CVEs from 2018

3,156 normalized CVEs published or assigned in this year.

Total
3,156
critical
critical 228
high
high 272
medium
medium 224
low
low 32
% Critical
7.2%
% with KEV
2.8%
% with exploit
4.0%

Top products

  • modicon_m221 6
  • erpnext 4
  • somachine_basic 2
  • modicon_m340 2
  • modicon_m580 2
  • 140cpu67160 1
  • 140cpu65160s 1
  • terminal_services_manager 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2018-15133 unknown 2.5 4y ago Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl…
CVE-2018-1000861 unknown 2.5 4y ago A code execution vulnerability exists in the Stapler web framework used by Jenkins
CVE-2018-8440 unknown 2.5 4y ago An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
CVE-2018-11138 unknown 2.5 4y ago The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
CVE-2018-8120 unknown 2.5 4y ago A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
CVE-2018-20250 unknown 2.5 4y ago WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
CVE-2018-8453 unknown 2.5 4y ago Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
CVE-2018-14847 unknown 2.5 5y ago MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability i…
CVE-2018-0296 unknown 2.5 5y ago Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or inform…
CVE-2018-15961 unknown 2.5 5y ago Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.
CVE-2018-13379 unknown 2.5 5y ago Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource request…
CVE-2018-20062 unknown 2.5 5y ago ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.
CVE-2018-15811 unknown 2.5 7y ago DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.
CVE-2018-18325 unknown 2.5 7y ago DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch f…
CVE-2018-11776 unknown 2.5 8y ago Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defi…
CVE-2018-14634 unknown 1.5 4mo ago Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escala…
CVE-2018-4063 unknown 1.5 6mo ago Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploade…
CVE-2018-8639 unknown 1.5 1y ago Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnera…
CVE-2018-19410 unknown 1.5 1y ago Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).
CVE-2018-5430 unknown 1.5 4y ago TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files.
CVE-2018-18809 unknown 1.5 4y ago TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.
CVE-2018-19320 unknown 1.5 4y ago The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complet…
CVE-2018-19321 unknown 1.5 4y ago The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could…
CVE-2018-19323 unknown 1.5 4y ago The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be…
CVE-2018-19322 unknown 1.5 4y ago The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leve…
CVE-2018-13374 unknown 1.5 4y ago Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server conn…
CVE-2018-7445 unknown 1.5 4y ago In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code e…
CVE-2018-6530 unknown 1.5 4y ago Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.
CVE-2018-4344 unknown 1.5 4y ago Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution.
CVE-2018-6065 unknown 1.5 4y ago Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect mult…
CVE-2018-4990 unknown 1.5 4y ago Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
CVE-2018-19949 unknown 1.5 4y ago A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
CVE-2018-19943 unknown 1.5 4y ago A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
CVE-2018-19953 unknown 1.5 4y ago A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
CVE-2018-8611 unknown 1.5 4y ago A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.
CVE-2018-5002 unknown 1.5 4y ago Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
CVE-2018-8589 unknown 1.5 4y ago A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security contex…
CVE-2018-8298 unknown 1.5 4y ago The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
CVE-2018-14667 unknown 1.5 4y ago Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute…
CVE-2018-6882 unknown 1.5 4y ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
CVE-2018-7841 unknown 1.5 4y ago A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
CVE-2018-20753 unknown 1.5 4y ago Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
CVE-2018-10562 unknown 1.5 4y ago Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
CVE-2018-10561 unknown 1.5 4y ago Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
CVE-2018-8405 unknown 1.5 4y ago An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
CVE-2018-8406 unknown 1.5 4y ago An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
CVE-2018-0147 unknown 1.5 4y ago A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulne…
CVE-2018-0125 unknown 1.5 4y ago A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
CVE-2018-14839 unknown 1.5 4y ago LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.
CVE-2018-6961 unknown 1.5 4y ago VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.
CVE-2018-8414 unknown 1.5 4y ago A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
CVE-2018-8373 unknown 1.5 4y ago A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
CVE-2018-0154 unknown 1.5 4y ago A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service …
CVE-2018-0151 unknown 1.5 4y ago A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition …
CVE-2018-0167 unknown 1.5 4y ago There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthentic…
CVE-2018-0161 unknown 1.5 4y ago A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to …
CVE-2018-0159 unknown 1.5 4y ago A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause…
CVE-2018-0158 unknown 1.5 4y ago A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause…
CVE-2018-0156 unknown 1.5 4y ago A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a …
CVE-2018-0155 unknown 1.5 4y ago A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated,…
CVE-2018-0179 unknown 1.5 4y ago A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial …
CVE-2018-0175 unknown 1.5 4y ago Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent atta…
CVE-2018-0174 unknown 1.5 4y ago A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
CVE-2018-0172 unknown 1.5 4y ago A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
CVE-2018-0173 unknown 1.5 4y ago A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS).
CVE-2018-8581 unknown 1.5 4y ago A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.
CVE-2018-0180 unknown 1.5 4y ago A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial …
CVE-2018-8174 unknown 1.5 4y ago A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
CVE-2018-15982 unknown 1.5 4y ago Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
CVE-2018-13382 unknown 1.5 4y ago An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
CVE-2018-13383 unknown 1.5 4y ago A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
CVE-2018-4878 unknown 1.5 5y ago Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
CVE-2018-4939 unknown 1.5 5y ago Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
CVE-2018-8653 unknown 1.5 5y ago Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.
CVE-2018-2380 unknown 1.5 5y ago SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.
CVE-2018-0802 unknown 1.5 5y ago Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. …
CVE-2018-0171 unknown 1.5 5y ago Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or p…
CVE-2018-0798 unknown 1.5 5y ago Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. …
CVE-2018-14558 unknown 1.5 5y ago Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows…
CVE-2018-1273 unknown 1.5 8y ago Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
CVE-2018-16509 unknown 1.0 An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafte…
CVE-2018-5333 unknown 1.0 In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL …
CVE-2018-18955 unknown 1.0 In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ra…
CVE-2018-10054 unknown 1.0 4y ago Improper Input Validation in Datomic
CVE-2018-11770 unknown 1.0 8y ago org.apache.spark:spark-core_2.10 and org.apache.spark:spark-core_2.11 Improper Authentication vulnerability
CVE-2018-1335 unknown 1.0 8y ago Command injection in org.apache.tika:tika-core
CVE-2018-19134 unknown In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, exe…
CVE-2018-19409 unknown An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.
CVE-2018-19476 unknown psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
CVE-2018-19477 unknown psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
CVE-2018-12565 unknown An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.
CVE-2018-1000127 unknown memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused f…
CVE-2018-1000200 unknown The Linux Kernel versions 4.14, 4.15, and 4.16 has a null pointer dereference which can result in an out of memory (OOM) killing of large mlocked processes. The issue arises from an oom killed proces…
CVE-2018-13441 unknown qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload …
CVE-2018-1000657 unknown Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and later contains a Buffer Overflow vulnerability in std::coll…
CVE-2018-1000622 unknown The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rustdoc plugins that can result in local code execution as a…
CVE-2018-5344 unknown In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release serialization, which allows attackers to cause a denial of service (__lock_acquire use-after-free) or possibly have uns…
CVE-2018-10853 unknown A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged …
CVE-2018-12563 unknown An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavas…
CVE-2018-12564 unknown An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on…