2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8207 | — | — | 2.4% | Jun 14, 2018 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2018-8205 | — | — | 1.6% | Jun 14, 2018 | A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Servi... |
| CVE-2018-8201 | — | — | 1.8% | Jun 14, 2018 | A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int... |
| CVE-2018-8175 | — | — | 6.7% | Jun 14, 2018 | An denial of service vulnerability exists when Windows NT WEBDAV Minirdr attempts to query a WEBDAV directory, aka "WEBD... |
| CVE-2018-8169 | — | — | 1.1% | Jun 14, 2018 | An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly ha... |
| CVE-2018-8140 | — | — | 1.6% | Jun 14, 2018 | An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideratio... |
| CVE-2018-8121 | — | — | 1.4% | Jun 14, 2018 | An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Wi... |
| CVE-2018-8113 | — | — | 4.9% | Jun 14, 2018 | A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (M... |
| CVE-2018-8111 | — | — | 15.2% | Jun 14, 2018 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E... |
| CVE-2018-8110 | — | — | 15.2% | Jun 14, 2018 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E... |
| CVE-2018-1040 | — | — | 6.7% | Jun 14, 2018 | A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Window... |
| CVE-2018-1036 | — | — | 1.1% | Jun 14, 2018 | An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vuln... |
| CVE-2018-0982 | — | — | 2.6% | Jun 14, 2018 | An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows... |
| CVE-2018-0978 | — | — | 14.7% | Jun 14, 2018 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet... |
| CVE-2018-0871 | — | — | 5.7% | Jun 14, 2018 | An information disclosure vulnerability exists when Edge improperly marks files, aka "Microsoft Edge Information Disclos... |
| CVE-2018-12354 | — | — | 0.5% | Jun 13, 2018 | Knowage (formerly SpagoBI) 6.1.1 allows CSRF via every form, as demonstrated by a /knowage/restful-services/2.0/analytic... |
| CVE-2018-12353 | — | — | 0.6% | Jun 13, 2018 | Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue. |
| CVE-2018-12271 | — | — | 0.4% | Jun 13, 2018 | An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) val... |
| CVE-2018-12019 | — | — | 2.1% | Jun 13, 2018 | The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not ... |
| CVE-2018-0495 | — | — | 0.9% | Jun 13, 2018 | Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be... |
| CVE-2018-12040 | — | — | 1.3% | Jun 13, 2018 | Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attacke... |
| CVE-2018-10408 | — | — | 0.9% | Jun 13, 2018 | An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing che... |
| CVE-2018-10407 | — | — | 0.4% | Jun 13, 2018 | An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party co... |
| CVE-2018-10406 | — | — | 0.9% | Jun 13, 2018 | An issue was discovered in Yelp OSXCollector. A maliciously crafted Universal/fat binary can evade third-party code sign... |
| CVE-2018-10405 | — | — | 0.3% | Jun 13, 2018 | An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade thi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now