CVEs from 2018

3,126 normalized CVEs published or assigned in this year.

Total
3,126
critical
critical 232
high
high 319
medium
medium 258
low
low 39
% Critical
7.4%
% with KEV
2.8%
% with exploit
8.3%

Top products

  • core_i7 379
  • core_i5 375
  • core_i3 242
  • xeon_e5 82
  • xeon_e7 62
  • xeon_e3 58
  • xeon_gold 33
  • atom_z 30
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2018-16228 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14462 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14465 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14464 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-16451 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14467 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-16230 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14461 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-10103 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-16452 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-16300 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-10105 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-16229 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-20843 medium 5.5 6y ago RHSA-2020:4846: mingw-expat security update (Moderate)
CVE-2018-17189 medium 5.5 6y ago RHSA-2020:4751: httpd:2.4 security, bug fix, and enhancement update (Moderate)
CVE-2018-11782 medium 5.5 6y ago RHSA-2020:4712: subversion:1.10 security update (Moderate)
CVE-2018-21035 medium 5.5 6y ago RHSA-2020:4690: qt5-qtbase and qt5-qtwebsockets security and bug fix update (Moderate)
CVE-2018-14553 medium 5.5 6y ago RHSA-2020:4659: gd security update (Moderate)
CVE-2018-1000858 medium 5.5 6y ago RHSA-2020:4490: gnupg2 security, bug fix, and enhancement update (Moderate)
CVE-2018-20337 medium 5.5 6y ago RHSA-2020:1766: GNOME security, bug fix, and enhancement update (Moderate)
CVE-2018-11577 medium 5.5 6y ago RHSA-2020:1708: liblouis security and bug fix update (Moderate)
CVE-2018-12085 medium 5.5 6y ago RHSA-2020:1708: liblouis security and bug fix update (Moderate)
CVE-2018-11685 medium 5.5 6y ago RHSA-2020:1708: liblouis security and bug fix update (Moderate)
CVE-2018-11684 medium 5.5 6y ago RHSA-2020:1708: liblouis security and bug fix update (Moderate)
CVE-2018-19869 medium 5.5 6y ago RHSA-2020:1665: qt5 security, bug fix, and enhancement update (Moderate)
CVE-2018-19872 medium 5.5 6y ago RHSA-2020:1665: qt5 security, bug fix, and enhancement update (Moderate)
CVE-2018-19871 medium 5.5 6y ago RHSA-2020:1665: qt5 security, bug fix, and enhancement update (Moderate)
CVE-2018-13139 medium 5.5 6y ago RHSA-2020:1636: libsndfile security update (Moderate)
CVE-2018-19662 medium 5.5 6y ago RHSA-2020:1636: libsndfile security update (Moderate)
CVE-2018-20783 medium 5.5 6y ago RHSA-2020:1624: php:7.2 security, bug fix, and enhancement update (Moderate)
CVE-2018-20852 medium 5.5 6y ago RHSA-2020:1764: python3 security and bug fix update (Moderate)
CVE-2018-9306 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-9305 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-17282 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-18915 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-19107 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-19108 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-19535 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-19607 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-17581 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-9303 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-9304 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-4868 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-17230 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-17229 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-14338 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-11037 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-10772 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-15587 medium 5.5 6y ago RHSA-2020:1600: evolution security and bug fix update (Moderate)
CVE-2018-9251 medium 5.5 6y ago RHSA-2020:1827: libxml2 security update (Moderate)
CVE-2018-14498 medium 5.5 7y ago RHSA-2019:3705: libjpeg-turbo security update (Moderate)
CVE-2018-1000877 medium 5.5 7y ago RHSA-2019:3698: libarchive security and bug fix update (Moderate)
CVE-2018-1000878 medium 5.5 7y ago RHSA-2019:3698: libarchive security and bug fix update (Moderate)
CVE-2018-20534 medium 5.5 7y ago RHSA-2019:3583: yum security, bug fix, and enhancement update (Moderate)
CVE-2018-16890 medium 5.5 7y ago RHSA-2019:3701: curl security and bug fix update (Moderate)
CVE-2018-12900 medium 5.5 7y ago RHSA-2019:3419: libtiff security update (Moderate)
CVE-2018-12121 medium 5.5 7y ago RHSA-2019:3497: http-parser security and bug fix update (Moderate)
CVE-2018-19873 medium 5.5 7y ago RHSA-2019:3390: qt5-qtbase security and bug fix update (Moderate)
CVE-2018-12181 medium 5.5 7y ago RHSA-2019:3338: edk2 security, bug fix, and enhancement update (Moderate)
CVE-2018-19870 medium 5.5 7y ago RHSA-2019:3390: qt5-qtbase security and bug fix update (Moderate)
CVE-2018-15518 medium 5.5 7y ago RHSA-2019:3390: qt5-qtbase security and bug fix update (Moderate)
CVE-2018-20483 medium 5.5 7y ago RHSA-2019:3701: curl security and bug fix update (Moderate)
CVE-2018-20685 medium 5.5 7y ago RHSA-2019:3702: openssh security, bug fix, and enhancement update (Moderate)
CVE-2018-20481 medium 5.5 7y ago RHSA-2019:2713: poppler security update (Moderate)
CVE-2018-18897 medium 5.5 7y ago RHSA-2019:2713: poppler security update (Moderate)
CVE-2018-20662 medium 5.5 7y ago RHSA-2019:2713: poppler security update (Moderate)
CVE-2018-20551 medium 5.5 7y ago RHSA-2019:2713: poppler security update (Moderate)
CVE-2018-20650 medium 5.5 7y ago RHSA-2019:2713: poppler security update (Moderate)
CVE-2018-18508 medium 5.5 7y ago In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.
CVE-2018-19800 medium 5.5 7y ago aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo.
CVE-2018-19802 medium 5.5 7y ago aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.
CVE-2018-19801 medium 5.5 7y ago aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters.
CVE-2018-20676 medium 5.5 8y ago RHSA-2020:4670: idm:DL1 and idm:client security, bug fix, and enhancement update (Moderate)
CVE-2018-20677 medium 5.5 8y ago RHSA-2020:4670: idm:DL1 and idm:client security, bug fix, and enhancement update (Moderate)
CVE-2018-7536 medium 5.5 8y ago An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastroph…
CVE-2018-7537 medium 5.5 8y ago An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they w…
CVE-2018-20060 medium 5.5 8y ago RHSA-2020:1916: python-pip security update (Moderate)
CVE-2018-20096 medium 5.5 8y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-20098 medium 5.5 8y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-20097 medium 5.5 8y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-20099 medium 5.5 8y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-19352 medium 5.5 8y ago Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
CVE-2018-19351 medium 5.5 8y ago Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can e…
CVE-2018-18074 medium 5.5 8y ago RHSA-2020:1916: python-pip security update (Moderate)
CVE-2018-3750 medium 5.5 8y ago RHSA-2021:0549: nodejs:12 security update (Moderate)
CVE-2018-14574 medium 5.5 8y ago django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
CVE-2018-14404 medium 5.5 8y ago RHSA-2020:1827: libxml2 security update (Moderate)
CVE-2018-6188 medium 5.5 8y ago django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from th…
CVE-2018-16984 medium 5.5 8y ago An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display a…
CVE-2018-1000559 medium 5.5 8y ago qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via…
CVE-2018-14042 medium 5.5 8y ago RHSA-2020:4847: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (Moderate)
CVE-2018-1999024 medium 5.5 8y ago MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running within a web browser. Th…
CVE-2018-3740 medium 5.5 8y ago A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.
CVE-2018-25384 medium 5.4 5.4 1d ago Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted HTML in the reply_text parameter. Attackers can pos…
CVE-2018-25334 medium 5.4 5.4 13d ago Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but…
CVE-2018-7795 medium 5.4 5.4 8y ago A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting …
CVE-2018-25397 medium 5.3 5.3 1d ago PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated …
CVE-2018-25387 medium 5.3 5.3 1d ago HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft…
CVE-2018-25370 medium 5.3 5.3 5d ago Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious H…
CVE-2018-25336 medium 5.3 5.3 13d ago jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HTML form…