CVEs from 2018
Total
3,289
critical
critical 225
high
high 266
medium
medium 224
low
low 32
% Critical
6.8%
% with KEV
2.7%
% with exploit
2.8%
Top vendors
- frappe 4
- redhat 2
- magix 1
- mybb 1
- gitbucket 1
- qemu 1
- dragonexpert 1
- kingsoftstore 1
Top products
- erpnext 4
- terminal_services_manager 1
- ultraiso 1
- dolibarr_erp\/crm 1
- gitbucket 1
- pdfunite 1
- qemu 1
- virtualization_manager 1
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2018-14042 | medium | — | 5.5 | 8y ago | Bootstrap Cross-site Scripting vulnerability | |
| CVE-2018-1999024 | medium | — | 5.5 | 8y ago | MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running within a web browser. Th… | |
| CVE-2018-3740 | medium | — | 5.5 | 8y ago | A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element. | |
| CVE-2018-25334 | medium | 5.4 | 5.4 | 11d ago | Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but… | |
| CVE-2018-25370 | medium | 5.3 | 5.3 | 3d ago | Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious H… | |
| CVE-2018-25336 | medium | 5.3 | 5.3 | 11d ago | jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HTML form… | |
| CVE-2018-25327 | medium | 5.3 | 5.3 | 11d ago | Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTM… | |
| CVE-2018-25298 | medium | 5.3 | 5.3 | 29d ago | Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attacker… | |
| CVE-2018-10626 | medium | 4.4 | 4.4 | 8y ago | Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired … | |
| CVE-2018-25363 | medium | 4.3 | 4.3 | 3d ago | Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can create hidden forms t… | |
| CVE-2018-25354 | medium | 4.3 | 4.3 | 5d ago | Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting malicious pag… | |
| CVE-2018-25343 | medium | 4.3 | 4.3 | 5d ago | Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by tricking authenticated users into submitting malicious requests. Attackers can craft H… | |
| CVE-2018-25337 | medium | 4.3 | 4.3 | 11d ago | Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML fo… | |
| CVE-2018-25321 | medium | 4.3 | 4.3 | 11d ago | TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attacker… | |
| CVE-2018-25310 | medium | 4.3 | 4.3 | 29d ago | VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cros… | |
| CVE-2018-7453 | low | — | 2.5 | — | Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml. | |
| CVE-2018-9234 | low | — | 2.5 | — | GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with acce… | |
| CVE-2018-10932 | low | — | 2.5 | — | lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the … | |
| CVE-2018-7455 | low | — | 2.5 | — | An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | |
| CVE-2018-5388 | low | — | 2.5 | — | In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket. | |
| CVE-2018-0734 | low | — | 2.5 | — | The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in Ope… | |
| CVE-2018-8956 | low | — | 2.5 | — | ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packet… | |
| CVE-2018-0502 | low | — | 2.5 | — | An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line. | |
| CVE-2018-13259 | low | — | 2.5 | — | An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one. | |
| CVE-2018-7452 | low | — | 2.5 | — | A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | |
| CVE-2018-1071 | low | — | 2.5 | — | zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service. | |
| CVE-2018-0732 | low | — | 2.5 | — | During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long pe… | |
| CVE-2018-0735 | low | — | 2.5 | — | The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in O… | |
| CVE-2018-18445 | low | — | 2.5 | — | In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min… | |
| CVE-2018-7175 | low | — | 2.5 | — | An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components. | |
| CVE-2018-20225 | low | — | 2.5 | — | arbitrary code execution in python-pip | |
| CVE-2018-12558 | low | — | 2.5 | — | The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that c… | |
| CVE-2018-6942 | low | — | 2.5 | — | An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file. | |
| CVE-2018-0737 | low | — | 2.5 | — | The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key gen… | |
| CVE-2018-7173 | low | — | 2.5 | — | A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding. | |
| CVE-2018-9055 | low | — | 2.5 | — | denial of service in jasper | |
| CVE-2018-7174 | low | — | 2.5 | — | An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams. | |
| CVE-2018-7454 | low | — | 2.5 | — | A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | |
| CVE-2018-20482 | low | — | 2.5 | — | GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c)… | |
| CVE-2018-12699 | low | — | 2.5 | 2y ago | Low: binutils security update | |
| CVE-2018-20673 | low | — | 2.5 | 5y ago | Low: gcc security and bug fix update | |
| CVE-2018-7263 | low | — | 2.5 | 6y ago | Low: GStreamer, libmad, and SDL security, bug fix, and enhancement update | |
| CVE-2018-19840 | low | — | 2.5 | 6y ago | Low: wavpack security update | |
| CVE-2018-19841 | low | — | 2.5 | 6y ago | Low: wavpack security update | |
| CVE-2018-10393 | low | — | 2.5 | 7y ago | Low: libvorbis security update | |
| CVE-2018-10392 | low | — | 2.5 | 7y ago | Low: libvorbis security update | |
| CVE-2018-18751 | low | — | 2.5 | 7y ago | Low: gettext security update | |
| CVE-2018-14634 | unknown | — | 1.5 | 4mo ago | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate … | |
| CVE-2018-4063 | unknown | — | 1.5 | 6mo ago | Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploade… | |
| CVE-2018-8639 | unknown | — | 1.5 | 1y ago | Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnera… | |
| CVE-2018-19410 | unknown | — | 1.5 | 1y ago | Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator). | |
| CVE-2018-9276 | unknown | — | 1.5 | 1y ago | Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console. | |
| CVE-2018-14933 | unknown | — | 1.5 | 2y ago | NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. | |
| CVE-2018-0824 | unknown | — | 1.5 | 2y ago | Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script. | |
| CVE-2018-5430 | unknown | — | 1.5 | 4y ago | TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. | |
| CVE-2018-18809 | unknown | — | 1.5 | 4y ago | TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system. | |
| CVE-2018-19321 | unknown | — | 1.5 | 4y ago | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could… | |
| CVE-2018-19320 | unknown | — | 1.5 | 4y ago | The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complet… | |
| CVE-2018-19323 | unknown | — | 1.5 | 4y ago | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be… | |
| CVE-2018-19322 | unknown | — | 1.5 | 4y ago | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leve… | |
| CVE-2018-13374 | unknown | — | 1.5 | 4y ago | Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server conn… | |
| CVE-2018-7445 | unknown | — | 1.5 | 4y ago | In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code e… | |
| CVE-2018-6530 | unknown | — | 1.5 | 4y ago | Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands. | |
| CVE-2018-2628 | unknown | — | 1.5 | 4y ago | Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server. | |
| CVE-2018-4344 | unknown | — | 1.5 | 4y ago | Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution. | |
| CVE-2018-4990 | unknown | — | 1.5 | 4y ago | Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution. | |
| CVE-2018-6065 | unknown | — | 1.5 | 4y ago | Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect mult… | |
| CVE-2018-8611 | unknown | — | 1.5 | 4y ago | A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. | |
| CVE-2018-19953 | unknown | — | 1.5 | 4y ago | A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | |
| CVE-2018-19943 | unknown | — | 1.5 | 4y ago | A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | |
| CVE-2018-19949 | unknown | — | 1.5 | 4y ago | A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. | |
| CVE-2018-5002 | unknown | — | 1.5 | 4y ago | Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution. | |
| CVE-2018-8589 | unknown | — | 1.5 | 4y ago | A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security contex… | |
| CVE-2018-15133 | unknown | — | 1.5 | 4y ago | Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl… | |
| CVE-2018-8298 | unknown | — | 1.5 | 4y ago | The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution. | |
| CVE-2018-14667 | unknown | — | 1.5 | 4y ago | Richfaces vulnerable to arbitrary code execution | |
| CVE-2018-1000861 | unknown | — | 1.5 | 4y ago | Deserialization of Untrusted Data in Jenkins | |
| CVE-2018-6882 | unknown | — | 1.5 | 4y ago | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. | |
| CVE-2018-7841 | unknown | — | 1.5 | 4y ago | A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered. | |
| CVE-2018-20753 | unknown | — | 1.5 | 4y ago | Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. | |
| CVE-2018-10561 | unknown | — | 1.5 | 4y ago | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution. | |
| CVE-2018-10562 | unknown | — | 1.5 | 4y ago | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. | |
| CVE-2018-8405 | unknown | — | 1.5 | 4y ago | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | |
| CVE-2018-8406 | unknown | — | 1.5 | 4y ago | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | |
| CVE-2018-8440 | unknown | — | 1.5 | 4y ago | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). | |
| CVE-2018-11138 | unknown | — | 1.5 | 4y ago | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution. | |
| CVE-2018-8414 | unknown | — | 1.5 | 4y ago | A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths. | |
| CVE-2018-6961 | unknown | — | 1.5 | 4y ago | VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution. | |
| CVE-2018-8373 | unknown | — | 1.5 | 4y ago | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. | |
| CVE-2018-14839 | unknown | — | 1.5 | 4y ago | LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability. | |
| CVE-2018-0147 | unknown | — | 1.5 | 4y ago | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulne… | |
| CVE-2018-0125 | unknown | — | 1.5 | 4y ago | A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system. | |
| CVE-2018-8120 | unknown | — | 1.5 | 4y ago | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | |
| CVE-2018-0154 | unknown | — | 1.5 | 4y ago | A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service … | |
| CVE-2018-0158 | unknown | — | 1.5 | 4y ago | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause… | |
| CVE-2018-0175 | unknown | — | 1.5 | 4y ago | Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent atta… | |
| CVE-2018-0174 | unknown | — | 1.5 | 4y ago | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). | |
| CVE-2018-0159 | unknown | — | 1.5 | 4y ago | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause… | |
| CVE-2018-0156 | unknown | — | 1.5 | 4y ago | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a … | |
| CVE-2018-8581 | unknown | — | 1.5 | 4y ago | A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. |