Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-02-15 CVE-2018-0822 Unspecified vulnerability in Microsoft Windows 10 and Windows Server 2016
NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way NTFS handles objects, aka "Windows NTFS Global Reparse Point Elevation of Privilege Vulnerability".
local
high complexity
microsoft
7.0
2018-02-15 CVE-2018-0821 Improper Privilege Management vulnerability in Microsoft Windows 10 and Windows Server 2016
AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way constrained impersonations are handled, aka "Windows AppContainer Elevation Of Privilege Vulnerability".
local
high complexity
microsoft CWE-269
7.0
2018-02-15 CVE-2018-0820 Unspecified vulnerability in Microsoft products
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Kernel Elevation Of Privilege Vulnerability".
local
low complexity
microsoft
7.8
2018-02-15 CVE-2018-0809 Unspecified vulnerability in Microsoft Windows 10 and Windows Server 2016
The Windows kernel in Windows 10, versions 1703 and 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability".
local
high complexity
microsoft
7.0
2018-02-15 CVE-2018-0756 Unspecified vulnerability in Microsoft Windows 10 and Windows Server 2016
The Windows kernel in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Kernel Elevation of Privilege Vulnerability".
local
low complexity
microsoft
7.8
2018-02-15 CVE-2018-0742 Unspecified vulnerability in Microsoft products
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Kernel Elevation of Privilege Vulnerability".
local
low complexity
microsoft
7.8
2018-02-15 CVE-2017-13273 Unspecified vulnerability in Google Android
In xt_qtaguid.c, there is a race condition due to insufficient locking.
local
high complexity
google
7.0
2018-02-14 CVE-2017-6230 OS Command Injection vulnerability in Ruckuswireless products
Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective systems.
network
low complexity
ruckuswireless CWE-78
8.8
2018-02-14 CVE-2017-6229 OS Command Injection vulnerability in Ruckuswireless products
Ruckus Networks Unleashed AP firmware releases before 200.6.10.1.x and Ruckus Networks Zone Director firmware releases 10.1.0.0.x, 9.10.2.0.x, 9.12.3.0.x, 9.13.3.0.x, 10.0.1.0.x or before contain authenticated Root Command Injection in the CLI that could allow authenticated valid users to execute privileged commands on the respective systems.
network
low complexity
ruckuswireless CWE-78
8.8
2018-02-14 CVE-2018-7034 Improper Authentication vulnerability in Trendnet products
TRENDnet TEW-751DR v1.03B03, TEW-752DRU v1.03B01, and TEW733GR v1.03B01 devices allow authentication bypass via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.
network
low complexity
trendnet CWE-287
7.5