2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8606 | — | — | 1.4% | Nov 14, 2018 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly saniti... |
| CVE-2018-8605 | — | — | 1.4% | Nov 14, 2018 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly saniti... |
| CVE-2018-8602 | — | — | 1.5% | Nov 14, 2018 | A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i... |
| CVE-2018-8600 | — | — | 2.0% | Nov 14, 2018 | A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user... |
| CVE-2018-8592 | — | — | 1.2% | Nov 14, 2018 | An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, ... |
| CVE-2018-8588 | — | — | 14.2% | Nov 14, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8584 | — | — | 2.7% | Nov 14, 2018 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A... |
| CVE-2018-8582 | — | — | 18.6% | Nov 14, 2018 | A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export fil... |
| CVE-2018-8579 | — | — | 6.3% | Nov 14, 2018 | An information disclosure vulnerability exists when attaching files to Outlook messages, aka "Microsoft Outlook Informat... |
| CVE-2018-8578 | — | — | 4.8% | Nov 14, 2018 | An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structur... |
| CVE-2018-8577 | — | — | 19.1% | Nov 14, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2018-8576 | — | — | 19.1% | Nov 14, 2018 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in m... |
| CVE-2018-8575 | — | — | 19.3% | Nov 14, 2018 | A remote code execution vulnerability exists in Microsoft Project software when it fails to properly handle objects in m... |
| CVE-2018-8574 | — | — | 19.1% | Nov 14, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2018-8573 | — | — | 19.1% | Nov 14, 2018 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memo... |
| CVE-2018-8572 | — | — | 1.6% | Nov 14, 2018 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c... |
| CVE-2018-8570 | — | — | 14.2% | Nov 14, 2018 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet... |
| CVE-2018-8567 | — | — | 3.1% | Nov 14, 2018 | An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, whic... |
| CVE-2018-8566 | — | — | 1.0% | Nov 14, 2018 | A security feature bypass vulnerability exists when Windows improperly suspends BitLocker Device Encryption, aka "BitLoc... |
| CVE-2018-8565 | — | — | 3.2% | Nov 14, 2018 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Wi... |
| CVE-2018-8564 | — | — | 2.7% | Nov 14, 2018 | A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofi... |
| CVE-2018-8563 | — | — | 1.7% | Nov 14, 2018 | An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Informati... |
| CVE-2018-8562 | — | — | 1.4% | Nov 14, 2018 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ... |
| CVE-2018-8561 | — | — | 1.2% | Nov 14, 2018 | An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation... |
| CVE-2018-8558 | — | — | 5.6% | Nov 14, 2018 | An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings conf... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now