2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-12418Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulne...
CVE-2018-10821MEDIUM4.8Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated user...
CVE-2018-8927MEDIUM5.4Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users t...
CVE-2018-8267A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ...
CVE-2018-8254An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c...
CVE-2018-8252An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c...
CVE-2018-8251A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media ...
CVE-2018-8249A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet...
CVE-2018-8248A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2018-8247An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properl...
CVE-2018-8246An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka...
CVE-2018-8245A remote code execution vulnerability exists when Microsoft Publisher fails to utilize features that lock down the Local...
CVE-2018-8244An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka...
CVE-2018-8243A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, ...
CVE-2018-8239An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m...
CVE-2018-8236A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E...
CVE-2018-8235A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka...
CVE-2018-8234An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft ...
CVE-2018-8233An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ...
CVE-2018-8231A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles objects in memory, a...
CVE-2018-8229A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8227A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8226A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses speci...
CVE-2018-8225A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly ha...
CVE-2018-8224An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now