2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-8345A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file ...
CVE-2018-8344A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded...
CVE-2018-8343An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails ...
CVE-2018-8342An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails ...
CVE-2018-8341An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window...
CVE-2018-8340A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles mult...
CVE-2018-8339An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly san...
CVE-2018-8316A remote code execution vulnerability exists when Internet Explorer improperly validates hyperlinks before loading execu...
CVE-2018-8302A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o...
CVE-2018-8266A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8253An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscree...
CVE-2018-8204A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int...
CVE-2018-8200A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int...
CVE-2018-15172TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
CVE-2018-15156OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a...
CVE-2018-15155OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a...
CVE-2018-15154OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a...
CVE-2018-15153OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a...
CVE-2018-15151SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1...
CVE-2018-15150SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR be...
CVE-2018-15149SQL injection vulnerability in interface/forms/eye_mag/php/Anything_simple.php from library/forms.inc in versions of Ope...
CVE-2018-15148SQL injection vulnerability in interface/patient_file/encounter/search_code.php in versions of OpenEMR before 5.0.1.4 al...
CVE-2018-15147SQL injection vulnerability in interface/forms_admin/forms_admin.php from library/registry.inc in versions of OpenEMR be...
CVE-2018-15146SQL injection vulnerability in interface/de_identification_forms/find_immunization_popup.php in versions of OpenEMR befo...
CVE-2018-15138Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now