CVEs from 2018

3,113 normalized CVEs published or assigned in this year.

Total
3,113
critical
critical 229
high
high 302
medium
medium 256
low
low 39
% Critical
7.4%
% with KEV
2.9%
% with exploit
4.0%

Top products

  • core_i7 379
  • core_i5 375
  • core_i3 242
  • xeon_e5 82
  • xeon_e7 62
  • xeon_e3 58
  • xeon_gold 33
  • atom_z 30
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2018-7185 high 8.0 The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address…
CVE-2018-11769 high 8.0 arbitrary code execution in couchdb
CVE-2018-16840 high 8.0 A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` fun…
CVE-2018-16864 high 8.0 arbitrary code execution in systemd
CVE-2018-0500 high 8.0 Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits o…
CVE-2018-20030 high 8.0 An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU resources.
CVE-2018-16865 high 8.0 arbitrary code execution in systemd
CVE-2018-0492 high 8.0 Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
CVE-2018-11376 high 8.0 The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.
CVE-2018-17407 high 8.0 An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution wh…
CVE-2018-20199 high 8.0 A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash…
CVE-2018-6126 high 8.0 A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
CVE-2018-1000879 high 8.0 libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c…
CVE-2018-14379 high 8.0 multiple issues in libmp4v2
CVE-2018-1999023 high 8.0 The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appe…
CVE-2018-8792 high 8.0 rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that results in a Denial of Service (segfault).
CVE-2018-8795 high 8.0 rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_updates() and results in a memory corruption and probabl…
CVE-2018-8793 high 8.0 rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corruption and probably even a remote code execution.
CVE-2018-8794 high 8.0 rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruption and possibly even…
CVE-2018-8796 high 8.0 rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that results in a Denial of Service (segfault).
CVE-2018-16151 high 8.0 In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded al…
CVE-2018-1046 high 8.0 pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a specially crafted PCAP file can trigger a stack-base…
CVE-2018-8797 high 8.0 rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and probably even a remote code execution.
CVE-2018-8800 high 8.0 rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.
CVE-2018-8799 high 8.0 rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault).
CVE-2018-1000051 high 8.0 Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a …
CVE-2018-14360 high 8.0 An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
CVE-2018-20179 high 8.0 rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() and results in memory corruption and probably even…
CVE-2018-20174 high 8.0 rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function ui_clip_handle_data() that results in an information leak.
CVE-2018-14403 high 8.0 multiple issues in libmp4v2
CVE-2018-20180 high 8.0 rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably …
CVE-2018-14325 high 8.0 multiple issues in libmp4v2
CVE-2018-6574 high 8.0 4y ago Remote command execution via "go get" command with cgo in cmd/go
CVE-2018-16873 high 8.0 4y ago Remote command execution via "go get" with "-u" flag in cmd/go
CVE-2018-16874 high 8.0 4y ago Directory traversal via "go get" command in cmd/go
CVE-2018-16875 high 8.0 4y ago Denial of service in chain verification in crypto/x509
CVE-2018-20303 high 8.0 4y ago Gogs Directory Traversal
CVE-2018-1999006 high 8.0 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
CVE-2018-7408 high 8.0 4y ago An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announced in the vendor's bl…
CVE-2018-1999002 high 8.0 4y ago Improper Input Validation in Jenkins
CVE-2018-1999007 high 8.0 4y ago Cross-site scripting vulnerability exists in Jenkins and Stapler Plugin
CVE-2018-1999004 high 8.0 4y ago Incorrect Authorization in Jenkins
CVE-2018-1999005 high 8.0 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2018-1999001 high 8.0 4y ago Improper Input Validation in Jenkins
CVE-2018-1999003 high 8.0 4y ago Incorrect Authorization in Jenkins
CVE-2018-25032 high 8.0 4y ago RHSA-2022:7813: mingw-zlib security update (Important)
CVE-2018-13405 high 8.0 4y ago RHSA-2022:1988: kernel security, bug fix, and enhancement update (Important)
CVE-2018-25011 high 8.0 5y ago RHSA-2021:2354: libwebp security update (Important)
CVE-2018-16871 high 8.0 6y ago RHSA-2020:1769: kernel security, bug fix, and enhancement update (Important)
CVE-2018-12207 high 8.0 7y ago RHSA-2019:4245: kpatch-patch security update (Important)
CVE-2018-19985 high 8.0 7y ago RHSA-2019:3517: kernel security, bug fix, and enhancement update (Important)
CVE-2018-19854 high 8.0 7y ago RHSA-2019:3517: kernel security, bug fix, and enhancement update (Important)
CVE-2018-16884 high 8.0 7y ago RHSA-2019:3517: kernel security, bug fix, and enhancement update (Important)
CVE-2018-20169 high 8.0 7y ago RHSA-2019:3517: kernel security, bug fix, and enhancement update (Important)
CVE-2018-10871 high 8.0 7y ago RHSA-2019:3401: 389-ds:1.4 security, bug fix, and enhancement update (Important)
CVE-2018-20969 high 8.0 7y ago RHSA-2019:2798: patch security update (Important)
CVE-2018-19824 high 8.0 7y ago RHSA-2019:2741: kernel-rt security and bug fix update (Important)
CVE-2018-20784 high 8.0 7y ago RHSA-2019:1971: kernel-rt security and bug fix update (Important)
CVE-2018-16878 high 8.0 7y ago RHSA-2019:1279: pacemaker security and bug fix update (Important)
CVE-2018-16877 high 8.0 7y ago RHSA-2019:1279: pacemaker security and bug fix update (Important)
CVE-2018-18511 high 8.0 7y ago RHSA-2019:1308: thunderbird security update (Important)
CVE-2018-20815 high 8.0 7y ago RHSA-2019:1175: virt:rhel security update (Important)
CVE-2018-18509 high 8.0 7y ago RHSA-2019:1144: thunderbird security update (Important)
CVE-2018-5743 high 8.0 7y ago RHSA-2019:1145: bind security update (Important)
CVE-2018-18356 high 8.0 7y ago RHSA-2019:1144: thunderbird security update (Important)
CVE-2018-18506 high 8.0 7y ago RHSA-2019:1144: thunderbird security update (Important)
CVE-2018-12180 high 8.0 7y ago RHSA-2019:0968: edk2 security update (Important)
CVE-2018-8037 high 8.0 8y ago RHSA-2019:1529: pki-deps:10.6 security update (Important)
CVE-2018-8034 high 8.0 8y ago RHSA-2019:1529: pki-deps:10.6 security update (Important)
CVE-2018-8014 high 8.0 8y ago RHSA-2019:1529: pki-deps:10.6 security update (Important)
CVE-2018-11784 high 8.0 8y ago RHSA-2019:1529: pki-deps:10.6 security update (Important)
CVE-2018-12086 high 8.0 8y ago Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
CVE-2018-25302 high 7.8 7.8 1mo ago Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a ma…
CVE-2018-25261 high 7.8 7.8 1mo ago Iperius Backup 5.8.1 contains a local buffer overflow vulnerability in the structured exception handling (SEH) mechanism that allows local attackers to execute arbitrary code by supplying a malicious…
CVE-2018-25260 high 7.8 7.8 1mo ago MAGIX Music Editor 3.1 contains a buffer overflow vulnerability in the FreeDB Proxy Options dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. A…
CVE-2018-25259 high 7.8 7.8 1mo ago Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception…
CVE-2018-25213 high 7.8 7.8 2mo ago Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. At…
CVE-2018-6400 high 7.8 7.8 8y ago Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\.\pipe\WPSCloudSvr\WpsCloudSvr -- an "insecur…
CVE-2018-25396 high 7.5 7.5 16h ago Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attac…
CVE-2018-25391 high 7.5 7.5 16h ago HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target rec…
CVE-2018-25374 high 7.5 7.5 5d ago Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers …
CVE-2018-25368 high 7.5 7.5 5d ago Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers ca…
CVE-2018-25365 high 7.5 7.5 5d ago PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative path sequences in GET requests. Attackers can use pat…
CVE-2018-25358 high 7.5 7.5 7d ago D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the table_name parameter in POST req…
CVE-2018-25329 high 7.5 7.5 13d ago WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attack…
CVE-2018-25326 high 7.5 7.5 13d ago Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parame…
CVE-2018-25325 high 7.5 7.5 13d ago Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX …
CVE-2018-7794 high 7.5 7.5 7y ago A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) …
CVE-2018-7852 high 7.5 7.5 7y ago A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when an invalid private …
CVE-2018-7821 high 7.5 7.5 7y ago An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flood…
CVE-2018-17958 high 7.5 7.5 8y ago Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
CVE-2018-7792 high 7.5 7.5 8y ago A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows una…
CVE-2018-7789 high 7.5 7.5 8y ago An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability …
CVE-2018-3615 high 7.3 7.3 8y ago Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enc…
CVE-2018-25392 high 7.1 7.1 16h ago MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor, user, and jenis parameters in the log_activity f…
CVE-2018-25381 high 7.1 7.1 5d ago Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can injec…
CVE-2018-25380 high 7.1 7.1 5d ago Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_s…
CVE-2018-25352 high 7.1 7.1 7d ago WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code th…
CVE-2018-25347 high 7.1 7.1 7d ago WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv_f…
CVE-2018-25346 high 7.1 7.1 7d ago WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMa…