Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2017-7559

Published Jan 10, 2018

In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters ar…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12169

Published Jan 10, 2018

It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potentia…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6810

Published Jan 10, 2018

In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5331

Published Jan 10, 2018

Discuz! DiscuzX X3.4 has XSS via the view parameter to include/space/space_poll.php, as demonstrated by a mod=space do=poll request to home.php.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18026

Published Jan 10, 2018

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to exe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9796

Published Jan 10, 2018

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a reg…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9795

Published Jan 10, 2018

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12622

Published Jan 10, 2018

When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obt…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000428

Published Jan 10, 2018

flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifyin…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10256

Published Jan 10, 2018

The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a craft…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0819

Published Jan 10, 2018

Microsoft Office 2016 for Mac allows an attacker to send a specially crafted email attachment to a user in an attempt to launch a social engineering attack, such as phishing, due…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-0818

Published Jan 10, 2018

Microsoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to run arbitrary code on a target system, due to how the Chakr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0799

Published Jan 10, 2018

Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way im…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0797

Published Jan 10, 2018

Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memo…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Showing 16,176-16,200 of 16,510 CVEsPage 648 of 661