2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0971 | — | — | 3.6% | Apr 12, 2018 | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio... |
| CVE-2018-0970 | — | — | 3.6% | Apr 12, 2018 | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio... |
| CVE-2018-0969 | — | — | 3.6% | Apr 12, 2018 | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio... |
| CVE-2018-0968 | — | — | 3.7% | Apr 12, 2018 | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio... |
| CVE-2018-0967 | — | — | 18.7% | Apr 12, 2018 | A denial of service vulnerability exists in the way that Windows SNMP Service handles malformed SNMP traps, aka "Windows... |
| CVE-2018-0966 | — | — | 2.4% | Apr 12, 2018 | A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F... |
| CVE-2018-0964 | — | — | 1.6% | Apr 12, 2018 | An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validat... |
| CVE-2018-0963 | — | — | 1.3% | Apr 12, 2018 | An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Window... |
| CVE-2018-0960 | — | — | 1.9% | Apr 12, 2018 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2018-0957 | — | — | 1.6% | Apr 12, 2018 | An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validat... |
| CVE-2018-0956 | — | — | 13.8% | Apr 12, 2018 | A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses speci... |
| CVE-2018-0950 | — | — | 9.0% | Apr 12, 2018 | An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE ... |
| CVE-2018-0920 | — | — | 21.2% | Apr 12, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2018-0892 | — | — | 5.4% | Apr 12, 2018 | An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft ... |
| CVE-2018-0890 | — | — | 4.3% | Apr 12, 2018 | A security feature bypass vulnerability exists when Active Directory incorrectly applies Network Isolation settings, aka... |
| CVE-2018-0887 | — | — | 1.9% | Apr 12, 2018 | An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, ak... |
| CVE-2018-0870 | — | — | 15.1% | Apr 12, 2018 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet... |
| CVE-2018-3888 | HIGH | 7.8 | 1.5% | Apr 11, 2018 | A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.53. A specially ... |
| CVE-2018-3887 | HIGH | 7.8 | 1.5% | Apr 11, 2018 | A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.53. A specially ... |
| CVE-2018-3886 | HIGH | 7.8 | 1.5% | Apr 11, 2018 | A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.53. A specially ... |
| CVE-2018-10054 | HIGH | 8.8 | 35.0% | Apr 11, 2018 | H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can... |
| CVE-2018-10052 | — | — | 0.6% | Apr 11, 2018 | iScripts SupportDesk v4.3 has XSS via the admin/inteligentsearchresult.php txtinteligentsearch parameter. |
| CVE-2018-10051 | — | — | 0.6% | Apr 11, 2018 | iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter. |
| CVE-2018-10050 | — | — | 1.0% | Apr 11, 2018 | iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel. |
| CVE-2018-10049 | — | — | 0.5% | Apr 11, 2018 | iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now