Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2017-1668

Published Jan 9, 2018

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a spec…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1666

Published Jan 9, 2018

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vul…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1612

Published Jan 9, 2018

IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted code under 'mqm' user. IBM X-Force ID: 132953.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1493

Published Jan 9, 2018

IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 12869…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000415

Published Jan 9, 2018

MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning)…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5221

Published Jan 9, 2018

Multiple buffer overflows in BarCodeWiz BarCode before 6.7 ActiveX control (BarcodeWiz.DLL) allow remote attackers to execute arbitrary code via a long argument to the (1) BottomT…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5211

Published Jan 9, 2018

PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1290

Published Jan 9, 2018

The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption)…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1208

Published Jan 9, 2018

Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memor…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-2362

Published Jan 9, 2018

A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose information such as the platform's ho…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-2361

Published Jan 9, 2018

In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-2360

Published Jan 9, 2018

SAP Startup Service, SAP KERNEL 7.45, 7.49, and 7.52, is missing an authentication check for functionalities that require user identity and cause consumption of file system storag…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-5311

Published Jan 9, 2018

The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the tonjoo_ecae_options[custom_css] parameter to the wp-admin/admin.php?page=tonjoo_excerpt URI.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5310

Published Jan 9, 2018

In the "Media from FTP" plugin before 9.85 for WordPress, Directory Traversal exists via the searchdir parameter to the wp-admin/admin.php?page=mediafromftp-search-register URI.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5309

Published Jan 9, 2018

In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/PdfObjectStreamParserObject.cpp). Remote attackers could lev…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5308

Published Jan 9, 2018

PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote attackers could leverage this vulnerabilit…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18025

Published Jan 9, 2018

cgi-bin/drknow.cgi in Innotube ITGuard-Manager 0.0.0.1 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the username field, as demonstrated by…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3353

Published Jan 9, 2018

The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including loc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5263

Published Jan 8, 2018

The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5301

Published Jan 8, 2018

Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7998

Published Jan 8, 2018

Multiple cross-site scripting (XSS) vulnerabilities in Gespage before 7.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) printer name when adding a pr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7997

Published Jan 8, 2018

Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter to webapp/users/prnow.jsp or…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 16,226-16,250 of 16,510 CVEsPage 650 of 661