2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-25337MEDIUM5.3Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized ...
CVE-2018-25336MEDIUM6.9jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user acco...
CVE-2018-25335CRITICAL9.8WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers...
CVE-2018-25334MEDIUM5.4Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's informa...
CVE-2018-25333HIGH8.8Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated atta...
CVE-2018-25332CRITICAL9.8GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitr...
CVE-2018-25331MEDIUM6.1Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to i...
CVE-2018-25330HIGH8.8Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow at...
CVE-2018-25329HIGH8.7WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers...
CVE-2018-25328HIGH8.6VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction poin...
CVE-2018-25327MEDIUM6.9Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform sta...
CVE-2018-25326HIGH8.7Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arb...
CVE-2018-25325HIGH8.7Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitra...
CVE-2018-25324MEDIUM6.9Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticat...
CVE-2018-25323HIGH8.6Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that...
CVE-2018-25322HIGH8.6Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to exe...
CVE-2018-25321MEDIUM5.3TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform u...
CVE-2018-25320CRITICAL9.8ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers t...
CVE-2018-25319HIGH7.1Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulat...
CVE-2018-25318CRITICAL9.8Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to...
CVE-2018-25317CRITICAL9.8Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows...
CVE-2018-25316CRITICAL9.8Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify...
CVE-2018-25315HIGH8.6Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrar...
CVE-2018-25314HIGH8.6Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attacke...
CVE-2018-25313MEDIUM6.9SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now