2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18209XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter.
CVE-2018-18208Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI.
CVE-2018-18207Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.
CVE-2018-17919All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumente...
CVE-2018-17917All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses ...
CVE-2018-17915All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. Th...
CVE-2018-15311When F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.5.1-11.5.6 is processing specially crafted TCP t...
CVE-2018-12131Permissions in the driver pack installers for Intel NVMe before version 4.0.0.1007 and Intel RSTe before version 4.7.0.2...
CVE-2018-8533An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious X...
CVE-2018-8532An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious...
CVE-2018-8531A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesse...
CVE-2018-8530A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka...
CVE-2018-8527An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious...
CVE-2018-8518An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c...
CVE-2018-8513A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8512A security feature bypass vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to pr...
CVE-2018-8511A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8510A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8509A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E...
CVE-2018-8506An Information Disclosure vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memor...
CVE-2018-8505A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8504A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objec...
CVE-2018-8503A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8502A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2018-8501A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now