2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8350 | — | — | 18.6% | Aug 15, 2018 | A remote code execution vulnerability exists when Microsoft Windows PDF Library improperly handles objects in memory, ak... |
| CVE-2018-8349 | — | — | 22.7% | Aug 15, 2018 | A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized ... |
| CVE-2018-8348 | — | — | 2.6% | Aug 15, 2018 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2018-8347 | — | — | 1.2% | Aug 15, 2018 | An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle par... |
| CVE-2018-8346 | — | — | 18.8% | Aug 15, 2018 | A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file ... |
| CVE-2018-8345 | — | — | 13.6% | Aug 15, 2018 | A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file ... |
| CVE-2018-8344 | — | — | 21.8% | Aug 15, 2018 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded... |
| CVE-2018-8343 | — | — | 1.2% | Aug 15, 2018 | An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails ... |
| CVE-2018-8342 | — | — | 1.2% | Aug 15, 2018 | An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails ... |
| CVE-2018-8341 | — | — | 2.6% | Aug 15, 2018 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2018-8340 | — | — | 7.6% | Aug 15, 2018 | A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles mult... |
| CVE-2018-8339 | — | — | 1.1% | Aug 15, 2018 | An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly san... |
| CVE-2018-8316 | — | — | 13.6% | Aug 15, 2018 | A remote code execution vulnerability exists when Internet Explorer improperly validates hyperlinks before loading execu... |
| CVE-2018-8302 | — | — | 25.5% | Aug 15, 2018 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o... |
| CVE-2018-8273 | CRITICAL | 9.8 | 29.2% | Aug 15, 2018 | A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected... |
| CVE-2018-8266 | — | — | 27.1% | Aug 15, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8253 | — | — | 1.8% | Aug 15, 2018 | An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscree... |
| CVE-2018-8204 | — | — | 1.4% | Aug 15, 2018 | A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int... |
| CVE-2018-8200 | — | — | 1.4% | Aug 15, 2018 | A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int... |
| CVE-2018-15172 | — | — | 8.3% | Aug 15, 2018 | TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header. |
| CVE-2018-15156 | — | — | 10.2% | Aug 15, 2018 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a... |
| CVE-2018-15155 | — | — | 10.2% | Aug 15, 2018 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a... |
| CVE-2018-15154 | — | — | 10.2% | Aug 15, 2018 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a... |
| CVE-2018-15153 | — | — | 61.6% | Aug 15, 2018 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a... |
| CVE-2018-15152 | CRITICAL | 9.1 | 25.9% | Aug 15, 2018 | Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now