2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25337 | MEDIUM | 5.3 | 0.2% | May 17, 2026 | Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized ... |
| CVE-2018-25336 | MEDIUM | 6.9 | 0.2% | May 17, 2026 | jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user acco... |
| CVE-2018-25335 | CRITICAL | 9.8 | 0.5% | May 17, 2026 | WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers... |
| CVE-2018-25334 | MEDIUM | 5.4 | 0.1% | May 17, 2026 | Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's informa... |
| CVE-2018-25333 | HIGH | 8.8 | 0.3% | May 17, 2026 | Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated atta... |
| CVE-2018-25332 | CRITICAL | 9.8 | 0.6% | May 17, 2026 | GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitr... |
| CVE-2018-25331 | MEDIUM | 6.1 | 0.2% | May 17, 2026 | Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to i... |
| CVE-2018-25330 | HIGH | 8.8 | 0.3% | May 17, 2026 | Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow at... |
| CVE-2018-25329 | HIGH | 8.7 | 0.4% | May 17, 2026 | WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers... |
| CVE-2018-25328 | HIGH | 8.6 | 0.1% | May 17, 2026 | VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction poin... |
| CVE-2018-25327 | MEDIUM | 6.9 | 0.1% | May 17, 2026 | Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform sta... |
| CVE-2018-25326 | HIGH | 8.7 | 0.6% | May 17, 2026 | Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arb... |
| CVE-2018-25325 | HIGH | 8.7 | 0.6% | May 17, 2026 | Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitra... |
| CVE-2018-25324 | MEDIUM | 6.9 | 0.5% | May 17, 2026 | Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticat... |
| CVE-2018-25323 | HIGH | 8.6 | 0.1% | May 17, 2026 | Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that... |
| CVE-2018-25322 | HIGH | 8.6 | 0.1% | May 17, 2026 | Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to exe... |
| CVE-2018-25321 | MEDIUM | 5.3 | 0.2% | May 17, 2026 | TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform u... |
| CVE-2018-25320 | CRITICAL | 9.8 | 0.6% | May 17, 2026 | ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers t... |
| CVE-2018-25319 | HIGH | 7.1 | 0.3% | May 17, 2026 | Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulat... |
| CVE-2018-25318 | CRITICAL | 9.8 | 0.7% | Apr 29, 2026 | Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to... |
| CVE-2018-25317 | CRITICAL | 9.8 | 0.7% | Apr 29, 2026 | Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows... |
| CVE-2018-25316 | CRITICAL | 9.8 | 0.7% | Apr 29, 2026 | Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify... |
| CVE-2018-25315 | HIGH | 8.6 | 0.2% | Apr 29, 2026 | Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrar... |
| CVE-2018-25314 | HIGH | 8.6 | 0.2% | Apr 29, 2026 | Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attacke... |
| CVE-2018-25313 | MEDIUM | 6.9 | 0.1% | Apr 29, 2026 | SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now