2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-8409HIGH7.5A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines ...
CVE-2018-8393A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an...
CVE-2018-8392A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an...
CVE-2018-8391A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, ...
CVE-2018-8367A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8366An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response...
CVE-2018-8354A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft...
CVE-2018-8337A security feature bypass vulnerability exists when Windows Subsystem for Linux improperly handles case sensitivity, aka...
CVE-2018-8336An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window...
CVE-2018-8335A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially cr...
CVE-2018-8332A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded...
CVE-2018-8331A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2018-8315An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Mi...
CVE-2018-8271An information disclosure vulnerability exists in Windows when the Windows bowser.sys kernel-mode driver fails to proper...
CVE-2018-8269A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Servic...
CVE-2018-0965A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from...
CVE-2018-16981HIGH8.8stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__o...
CVE-2018-16980dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.
CVE-2018-16979Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related i...
CVE-2018-16978Monstra CMS V3.0.4 has XSS when ones tries to register an account with a crafted password parameter to users/registratio...
CVE-2018-16977Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/Err...
CVE-2018-16976Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git r...
CVE-2018-16975An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/styles...
CVE-2018-16974An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upl...
CVE-2018-15610HIGH7.3A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arb...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now