Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2018-0795

Published Jan 10, 2018

Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Of…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0791

Published Jan 10, 2018

Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, and Microsoft Outlook 2016 allow a remote code execution vulnerability due to the way email messages are pa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0786

Published Jan 10, 2018

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulne…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2018-0785

Published Jan 10, 2018

ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerabili…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-0784

Published Jan 10, 2018

ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Elevation Of Privilege Vulnerability". Th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0764

Published Jan 10, 2018

Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to t…

CVSS 7.5 · High

CVE-2017-1000465

Published Jan 9, 2018

Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of j…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-4871

Published Jan 9, 2018

An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the ta…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2018-3610

Published Jan 9, 2018

SEMA driver in Intel Driver and Support Assistant before version 3.1.1 allows a local attacker the ability to read and writing to Memory Status registers potentially allowing info…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9663

Published Jan 9, 2018

An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerabili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15124

Published Jan 9, 2018

VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer upda…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12697

Published Jan 9, 2018

A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker t…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12695

Published Jan 9, 2018

An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an att…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1671

Published Jan 9, 2018

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request cont…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1670

Published Jan 9, 2018

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 16,201-16,225 of 16,510 CVEsPage 649 of 661