2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-25437HIGH8.7WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated atta...
CVE-2018-25434HIGH8.8WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25433HIGH8.8Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to e...
CVE-2018-25432HIGH8.6Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwri...
CVE-2018-25431HIGH7.1No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint tha...
CVE-2018-25430HIGH7.1Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL que...
CVE-2018-25429HIGH7.1Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL que...
CVE-2018-25428HIGH8.8Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL q...
CVE-2018-25426HIGH8.7WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malfo...
CVE-2018-25425HIGH8.8Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL que...
CVE-2018-25424HIGH8.8Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass ...
CVE-2018-25422HIGH8.8MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2018-25421HIGH7.1Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files...
CVE-2018-25420HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25419HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25418HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25417HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25416HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25415HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25414HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25413HIGH8.8AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25411HIGH8.8MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execut...
CVE-2018-25410HIGH7.1SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queri...
CVE-2018-25409HIGH8.7SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious fi...
CVE-2018-25408HIGH8.7The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauth...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now