CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2016-10256

    Last Modified: 21 Nov 2024

    The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. This is a separate vulnerability from CVE-2016-10257.

    Published: 10 Jan 2018
    7.8
    High

    CVE-2018-0802

    Last Modified: 28 Oct 2025

    Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0798

    Last Modified: 28 Oct 2025

    Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".

    Published: 10 Jan 2018
    6.5
    Medium

    CVE-2018-0785

    Last Modified: 21 Nov 2024

    ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0789

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0790.

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0792

    Last Modified: 21 Nov 2024

    Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0794.

    Published: 10 Jan 2018
    7.8
    High

    CVE-2018-0793

    Last Modified: 21 Nov 2024

    Microsoft Outlook 2007, Microsoft Outlook 2010 and Microsoft Outlook 2013 allow a remote code execution vulnerability due to the way email messages are parsed, aka "Microsoft Outlook Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0791.

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0794

    Last Modified: 21 Nov 2024

    Microsoft Word in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0792.

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0795

    Last Modified: 21 Nov 2024

    Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Remote Code Execution Vulnerability".

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0796

    Last Modified: 21 Nov 2024

    Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".

    Published: 10 Jan 2018
    6.1
    Medium

    CVE-2018-0799

    Last Modified: 21 Nov 2024

    Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Microsoft Access Tampering Vulnerability".

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0801

    Last Modified: 21 Nov 2024

    Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Remote Code Execution Vulnerability".

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0805

    Last Modified: 21 Nov 2024

    Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0806, and CVE-2018-0807

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0807

    Last Modified: 21 Nov 2024

    Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0805, and CVE-2018-0806.

    Published: 10 Jan 2018
    7.8
    High

    CVE-2018-0812

    Last Modified: 21 Nov 2024

    Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Memory Corruption Vulnerability".

    Published: 10 Jan 2018
    7.5
    High

    CVE-2018-0818

    Last Modified: 21 Nov 2024

    Microsoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to run arbitrary code on a target system, due to how the Chakra scripting engine handles accessing memory, aka "Scripting Engine Security Feature Bypass".

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0790

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0789.

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0804

    Last Modified: 21 Nov 2024

    Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0806

    Last Modified: 21 Nov 2024

    Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0805, and CVE-2018-0807.

    Published: 10 Jan 2018
    6.5
    Medium

    CVE-2018-0819

    Last Modified: 21 Nov 2024

    Microsoft Office 2016 for Mac allows an attacker to send a specially crafted email attachment to a user in an attempt to launch a social engineering attack, such as phishing, due to how Outlook for Mac displays encoded email addresses, aka "Spoofing Vulnerability in Microsoft Office for Mac."

    Published: 10 Jan 2018
    8.8
    High

    CVE-2018-0784

    Last Modified: 21 Nov 2024

    ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0808.

    Published: 10 Jan 2018
    7.8
    High

    CVE-2018-0791

    Last Modified: 21 Nov 2024

    Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, and Microsoft Outlook 2016 allow a remote code execution vulnerability due to the way email messages are parsed, aka "Microsoft Outlook Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0793.

    Published: 10 Jan 2018
    7.8
    High

    CVE-2018-0797

    Last Modified: 21 Nov 2024

    Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".

    Published: 10 Jan 2018
    5.9
    Medium

    CVE-2018-1000004

    Last Modified: 21 Nov 2024

    In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound system, this can lead to a deadlock and denial of service condition.

    Published: 10 Jan 2018
    6.1
    Medium

    CVE-2018-5316

    Last Modified: 21 Nov 2024

    The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter.

    Published: 9 Jan 2018
    5.4
    Medium

    CVE-2017-1000465

    Last Modified: 21 Nov 2024

    Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of javascript code.

    Published: 9 Jan 2018
    6
    Medium

    CVE-2018-3610

    Last Modified: 21 Nov 2024

    SEMA driver in Intel Driver and Support Assistant before version 3.1.1 allows a local attacker the ability to read and writing to Memory Status registers potentially allowing information disclosure or a denial of service condition.

    Published: 9 Jan 2018
    10
    Critical

    CVE-2017-16740

    Last Modified: 21 Nov 2024

    A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.

    Published: 9 Jan 2018
    6.1
    Medium

    CVE-2017-1000429

    Last Modified: 21 Nov 2024

    rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php.

    Published: 9 Jan 2018
    8.8
    High

    CVE-2017-12695

    Last Modified: 21 Nov 2024

    An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to subvert security mechanisms and reset a user account password.

    Published: 9 Jan 2018
    5.9
    Medium

    CVE-2017-12697

    Last Modified: 21 Nov 2024

    A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to intercept sensitive information when the client connects to the server.

    Published: 9 Jan 2018
    7.5
    High

    CVE-2017-9663

    Last Modified: 21 Nov 2024

    An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow a remote attacker to access an encryption key that is stored in cleartext in memory.

    Published: 9 Jan 2018
    5.9
    Medium

    CVE-2017-1000415

    Last Modified: 21 Nov 2024

    MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.

    Published: 9 Jan 2018
    5.4
    Medium

    CVE-2017-1493

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691.

    Published: 9 Jan 2018
    7.8
    High

    CVE-2017-1612

    Last Modified: 21 Nov 2024

    IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted code under 'mqm' user. IBM X-Force ID: 132953.

    Published: 9 Jan 2018
    8.1
    High

    CVE-2017-1666

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 133540.

    Published: 9 Jan 2018
    6.1
    Medium

    CVE-2017-1668

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 133562.

    Published: 9 Jan 2018
    9.8
    Critical

    CVE-2017-1670

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 133637.

    Published: 9 Jan 2018
    7.5
    High

    CVE-2017-1671

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 133638.

    Published: 9 Jan 2018
    9.8
    Critical

    CVE-2018-5211

    Last Modified: 21 Nov 2024

    PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.

    Published: 9 Jan 2018
    8.8
    High

    CVE-2015-1290

    Last Modified: 21 Nov 2024

    The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted web site.

    Published: 9 Jan 2018
    5.5
    Medium

    CVE-2015-1208

    Last Modified: 21 Nov 2024

    Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file.

    Published: 9 Jan 2018
    8.8
    High

    CVE-2018-5221

    Last Modified: 21 Nov 2024

    Multiple buffer overflows in BarCodeWiz BarCode before 6.7 ActiveX control (BarcodeWiz.DLL) allow remote attackers to execute arbitrary code via a long argument to the (1) BottomText or (2) TopText property.

    Published: 9 Jan 2018
    7.5
    High

    CVE-2018-2360

    Last Modified: 21 Nov 2024

    SAP Startup Service, SAP KERNEL 7.45, 7.49, and 7.52, is missing an authentication check for functionalities that require user identity and cause consumption of file system storage.

    Published: 9 Jan 2018
    5.3
    Medium

    CVE-2018-2362

    Last Modified: 21 Nov 2024

    A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose information such as the platform's hostname.

    Published: 9 Jan 2018
    8.8
    High

    CVE-2018-2363

    Last Modified: 21 Nov 2024

    SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially escalate privileges by executing malicious code without legitimate credentials.

    Published: 9 Jan 2018
    8.8
    High

    CVE-2018-2361

    Last Modified: 21 Nov 2024

    In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools.

    Published: 9 Jan 2018
    7.8
    High

    CVE-2018-5308

    Last Modified: 21 Nov 2024

    PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.

    Published: 9 Jan 2018
    5.5
    Medium

    CVE-2018-5309

    Last Modified: 21 Nov 2024

    In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/PdfObjectStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.

    Published: 9 Jan 2018
    6.5
    Medium

    CVE-2018-5310

    Last Modified: 21 Nov 2024

    In the "Media from FTP" plugin before 9.85 for WordPress, Directory Traversal exists via the searchdir parameter to the wp-admin/admin.php?page=mediafromftp-search-register URI.

    Published: 9 Jan 2018