2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-25217HIGH7.8PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers t...
CVE-2018-25213HIGH7.8Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to...
CVE-2018-25212HIGH7.8Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows...
CVE-2018-25211HIGH7.8Allok Video Splitter 3.1.1217 contains a buffer overflow vulnerability that allows local attackers to cause a denial of ...
CVE-2018-25209HIGH8.8OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers t...
CVE-2018-25208HIGH8.2qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information b...
CVE-2018-25207HIGH7.1Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated ...
CVE-2018-25206HIGH8.8KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_ite...
CVE-2018-25205HIGH8.8ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL comma...
CVE-2018-25203HIGH8.8Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate ...
CVE-2018-25202HIGH8.8SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting S...
CVE-2018-25200HIGH8.8OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create adm...
CVE-2018-25197HIGH8.8PlayJoom 0.10.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL q...
CVE-2018-25196HIGH8.8ServerZilla 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database que...
CVE-2018-25194HIGH8.8Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL quer...
CVE-2018-25193HIGH8.7Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by ...
CVE-2018-25192HIGH8.8GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authent...
CVE-2018-25191HIGH7.1Facturation System 1.0 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary ...
CVE-2018-25189HIGH8.8Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows u...
CVE-2018-25188HIGH8.8Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrar...
CVE-2018-25182HIGH8.8Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute ...
CVE-2018-25181HIGH8.7Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary direct...
CVE-2018-25180HIGH7.1Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL querie...
CVE-2018-25179HIGH8.8Gumbo CMS 0.99 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL qu...
CVE-2018-25178HIGH8.7Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now