CVEs from 2018

3,844 normalized CVEs published or assigned in this year.

Total
3,844
critical
critical 225
high
high 266
medium
medium 224
low
low 32
% Critical
5.9%
% with KEV
2.3%
% with exploit
2.4%

Top products

  • erpnext 4
  • terminal_services_manager 1
  • ultraiso 1
  • dolibarr_erp\/crm 1
  • gitbucket 1
  • pdfunite 1
  • qemu 1
  • virtualization_manager 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2018-20099 medium 5.5 8y ago Moderate: exiv2 security, bug fix, and enhancement update susedebianrockylinuxpython
CVE-2018-19352 medium 5.5 8y ago Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely. archdebianpython
CVE-2018-19351 medium 5.5 8y ago Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can e… archdebianpython
CVE-2018-18074 medium 5.5 8y ago Moderate: python27:2.7 security, bug fix, and enhancement update suserockylinuxdebianpython
CVE-2018-3750 medium 5.5 8y ago Moderate: nodejs:12 security update rockylinuxdebiannpm
CVE-2018-14574 medium 5.5 8y ago django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect. archsusedebianpython
CVE-2018-6188 medium 5.5 8y ago django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from th… archdebianpython
CVE-2018-16984 medium 5.5 8y ago An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display a… archsusedebianpython
CVE-2018-1000559 medium 5.5 8y ago qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via… archdebianpython
CVE-2018-14042 medium 5.5 8y ago Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update rockylinuxdebianrubynpm+3
CVE-2018-1999024 medium 5.5 8y ago MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running within a web browser. Th… archdebiannpm
CVE-2018-3740 medium 5.5 8y ago A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element. archdebianruby
CVE-2018-25334 medium 5.4 5.4 11d ago Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but…
CVE-2018-25370 medium 5.3 5.3 3d ago Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious H…
CVE-2018-25336 medium 5.3 5.3 11d ago jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HTML form…
CVE-2018-25327 medium 5.3 5.3 11d ago Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTM…
CVE-2018-25298 medium 5.3 5.3 28d ago Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attacker…
CVE-2018-10626 medium 4.4 4.4 8y ago Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired …
CVE-2018-25363 medium 4.3 4.3 3d ago Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can create hidden forms t…
CVE-2018-25354 medium 4.3 4.3 5d ago Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting malicious pag…
CVE-2018-25343 medium 4.3 4.3 5d ago Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by tricking authenticated users into submitting malicious requests. Attackers can craft H…
CVE-2018-25337 medium 4.3 4.3 11d ago Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML fo…
CVE-2018-25321 medium 4.3 4.3 11d ago TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attacker…
CVE-2018-25310 medium 4.3 4.3 28d ago VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cros…
CVE-2018-7685 unknown The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow … susedebian
CVE-2018-19206 unknown steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment. debian
CVE-2018-1000071 unknown roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via networ… debian
CVE-2018-19205 unknown Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated w… debian
CVE-2018-1000153 unknown 4y ago Jenkins vSphere Plugin Cross-Site Request Forgery vulnerability java
CVE-2018-1000190 unknown 4y ago Exposure of sensitive information vulnerability in Jenkins Black Duck Hub Plugin java
CVE-2018-1999042 unknown 4y ago Deserialization of Untrusted Data in Jenkins java
CVE-2018-15761 unknown 4y ago Cloud Foundry UAA Privilege Escalation java
CVE-2018-15801 unknown 8y ago Spring Security vulnerable to Authorization Bypass java