2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8345 | — | — | 13.6% | Aug 15, 2018 | A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file ... |
| CVE-2018-8344 | — | — | 21.8% | Aug 15, 2018 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded... |
| CVE-2018-8343 | — | — | 1.2% | Aug 15, 2018 | An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails ... |
| CVE-2018-8342 | — | — | 1.2% | Aug 15, 2018 | An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails ... |
| CVE-2018-8341 | — | — | 2.6% | Aug 15, 2018 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2018-8340 | — | — | 7.6% | Aug 15, 2018 | A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles mult... |
| CVE-2018-8339 | — | — | 1.1% | Aug 15, 2018 | An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly san... |
| CVE-2018-8316 | — | — | 13.6% | Aug 15, 2018 | A remote code execution vulnerability exists when Internet Explorer improperly validates hyperlinks before loading execu... |
| CVE-2018-8302 | — | — | 25.5% | Aug 15, 2018 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o... |
| CVE-2018-8266 | — | — | 27.1% | Aug 15, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8253 | — | — | 1.8% | Aug 15, 2018 | An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscree... |
| CVE-2018-8204 | — | — | 1.4% | Aug 15, 2018 | A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int... |
| CVE-2018-8200 | — | — | 1.4% | Aug 15, 2018 | A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int... |
| CVE-2018-15172 | — | — | 8.3% | Aug 15, 2018 | TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header. |
| CVE-2018-15156 | — | — | 10.2% | Aug 15, 2018 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a... |
| CVE-2018-15155 | — | — | 10.2% | Aug 15, 2018 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a... |
| CVE-2018-15154 | — | — | 10.2% | Aug 15, 2018 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a... |
| CVE-2018-15153 | — | — | 61.6% | Aug 15, 2018 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a... |
| CVE-2018-15151 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1... |
| CVE-2018-15150 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR be... |
| CVE-2018-15149 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/forms/eye_mag/php/Anything_simple.php from library/forms.inc in versions of Ope... |
| CVE-2018-15148 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/patient_file/encounter/search_code.php in versions of OpenEMR before 5.0.1.4 al... |
| CVE-2018-15147 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/forms_admin/forms_admin.php from library/registry.inc in versions of OpenEMR be... |
| CVE-2018-15146 | — | — | 2.4% | Aug 15, 2018 | SQL injection vulnerability in interface/de_identification_forms/find_immunization_popup.php in versions of OpenEMR befo... |
| CVE-2018-15138 | — | — | 12.9% | Aug 15, 2018 | Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now