2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8426 | — | — | 2.3% | Sep 13, 2018 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2018-8425 | — | — | 3.5% | Sep 13, 2018 | A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofi... |
| CVE-2018-8424 | — | — | 13.0% | Sep 13, 2018 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m... |
| CVE-2018-8422 | — | — | 6.3% | Sep 13, 2018 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m... |
| CVE-2018-8421 | — | — | 28.9% | Sep 13, 2018 | A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framewor... |
| CVE-2018-8420 | — | — | 48.9% | Sep 13, 2018 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka... |
| CVE-2018-8419 | — | — | 1.7% | Sep 13, 2018 | An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, ak... |
| CVE-2018-8410 | — | — | 4.0% | Sep 13, 2018 | An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory... |
| CVE-2018-8393 | — | — | 22.5% | Sep 13, 2018 | A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an... |
| CVE-2018-8392 | — | — | 22.8% | Sep 13, 2018 | A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an... |
| CVE-2018-8391 | — | — | 10.9% | Sep 13, 2018 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, ... |
| CVE-2018-8367 | — | — | 14.8% | Sep 13, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8366 | — | — | 5.0% | Sep 13, 2018 | An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response... |
| CVE-2018-8354 | — | — | 14.7% | Sep 13, 2018 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft... |
| CVE-2018-8337 | — | — | 1.5% | Sep 13, 2018 | A security feature bypass vulnerability exists when Windows Subsystem for Linux improperly handles case sensitivity, aka... |
| CVE-2018-8336 | — | — | 2.8% | Sep 13, 2018 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2018-8335 | — | — | 9.0% | Sep 13, 2018 | A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially cr... |
| CVE-2018-8332 | — | — | 19.1% | Sep 13, 2018 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded... |
| CVE-2018-8331 | — | — | 19.5% | Sep 13, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2018-8315 | — | — | 3.1% | Sep 13, 2018 | An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Mi... |
| CVE-2018-8271 | — | — | 2.8% | Sep 13, 2018 | An information disclosure vulnerability exists in Windows when the Windows bowser.sys kernel-mode driver fails to proper... |
| CVE-2018-8269 | — | — | 25.7% | Sep 13, 2018 | A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Servic... |
| CVE-2018-0965 | — | — | 5.1% | Sep 13, 2018 | A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from... |
| CVE-2018-16980 | — | — | 0.8% | Sep 12, 2018 | dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters. |
| CVE-2018-16979 | — | — | 3.0% | Sep 12, 2018 | Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related i... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now