CVEs from 2018
Total
3,419
critical
critical 225
high
high 266
medium
medium 224
low
low 32
% Critical
6.6%
% with KEV
2.6%
% with exploit
2.7%
Top vendors
- frappe 4
- redhat 2
- magix 1
- mybb 1
- gitbucket 1
- qemu 1
- dragonexpert 1
- kingsoftstore 1
Top products
- erpnext 4
- terminal_services_manager 1
- ultraiso 1
- dolibarr_erp\/crm 1
- gitbucket 1
- pdfunite 1
- qemu 1
- virtualization_manager 1
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2018-17480 | critical | — | 10.0 | 4y ago | multiple issues in chromium | |
| CVE-2018-17463 | critical | — | 10.0 | 4y ago | multiple issues in chromium | |
| CVE-2018-7602 | critical | — | 10.0 | 8y ago | A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. | |
| CVE-2018-7600 | critical | — | 10.0 | 8y ago | Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. | |
| CVE-2018-6789 | high | — | 9.5 | 5y ago | Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution. | |
| CVE-2018-14634 | unknown | — | 1.5 | 4mo ago | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate … | |
| CVE-2018-14667 | unknown | — | 1.5 | 4y ago | Richfaces vulnerable to arbitrary code execution | |
| CVE-2018-1000861 | unknown | — | 1.5 | 4y ago | Deserialization of Untrusted Data in Jenkins | |
| CVE-2018-11776 | unknown | — | 1.5 | 8y ago | Apache Struts vulnerable to remote command execution (RCE) due to improper input validation | |
| CVE-2018-1273 | unknown | — | 1.5 | 8y ago | Spring Data Commons remote code injection vulnerability |