Strike Network Scanner 3.0 contains a local buffer overflow vulnerability in the host name field that allows attacker...
CVE-2018-25344HIGH8.610-Strike Network Inventory Explorer 8.54 contains a stack-based buffer overflow vulnerability in the registration key i...
CVE-2018-25343MEDIUM5.3Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by trickin...
CVE-2018-25342HIGH8.8Smartshop 1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate ...
CVE-2018-25341HIGH8.8Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL querie...
CVE-2018-25340HIGH8.8Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL querie...
CVE-2018-25339HIGH8.8Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract da...
CVE-2018-25338HIGH8.8Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extr...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now