2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17472 | — | — | 1.5% | Nov 14, 2018 | Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remo... |
| CVE-2018-17471 | — | — | 1.4% | Nov 14, 2018 | Incorrect dialog placement in WebContents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obscure th... |
| CVE-2018-17469 | — | — | 1.4% | Nov 14, 2018 | Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to pe... |
| CVE-2018-17468 | — | — | 1.4% | Nov 14, 2018 | Incorrect handling of timer information during navigation in Blink in Google Chrome prior to 70.0.3538.67 allowed a remo... |
| CVE-2018-17467 | — | — | 1.4% | Nov 14, 2018 | Insufficiently quick clearing of stale rendered content in Navigation in Google Chrome prior to 70.0.3538.67 allowed a r... |
| CVE-2018-17466 | — | — | 2.7% | Nov 14, 2018 | Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out o... |
| CVE-2018-17465 | — | — | 1.6% | Nov 14, 2018 | Incorrect implementation of object trimming in V8 in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to po... |
| CVE-2018-17464 | — | — | 1.3% | Nov 14, 2018 | Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to s... |
| CVE-2018-17462 | — | — | 1.5% | Nov 14, 2018 | Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform a sandbox ... |
| CVE-2018-3699 | — | — | 0.8% | Nov 14, 2018 | Cross-site scripting in the Intel RAID Web Console v3 for Windows may allow an unauthenticated user to elevate privilege... |
| CVE-2018-3698 | — | — | 0.3% | Nov 14, 2018 | Improper file permissions in the installer for the Intel Ready Mode Technology may allow an unprivileged user to potenti... |
| CVE-2018-3697 | — | — | 0.3% | Nov 14, 2018 | Improper directory permissions in the installer for the Intel Media Server Studio may allow unprivileged users to potent... |
| CVE-2018-3696 | — | — | 0.4% | Nov 14, 2018 | Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivileged user to potenti... |
| CVE-2018-3621 | — | — | 0.5% | Nov 14, 2018 | Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an unauthenticated user t... |
| CVE-2018-12174 | — | — | 0.4% | Nov 14, 2018 | Heap overflow in Intel Trace Analyzer 2018 in Intel Parallel Studio XE 2018 Update 3 may allow an authenticated user to ... |
| CVE-2018-19271 | — | — | 2.1% | Nov 14, 2018 | Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH paramet... |
| CVE-2018-19270 | — | — | — | Nov 14, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-16276. Reason: This candidate is a reservation... |
| CVE-2018-19190 | — | — | 0.8% | Nov 14, 2018 | The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter. |
| CVE-2018-19189 | — | — | 0.9% | Nov 14, 2018 | The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or val... |
| CVE-2018-19188 | — | — | 1.5% | Nov 14, 2018 | The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter. |
| CVE-2018-19187 | — | — | 0.9% | Nov 14, 2018 | The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or val... |
| CVE-2018-19186 | — | — | 0.7% | Nov 14, 2018 | The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the route.php paymentMethod parame... |
| CVE-2018-8609 | — | — | 8.7% | Nov 14, 2018 | A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to ... |
| CVE-2018-8608 | — | — | 1.4% | Nov 14, 2018 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly saniti... |
| CVE-2018-8607 | — | — | 1.4% | Nov 14, 2018 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly saniti... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now