2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0801 | — | — | 24.4% | Jan 10, 2018 | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows... |
| CVE-2018-0799 | — | — | 3.6% | Jan 10, 2018 | Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a... |
| CVE-2018-0797 | — | — | 24.8% | Jan 10, 2018 | Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due ... |
| CVE-2018-0796 | — | — | 23.3% | Jan 10, 2018 | Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows... |
| CVE-2018-0795 | — | — | 19.3% | Jan 10, 2018 | Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due ... |
| CVE-2018-0794 | — | — | 20.1% | Jan 10, 2018 | Microsoft Word in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows ... |
| CVE-2018-0793 | — | — | 20.6% | Jan 10, 2018 | Microsoft Outlook 2007, Microsoft Outlook 2010 and Microsoft Outlook 2013 allow a remote code execution vulnerability du... |
| CVE-2018-0792 | — | — | 28.3% | Jan 10, 2018 | Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are han... |
| CVE-2018-0791 | — | — | 20.6% | Jan 10, 2018 | Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, and Microsoft Outlook 2016 allow a remote code e... |
| CVE-2018-0790 | — | — | 5.3% | Jan 10, 2018 | Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an ele... |
| CVE-2018-0789 | — | — | 6.4% | Jan 10, 2018 | Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an ele... |
| CVE-2018-0786 | — | — | 3.7% | Jan 10, 2018 | Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and ... |
| CVE-2018-0785 | — | — | 3.0% | Jan 10, 2018 | ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project template... |
| CVE-2018-0784 | — | — | 6.5% | Jan 10, 2018 | ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, ... |
| CVE-2018-0764 | — | — | 8.9% | Jan 10, 2018 | Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1... |
| CVE-2018-5316 | — | — | 3.7% | Jan 9, 2018 | The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.p... |
| CVE-2018-4871 | — | — | 5.5% | Jan 9, 2018 | An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of... |
| CVE-2018-3610 | — | — | 0.3% | Jan 9, 2018 | SEMA driver in Intel Driver and Support Assistant before version 3.1.1 allows a local attacker the ability to read and w... |
| CVE-2018-5221 | — | — | 3.9% | Jan 9, 2018 | Multiple buffer overflows in BarCodeWiz BarCode before 6.7 ActiveX control (BarcodeWiz.DLL) allow remote attackers to ex... |
| CVE-2018-5211 | — | — | 1.9% | Jan 9, 2018 | PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist. |
| CVE-2018-2363 | — | — | 1.7% | Jan 9, 2018 | SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that a... |
| CVE-2018-2362 | — | — | 1.6% | Jan 9, 2018 | A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup... |
| CVE-2018-2361 | — | — | 1.2% | Jan 9, 2018 | In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user mor... |
| CVE-2018-2360 | — | — | 2.5% | Jan 9, 2018 | SAP Startup Service, SAP KERNEL 7.45, 7.49, and 7.52, is missing an authentication check for functionalities that requir... |
| CVE-2018-5312 | — | — | 0.6% | Jan 9, 2018 | The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now