CVEs from 2018
Total
2,887
critical
critical 238
high
high 329
medium
medium 259
low
low 39
% Critical
8.2%
% with KEV
3.1%
% with exploit
9.0%
Top vendors
- intel 1,561
- schneider-electric 43
- siemens 42
- rockwellautomation 16
- echelon 15
- redhat 12
- oracle 9
- mitel 8
Top products
- core_i7 379
- core_i5 375
- core_i3 242
- xeon_e5 82
- xeon_e7 62
- xeon_e3 58
- xeon_gold 33
- atom_z 30
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-25391 | high | 7.5 | 7.5 | 6d ago | HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target rec… | |||
| CVE-2018-25374 | high | 7.5 | 7.5 | 10d ago | Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers … | |||
| CVE-2018-25368 | high | 7.5 | 7.5 | 10d ago | Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers ca… | |||
| CVE-2018-25365 | high | 7.5 | 7.5 | 10d ago | PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative path sequences in GET requests. Attackers can use pat… | |||
| CVE-2018-25358 | high | 7.5 | 7.5 | 12d ago | D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the table_name parameter in POST req… | |||
| CVE-2018-25329 | high | 7.5 | 7.5 | 18d ago | WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attack… | |||
| CVE-2018-25326 | high | 7.5 | 7.5 | 18d ago | Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parame… | |||
| CVE-2018-25325 | high | 7.5 | 7.5 | 18d ago | Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX … | |||
| CVE-2018-7794 | high | 7.5 | 7.5 | 7y ago | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) … | |||
| CVE-2018-7852 | high | 7.5 | 7.5 | 7y ago | A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when an invalid private … | |||
| CVE-2018-7821 | high | 7.5 | 7.5 | 7y ago | An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flood… | |||
| CVE-2018-16561 | high | 7.5 | 7.5 | 7y ago | A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CPUs improperly validate S7 communication packets which could cause a Denial-of-Service condition of … | |||
| CVE-2018-17958 | high | 7.5 | 7.5 | 8y ago | Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used. | |||
| CVE-2018-7792 | high | 7.5 | 7.5 | 8y ago | A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows una… | |||
| CVE-2018-7789 | high | 7.5 | 7.5 | 8y ago | An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability … | |||
| CVE-2018-12594 | high | 7.5 | 7.5 | 8y ago | Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct request for the data/fileinfo.xml or job/job.json file, as demonstrated the Master Pa… | |||
| CVE-2018-3615 | high | 7.3 | 7.3 | 8y ago | Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enc… | |||
| CVE-2018-25431 | high | 7.1 | 7.1 | 3d ago | No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attackers to manipulate database queries. Attackers can … | |||
| CVE-2018-25430 | high | 7.1 | 7.1 | 3d ago | Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the eGeqIdEquipe parameter. Attackers … | |||
| CVE-2018-25429 | high | 7.1 | 7.1 | 3d ago | Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the zProIdPro parameter. Attackers can… | |||
| CVE-2018-25410 | high | 7.1 | 7.1 | 5d ago | SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send G… | |||
| CVE-2018-25392 | high | 7.1 | 7.1 | 6d ago | MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor, user, and jenis parameters in the log_activity f… | |||
| CVE-2018-25381 | high | 7.1 | 7.1 | 10d ago | Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can injec… | |||
| CVE-2018-25380 | high | 7.1 | 7.1 | 10d ago | Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_s… | |||
| CVE-2018-25352 | high | 7.1 | 7.1 | 12d ago | WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code th… | |||
| CVE-2018-25347 | high | 7.1 | 7.1 | 12d ago | WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv_f… | |||
| CVE-2018-25346 | high | 7.1 | 7.1 | 12d ago | WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMa… | |||
| CVE-2018-25319 | high | 7.1 | 7.1 | 18d ago | Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Att… | |||
| CVE-2018-25207 | high | 7.1 | 7.1 | 2mo ago | Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POS… | |||
| CVE-2018-14634 | unknown | — | 2.5 | 4mo ago | Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escala… | |||
| CVE-2018-9276 | unknown | — | 2.5 | 1y ago | Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console. | |||
| CVE-2018-14933 | unknown | — | 2.5 | 2y ago | NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. | |||
| CVE-2018-0824 | unknown | — | 2.5 | 2y ago | Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script. | |||
| CVE-2018-5430 | unknown | — | 2.5 | 4y ago | TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. | |||
| CVE-2018-13374 | unknown | — | 2.5 | 4y ago | Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server conn… | |||
| CVE-2018-2628 | unknown | — | 2.5 | 4y ago | Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server. | |||
| CVE-2018-7445 | unknown | — | 2.5 | 4y ago | In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code e… | |||
| CVE-2018-6065 | unknown | — | 2.5 | 4y ago | Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect mult… | |||
| CVE-2018-15133 | unknown | — | 2.5 | 4y ago | Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl… | |||
| CVE-2018-8298 | unknown | — | 2.5 | 4y ago | The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution. | |||
| CVE-2018-1000861 | unknown | — | 2.5 | 4y ago | A code execution vulnerability exists in the Stapler web framework used by Jenkins | |||
| CVE-2018-7841 | unknown | — | 2.5 | 4y ago | A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered. | |||
| CVE-2018-10562 | unknown | — | 2.5 | 4y ago | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. | |||
| CVE-2018-10561 | unknown | — | 2.5 | 4y ago | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution. | |||
| CVE-2018-8440 | unknown | — | 2.5 | 4y ago | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). | |||
| CVE-2018-11138 | unknown | — | 2.5 | 4y ago | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution. | |||
| CVE-2018-6961 | unknown | — | 2.5 | 4y ago | VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution. | |||
| CVE-2018-8120 | unknown | — | 2.5 | 4y ago | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | |||
| CVE-2018-8174 | unknown | — | 2.5 | 4y ago | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" | |||
| CVE-2018-20250 | unknown | — | 2.5 | 4y ago | WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution | |||
| CVE-2018-15982 | unknown | — | 2.5 | 4y ago | Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability | |||
| CVE-2018-8453 | unknown | — | 2.5 | 4y ago | Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. | |||
| CVE-2018-13382 | unknown | — | 2.5 | 5y ago | An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. | |||
| CVE-2018-14847 | unknown | — | 2.5 | 5y ago | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability i… | |||
| CVE-2018-20062 | unknown | — | 2.5 | 5y ago | ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter. | |||
| CVE-2018-2380 | unknown | — | 2.5 | 5y ago | SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users. | |||
| CVE-2018-0296 | unknown | — | 2.5 | 5y ago | Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or inform… | |||
| CVE-2018-13379 | unknown | — | 2.5 | 5y ago | Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource request… | |||
| CVE-2018-0171 | unknown | — | 2.5 | 5y ago | Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or p… | |||
| CVE-2018-15961 | unknown | — | 2.5 | 5y ago | Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution. | |||
| CVE-2018-4878 | unknown | — | 2.5 | 5y ago | Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. | |||
| CVE-2018-15811 | unknown | — | 2.5 | 7y ago | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. | |||
| CVE-2018-18325 | unknown | — | 2.5 | 7y ago | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch f… | |||
| CVE-2018-11776 | unknown | — | 2.5 | 8y ago | Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defi… | |||
| CVE-2018-4063 | unknown | — | 1.5 | 6mo ago | Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploade… | |||
| CVE-2018-8639 | unknown | — | 1.5 | 1y ago | Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnera… | |||
| CVE-2018-19410 | unknown | — | 1.5 | 1y ago | Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator). | |||
| CVE-2018-18809 | unknown | — | 1.5 | 4y ago | TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system. | |||
| CVE-2018-19320 | unknown | — | 1.5 | 4y ago | The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complet… | |||
| CVE-2018-19323 | unknown | — | 1.5 | 4y ago | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be… | |||
| CVE-2018-19322 | unknown | — | 1.5 | 4y ago | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leve… | |||
| CVE-2018-19321 | unknown | — | 1.5 | 4y ago | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could… | |||
| CVE-2018-6530 | unknown | — | 1.5 | 4y ago | Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands. | |||
| CVE-2018-4344 | unknown | — | 1.5 | 4y ago | Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution. | |||
| CVE-2018-4990 | unknown | — | 1.5 | 4y ago | Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution. | |||
| CVE-2018-8611 | unknown | — | 1.5 | 4y ago | A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. | |||
| CVE-2018-19953 | unknown | — | 1.5 | 4y ago | A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | |||
| CVE-2018-19949 | unknown | — | 1.5 | 4y ago | A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. | |||
| CVE-2018-19943 | unknown | — | 1.5 | 4y ago | A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | |||
| CVE-2018-8589 | unknown | — | 1.5 | 4y ago | A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security contex… | |||
| CVE-2018-5002 | unknown | — | 1.5 | 4y ago | Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution. | |||
| CVE-2018-14667 | unknown | — | 1.5 | 4y ago | Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute… | |||
| CVE-2018-6882 | unknown | — | 1.5 | 4y ago | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. | |||
| CVE-2018-20753 | unknown | — | 1.5 | 4y ago | Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. | |||
| CVE-2018-8405 | unknown | — | 1.5 | 4y ago | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | |||
| CVE-2018-8406 | unknown | — | 1.5 | 4y ago | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | |||
| CVE-2018-0147 | unknown | — | 1.5 | 4y ago | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulne… | |||
| CVE-2018-14839 | unknown | — | 1.5 | 4y ago | LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability. | |||
| CVE-2018-0125 | unknown | — | 1.5 | 4y ago | A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system. | |||
| CVE-2018-8414 | unknown | — | 1.5 | 4y ago | A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths. | |||
| CVE-2018-8373 | unknown | — | 1.5 | 4y ago | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. | |||
| CVE-2018-0151 | unknown | — | 1.5 | 4y ago | A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition … | |||
| CVE-2018-0155 | unknown | — | 1.5 | 4y ago | A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated,… | |||
| CVE-2018-0156 | unknown | — | 1.5 | 4y ago | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a … | |||
| CVE-2018-0161 | unknown | — | 1.5 | 4y ago | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to … | |||
| CVE-2018-0158 | unknown | — | 1.5 | 4y ago | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause… | |||
| CVE-2018-0167 | unknown | — | 1.5 | 4y ago | There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthentic… | |||
| CVE-2018-0159 | unknown | — | 1.5 | 4y ago | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause… | |||
| CVE-2018-0174 | unknown | — | 1.5 | 4y ago | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). | |||
| CVE-2018-0175 | unknown | — | 1.5 | 4y ago | Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent atta… |