|
247911
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016
|
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Named Pipe File System handles objects, aka "N…
|
NVD-CWE-noinfo
|
CVE-2018-0823
|
2024-11-21 12:39 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247912
|
4.7 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_10 windows_server_2016 windows_8.1 windows_server_2008 windows_7 windows_rt_8.1
|
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Window…
|
CWE-200
Information Exposure
|
CVE-2018-0830
|
2024-11-21 12:39 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247913
|
4.7 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_10 windows_server_2016 windows_8.1 windows_server_2008 windows_7 windows_rt_8.1
|
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Window…
|
CWE-200
Information Exposure
|
CVE-2018-0829
|
2024-11-21 12:39 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247914
|
7.5 |
HIGH
Network
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_server_2016 windows_7 windows_10 windows_8.1 windows_server_2008 windows_server
|
StructuredQuery in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows S…
|
NVD-CWE-noinfo
|
CVE-2018-0825
|
2024-11-21 12:39 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247915
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016
|
NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way NTFS handles objects, aka "Windo…
|
NVD-CWE-noinfo
|
CVE-2018-0822
|
2024-11-21 12:39 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247916
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016
|
AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way constrained impersonatio…
|
CWE-269
Improper Privilege Management
|
CVE-2018-0821
|
2024-11-21 12:39 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247917
|
7.8 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_server_2016 windows_7 windows_10 windows_8.1 windows_server_2008
|
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Window…
|
NVD-CWE-noinfo
|
CVE-2018-0820
|
2024-11-21 12:39 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247918
|
4.4 |
MEDIUM
Network
|
wondercms
|
wondercms
|
WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbi…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000062
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247919
|
9.8 |
CRITICAL
Network
|
validformbuilder
|
validform_builder
|
ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-1000059
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247920
|
4.3 |
MEDIUM
Network
|
jenkins
|
credentials_binding
|
Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-1000057
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|