2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25176 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ... |
| CVE-2018-25175 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | Alienor Web Libre 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary... |
| CVE-2018-25173 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database informa... |
| CVE-2018-25172 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | Pedidos 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri... |
| CVE-2018-25171 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by... |
| CVE-2018-25170 | HIGH | 8.8 | 0.1% | Mar 6, 2026 | DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri... |
| CVE-2018-25169 | HIGH | 8.7 | 0.3% | Mar 6, 2026 | AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malfor... |
| CVE-2018-25167 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthen... |
| CVE-2018-25166 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit... |
| CVE-2018-25165 | HIGH | 7.1 | 0.2% | Mar 6, 2026 | Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitr... |
| CVE-2018-25164 | HIGH | 8.7 | 0.3% | Mar 6, 2026 | EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive... |
| CVE-2018-25163 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri... |
| CVE-2018-25162 | HIGH | 7.1 | 0.4% | Mar 6, 2026 | 2-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executab... |
| CVE-2018-25161 | HIGH | 8.8 | 0.2% | Mar 6, 2026 | Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL ... |
| CVE-2018-25158 | HIGH | 8.8 | 0.4% | Feb 20, 2026 | Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute... |
| CVE-2018-25148 | HIGH | 8.8 | 0.7% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interfa... |
| CVE-2018-25146 | HIGH | 8.1 | 0.4% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and man... |
| CVE-2018-25145 | HIGH | 7.1 | 0.4% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers... |
| CVE-2018-25144 | HIGH | 8.7 | 0.4% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that... |
| CVE-2018-25143 | HIGH | 8.8 | 0.5% | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SS... |
| CVE-2018-25141 | HIGH | 8.7 | 0.4% | Dec 24, 2025 | FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video ... |
| CVE-2018-25139 | HIGH | 8.7 | 0.4% | Dec 24, 2025 | FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live vi... |
| CVE-2018-25137 | HIGH | 8.7 | 0.4% | Dec 24, 2025 | FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows att... |
| CVE-2018-25136 | HIGH | 8.7 | 0.4% | Dec 24, 2025 | FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live ... |
| CVE-2018-25131 | HIGH | 7.2 | 0.2% | Dec 24, 2025 | Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a stored cross-site scripting vulnerability in the configura... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now