2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-8207An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window...
CVE-2018-8205A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Servi...
CVE-2018-8201A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int...
CVE-2018-8175An denial of service vulnerability exists when Windows NT WEBDAV Minirdr attempts to query a WEBDAV directory, aka "WEBD...
CVE-2018-8169An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly ha...
CVE-2018-8140An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideratio...
CVE-2018-8121An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Wi...
CVE-2018-8113A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (M...
CVE-2018-8111A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E...
CVE-2018-8110A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E...
CVE-2018-1040A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Window...
CVE-2018-1036An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vuln...
CVE-2018-0982An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows...
CVE-2018-0978A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet...
CVE-2018-0871An information disclosure vulnerability exists when Edge improperly marks files, aka "Microsoft Edge Information Disclos...
CVE-2018-12354Knowage (formerly SpagoBI) 6.1.1 allows CSRF via every form, as demonstrated by a /knowage/restful-services/2.0/analytic...
CVE-2018-12353Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue.
CVE-2018-12271An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) val...
CVE-2018-12019The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not ...
CVE-2018-0495Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be...
CVE-2018-12040Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attacke...
CVE-2018-10408An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing che...
CVE-2018-10407An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party co...
CVE-2018-10406An issue was discovered in Yelp OSXCollector. A maliciously crafted Universal/fat binary can evade third-party code sign...
CVE-2018-10405An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade thi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now