2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-25176HIGH8.8Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ...
CVE-2018-25175HIGH8.8Alienor Web Libre 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary...
CVE-2018-25173HIGH8.8Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database informa...
CVE-2018-25172HIGH8.8Pedidos 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri...
CVE-2018-25171HIGH8.8EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by...
CVE-2018-25170HIGH8.8DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri...
CVE-2018-25169HIGH8.7AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malfor...
CVE-2018-25167HIGH8.8Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthen...
CVE-2018-25166HIGH8.8Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2018-25165HIGH7.1Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitr...
CVE-2018-25164HIGH8.7EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive...
CVE-2018-25163HIGH8.8BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri...
CVE-2018-25162HIGH7.12-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executab...
CVE-2018-25161HIGH8.8Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL ...
CVE-2018-25158HIGH8.8Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute...
CVE-2018-25148HIGH8.8Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interfa...
CVE-2018-25146HIGH8.1Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and man...
CVE-2018-25145HIGH7.1Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers...
CVE-2018-25144HIGH8.7Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that...
CVE-2018-25143HIGH8.8Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SS...
CVE-2018-25141HIGH8.7FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video ...
CVE-2018-25139HIGH8.7FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live vi...
CVE-2018-25137HIGH8.7FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows att...
CVE-2018-25136HIGH8.7FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live ...
CVE-2018-25131HIGH7.2Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a stored cross-site scripting vulnerability in the configura...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now