2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-8624A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8622An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window...
CVE-2018-8621An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window...
CVE-2018-8619A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly rest...
CVE-2018-8618A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8617A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8612A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain...
CVE-2018-8604A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Ex...
CVE-2018-8599An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonat...
CVE-2018-8598An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka...
CVE-2018-8597A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2018-8596An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m...
CVE-2018-8595An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m...
CVE-2018-8587A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in m...
CVE-2018-8583A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8540A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".N...
CVE-2018-8517A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framewor...
CVE-2018-8514An information disclosure vulnerability exists when Remote Procedure Call runtime improperly initializes objects in memo...
CVE-2018-8477An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window...
CVE-2018-10143The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote a...
CVE-2018-2505SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerabilit...
CVE-2018-2502TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend...
CVE-2018-2500Under certain conditions SAP Mobile Secure Android client (before version 6.60.19942.0 SP28 1711) allows an attacker to ...
CVE-2018-2497The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a state...
CVE-2018-2494Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now