2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8624 | — | — | 13.1% | Dec 12, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8622 | — | — | 1.8% | Dec 12, 2018 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2018-8621 | — | — | 1.8% | Dec 12, 2018 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2018-8619 | — | — | 45.8% | Dec 12, 2018 | A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly rest... |
| CVE-2018-8618 | — | — | 10.9% | Dec 12, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8617 | — | — | 62.5% | Dec 12, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8612 | — | — | 1.4% | Dec 12, 2018 | A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain... |
| CVE-2018-8604 | — | — | 2.6% | Dec 12, 2018 | A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Ex... |
| CVE-2018-8599 | — | — | 1.0% | Dec 12, 2018 | An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonat... |
| CVE-2018-8598 | — | — | 6.2% | Dec 12, 2018 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka... |
| CVE-2018-8597 | — | — | 16.1% | Dec 12, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2018-8596 | — | — | 6.9% | Dec 12, 2018 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m... |
| CVE-2018-8595 | — | — | 6.7% | Dec 12, 2018 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m... |
| CVE-2018-8587 | — | — | 28.8% | Dec 12, 2018 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in m... |
| CVE-2018-8583 | — | — | 10.9% | Dec 12, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8540 | — | — | 22.1% | Dec 12, 2018 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".N... |
| CVE-2018-8517 | — | — | 5.8% | Dec 12, 2018 | A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framewor... |
| CVE-2018-8514 | — | — | 1.9% | Dec 12, 2018 | An information disclosure vulnerability exists when Remote Procedure Call runtime improperly initializes objects in memo... |
| CVE-2018-8477 | — | — | 1.8% | Dec 12, 2018 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2018-10143 | — | — | 24.8% | Dec 12, 2018 | The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote a... |
| CVE-2018-2505 | — | — | 1.0% | Dec 11, 2018 | SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2018-2502 | — | — | 1.3% | Dec 11, 2018 | TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend... |
| CVE-2018-2500 | — | — | 0.3% | Dec 11, 2018 | Under certain conditions SAP Mobile Secure Android client (before version 6.60.19942.0 SP28 1711) allows an attacker to ... |
| CVE-2018-2497 | — | — | 0.9% | Dec 11, 2018 | The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a state... |
| CVE-2018-2494 | — | — | 0.8% | Dec 11, 2018 | Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now