2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-25436CRITICAL9.8WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows...
CVE-2018-25427CRITICAL9.8Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary co...
CVE-2018-25412CRITICAL9.8Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload maliciou...
CVE-2018-25357CRITICAL9.8Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute a...
CVE-2018-25350CRITICAL9.8userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid u...
CVE-2018-25335CRITICAL9.8WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers...
CVE-2018-25332CRITICAL9.8GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitr...
CVE-2018-25320CRITICAL9.8ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers t...
CVE-2018-25318CRITICAL9.8Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to...
CVE-2018-25317CRITICAL9.8Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows...
CVE-2018-25316CRITICAL9.8Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify...
CVE-2018-25272CRITICAL9.8ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and exec...
CVE-2018-25270CRITICAL9.8ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrar...
CVE-2018-25254CRITICAL9.8NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to ...
CVE-2018-25236CRITICAL9.8Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authenticatio...
CVE-2018-25237CRITICAL9.8Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interfac...
CVE-2018-25223CRITICAL9.8Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary cod...
CVE-2018-25221CRITICAL9.8EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execu...
CVE-2018-25220CRITICAL9.8Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supp...
CVE-2018-25204CRITICAL9.8Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication b...
CVE-2018-25201CRITICAL9.8School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows at...
CVE-2018-25195CRITICAL9.8Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticat...
CVE-2018-25185CRITICAL9.8Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate d...
CVE-2018-25183CRITICAL9.8Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authenti...
CVE-2018-25159CRITICAL9.8Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability th...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now