2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0872 | — | — | 15.9% | Mar 14, 2018 | ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot... |
| CVE-2018-0868 | — | — | 1.2% | Mar 14, 2018 | Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server... |
| CVE-2018-0817 | — | — | 1.4% | Mar 14, 2018 | The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 ... |
| CVE-2018-0816 | — | — | 1.3% | Mar 14, 2018 | The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 ... |
| CVE-2018-0815 | — | — | 1.4% | Mar 14, 2018 | The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Windows 7 SP1 allows an ... |
| CVE-2018-0814 | — | — | 1.9% | Mar 14, 2018 | The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve... |
| CVE-2018-0813 | — | — | 1.9% | Mar 14, 2018 | The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve... |
| CVE-2018-0811 | — | — | 1.9% | Mar 14, 2018 | The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve... |
| CVE-2018-0808 | — | — | 8.1% | Mar 14, 2018 | ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle ... |
| CVE-2018-0787 | — | — | 9.9% | Mar 14, 2018 | ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are create... |
| CVE-2018-5782 | — | — | 19.7% | Mar 14, 2018 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.... |
| CVE-2018-5781 | — | — | 1.8% | Mar 14, 2018 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.... |
| CVE-2018-5780 | — | — | 1.8% | Mar 14, 2018 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.... |
| CVE-2018-5779 | — | — | 2.8% | Mar 14, 2018 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.... |
| CVE-2018-7474 | — | — | 6.6% | Mar 14, 2018 | An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on... |
| CVE-2018-7279 | — | — | 2.5% | Mar 14, 2018 | A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1. |
| CVE-2018-6875 | — | — | 1.1% | Mar 14, 2018 | Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information tha... |
| CVE-2018-1000132 | — | — | 2.7% | Mar 14, 2018 | Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that ca... |
| CVE-2018-1000131 | — | — | 2.1% | Mar 14, 2018 | Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulner... |
| CVE-2018-1000130 | — | — | 73.6% | Mar 14, 2018 | A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to ... |
| CVE-2018-1000129 | — | — | 25.5% | Mar 14, 2018 | An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute ma... |
| CVE-2018-8108 | — | — | 1.1% | Mar 14, 2018 | The select component in bui through 2018-03-13 has XSS because it performs an escape operation on already-escaped text, ... |
| CVE-2018-8097 | — | — | 5.2% | Mar 14, 2018 | io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection ... |
| CVE-2018-8107 | — | — | 0.8% | Mar 14, 2018 | The JPXStream::close function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buff... |
| CVE-2018-8106 | — | — | 0.8% | Mar 14, 2018 | The JPXStream::readTilePartData function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now