CVEs from 2018

3,289 normalized CVEs published or assigned in this year.

Total
3,289
critical
critical 225
high
high 266
medium
medium 224
low
low 32
% Critical
6.8%
% with KEV
2.7%
% with exploit
2.8%

Top products

  • erpnext 4
  • terminal_services_manager 1
  • ultraiso 1
  • dolibarr_erp\/crm 1
  • gitbucket 1
  • pdfunite 1
  • qemu 1
  • virtualization_manager 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2018-14042 medium 5.5 8y ago Bootstrap Cross-site Scripting vulnerability rockylinuxdebianrubynpm+3
CVE-2018-1999024 medium 5.5 8y ago MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running within a web browser. Th… archdebiannpm
CVE-2018-3740 medium 5.5 8y ago A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element. archdebianruby
CVE-2018-25334 medium 5.4 5.4 11d ago Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but…
CVE-2018-25370 medium 5.3 5.3 3d ago Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious H…
CVE-2018-25336 medium 5.3 5.3 11d ago jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HTML form…
CVE-2018-25327 medium 5.3 5.3 11d ago Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTM…
CVE-2018-25298 medium 5.3 5.3 29d ago Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attacker…
CVE-2018-10626 medium 4.4 4.4 8y ago Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired …
CVE-2018-25363 medium 4.3 4.3 3d ago Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can create hidden forms t…
CVE-2018-25354 medium 4.3 4.3 5d ago Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting malicious pag…
CVE-2018-25343 medium 4.3 4.3 5d ago Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by tricking authenticated users into submitting malicious requests. Attackers can craft H…
CVE-2018-25337 medium 4.3 4.3 11d ago Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML fo…
CVE-2018-25321 medium 4.3 4.3 11d ago TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attacker…
CVE-2018-25310 medium 4.3 4.3 29d ago VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cros…
CVE-2018-7453 low 2.5 Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml. archsusedebian
CVE-2018-9234 low 2.5 GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with acce… archsusedebian
CVE-2018-10932 low 2.5 lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the … suserockylinuxdebian
CVE-2018-7455 low 2.5 An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. archdebian
CVE-2018-5388 low 2.5 In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket. archsusedebian
CVE-2018-0734 low 2.5 The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in Ope… archsusedebian
CVE-2018-8956 low 2.5 ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packet… archsusedebian
CVE-2018-0502 low 2.5 An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line. archsusedebian
CVE-2018-13259 low 2.5 An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one. archsusedebian
CVE-2018-7452 low 2.5 A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. archsusedebian
CVE-2018-1071 low 2.5 zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service. archsusedebian
CVE-2018-0732 low 2.5 During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long pe… archsusedebian
CVE-2018-0735 low 2.5 The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in O… archsusedebian
CVE-2018-18445 low 2.5 In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min… archsusedebian
CVE-2018-7175 low 2.5 An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components. archsusedebian
CVE-2018-20225 low 2.5 arbitrary code execution in python-pip archsuse
CVE-2018-12558 low 2.5 The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that c… archdebian
CVE-2018-6942 low 2.5 An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file. archdebian
CVE-2018-0737 low 2.5 The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key gen… archsusedebian
CVE-2018-7173 low 2.5 A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding. archsusedebian
CVE-2018-9055 low 2.5 denial of service in jasper archsuse
CVE-2018-7174 low 2.5 An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams. archsusedebian
CVE-2018-7454 low 2.5 A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. archsusedebian
CVE-2018-20482 low 2.5 GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c)… archsusedebian
CVE-2018-12699 low 2.5 2y ago Low: binutils security update debiansuserockylinux
CVE-2018-20673 low 2.5 5y ago Low: gcc security and bug fix update debiansuserockylinux
CVE-2018-7263 low 2.5 6y ago Low: GStreamer, libmad, and SDL security, bug fix, and enhancement update rockylinux
CVE-2018-19840 low 2.5 6y ago Low: wavpack security update suserockylinuxdebian
CVE-2018-19841 low 2.5 6y ago Low: wavpack security update suserockylinuxdebian
CVE-2018-10393 low 2.5 7y ago Low: libvorbis security update susedebianrockylinux
CVE-2018-10392 low 2.5 7y ago Low: libvorbis security update susedebianrockylinux
CVE-2018-18751 low 2.5 7y ago Low: gettext security update archsusedebianrockylinux
CVE-2018-14634 unknown 1.5 4mo ago An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate … susedebian
CVE-2018-4063 unknown 1.5 6mo ago Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploade…
CVE-2018-8639 unknown 1.5 1y ago Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnera…
CVE-2018-19410 unknown 1.5 1y ago Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).
CVE-2018-9276 unknown 1.5 1y ago Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console.
CVE-2018-14933 unknown 1.5 2y ago NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
CVE-2018-0824 unknown 1.5 2y ago Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.
CVE-2018-5430 unknown 1.5 4y ago TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files.
CVE-2018-18809 unknown 1.5 4y ago TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.
CVE-2018-19321 unknown 1.5 4y ago The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could…
CVE-2018-19320 unknown 1.5 4y ago The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complet…
CVE-2018-19323 unknown 1.5 4y ago The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be…
CVE-2018-19322 unknown 1.5 4y ago The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leve…
CVE-2018-13374 unknown 1.5 4y ago Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server conn…
CVE-2018-7445 unknown 1.5 4y ago In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code e…
CVE-2018-6530 unknown 1.5 4y ago Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.
CVE-2018-2628 unknown 1.5 4y ago Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.
CVE-2018-4344 unknown 1.5 4y ago Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution.
CVE-2018-4990 unknown 1.5 4y ago Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
CVE-2018-6065 unknown 1.5 4y ago Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect mult…
CVE-2018-8611 unknown 1.5 4y ago A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.
CVE-2018-19953 unknown 1.5 4y ago A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
CVE-2018-19943 unknown 1.5 4y ago A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
CVE-2018-19949 unknown 1.5 4y ago A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
CVE-2018-5002 unknown 1.5 4y ago Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
CVE-2018-8589 unknown 1.5 4y ago A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security contex…
CVE-2018-15133 unknown 1.5 4y ago Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl… debianphp
CVE-2018-8298 unknown 1.5 4y ago The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution. nuget
CVE-2018-14667 unknown 1.5 4y ago Richfaces vulnerable to arbitrary code execution java
CVE-2018-1000861 unknown 1.5 4y ago Deserialization of Untrusted Data in Jenkins java
CVE-2018-6882 unknown 1.5 4y ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
CVE-2018-7841 unknown 1.5 4y ago A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
CVE-2018-20753 unknown 1.5 4y ago Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
CVE-2018-10561 unknown 1.5 4y ago Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
CVE-2018-10562 unknown 1.5 4y ago Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
CVE-2018-8405 unknown 1.5 4y ago An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
CVE-2018-8406 unknown 1.5 4y ago An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
CVE-2018-8440 unknown 1.5 4y ago An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
CVE-2018-11138 unknown 1.5 4y ago The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
CVE-2018-8414 unknown 1.5 4y ago A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
CVE-2018-6961 unknown 1.5 4y ago VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.
CVE-2018-8373 unknown 1.5 4y ago A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
CVE-2018-14839 unknown 1.5 4y ago LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.
CVE-2018-0147 unknown 1.5 4y ago A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulne…
CVE-2018-0125 unknown 1.5 4y ago A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
CVE-2018-8120 unknown 1.5 4y ago A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
CVE-2018-0154 unknown 1.5 4y ago A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service …
CVE-2018-0158 unknown 1.5 4y ago A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause…
CVE-2018-0175 unknown 1.5 4y ago Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent atta…
CVE-2018-0174 unknown 1.5 4y ago A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
CVE-2018-0159 unknown 1.5 4y ago A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause…
CVE-2018-0156 unknown 1.5 4y ago A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a …
CVE-2018-8581 unknown 1.5 4y ago A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.