2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25226 | MEDIUM | 5.5 | 0.2% | Mar 30, 2026 | FTPShell Server 6.83 contains a buffer overflow vulnerability that allows local attackers to crash the application by su... |
| CVE-2018-25216 | MEDIUM | 5.5 | 0.2% | Mar 26, 2026 | AnyBurn 4.3 contains a local buffer overflow vulnerability that allows local attackers to crash the application by suppl... |
| CVE-2018-25215 | MEDIUM | 5.5 | 0.2% | Mar 26, 2026 | Excel Password Recovery Professional 8.2.0.0 contains a local buffer overflow vulnerability that allows attackers to cau... |
| CVE-2018-25214 | MEDIUM | 5.5 | 0.2% | Mar 26, 2026 | MegaPing contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplyin... |
| CVE-2018-25210 | MEDIUM | 6.1 | 0.3% | Mar 26, 2026 | WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows u... |
| CVE-2018-25198 | MEDIUM | 6.9 | 0.1% | Mar 6, 2026 | eToolz 3.4.8.0 contains a denial of service vulnerability that allows local attackers to crash the application by supply... |
| CVE-2018-25190 | MEDIUM | 6.5 | 0.1% | Mar 6, 2026 | Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin... |
| CVE-2018-25186 | MEDIUM | 4.3 | 0.1% | Mar 6, 2026 | Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credent... |
| CVE-2018-25184 | MEDIUM | 6.9 | 0.8% | Mar 6, 2026 | Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitra... |
| CVE-2018-25177 | MEDIUM | 6.9 | 0.1% | Mar 6, 2026 | Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator... |
| CVE-2018-25174 | MEDIUM | 6.9 | 0.1% | Mar 6, 2026 | ABC ERP 0.6.4 contains a cross-site request forgery vulnerability that allows attackers to modify administrator credenti... |
| CVE-2018-25168 | MEDIUM | 5.3 | 0.2% | Mar 6, 2026 | Precurio Intranet Portal 2.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers t... |
| CVE-2018-25160 | MEDIUM | 6.5 | 0.4% | Feb 27, 2026 | HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code i... |
| CVE-2018-25157 | MEDIUM | 6.4 | 0.3% | Feb 11, 2026 | Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject maliciou... |
| CVE-2018-25132 | MEDIUM | 6.1 | 0.2% | Jan 23, 2026 | MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious ... |
| CVE-2018-25116 | MEDIUM | 6.1 | 0.3% | Jan 23, 2026 | MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for threa... |
| CVE-2018-25156 | MEDIUM | 5.1 | 0.2% | Dec 24, 2025 | Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative pa... |
| CVE-2018-25155 | MEDIUM | 5.1 | 0.2% | Dec 24, 2025 | Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative ... |
| CVE-2018-25152 | MEDIUM | 5.3 | 0.1% | Dec 24, 2025 | Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrat... |
| CVE-2018-25151 | MEDIUM | 5.1 | 0.1% | Dec 24, 2025 | Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to... |
| CVE-2018-25150 | MEDIUM | 5.3 | 0.1% | Dec 24, 2025 | Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create ad... |
| CVE-2018-25149 | MEDIUM | 6.5 | 0.2% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform admin... |
| CVE-2018-25133 | MEDIUM | 5.1 | 0.1% | Dec 24, 2025 | Synaccess netBooter NP-0801DU 7.4 contains a cross-site request forgery vulnerability that allows attackers to perform a... |
| CVE-2018-25130 | MEDIUM | 6.8 | 0.1% | Dec 24, 2025 | Beward Intercom 2.3.1 contains a credentials disclosure vulnerability that allows local attackers to access plain-text a... |
| CVE-2018-25127 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | SOCA Access Control System 180612 contains a cross-site request forgery vulnerability that allows attackers to perform a... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now