6.1
    Medium

    CVE-2018-8738

    Last Modified: 6 Jul 2018

    Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.

    Source:Raif Berkay Dincel
    Published:5 Jul 2018
    8.8
    High

    CVE-2018-8736

    Last Modified: 2 Jul 2018

    A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.

    Source:Metasploit
    Published:18 Apr 2018
    8.8
    High

    CVE-2018-8735

    Last Modified: 2 Jul 2018

    Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.

    Source:Metasploit
    Published:18 Apr 2018
    9.8
    Critical

    CVE-2018-8734

    Last Modified: 2 Jul 2018

    SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.

    Source:Metasploit
    Published:18 Apr 2018
    9.8
    Critical

    CVE-2018-8733

    Last Modified: 2 Jul 2018

    Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.

    Source:Metasploit
    Published:18 Apr 2018
    5.4
    Medium

    CVE-2018-8732

    Last Modified: 2 Apr 2018

    Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter.

    Source:Vipin Chaudhary
    Published:19 Mar 2018
    6.1
    Medium

    CVE-2018-8729

    Last Modified: 3 May 2018

    Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped.

    Source:Stefan Broeder
    Published:15 Mar 2018
    5.3
    Medium

    CVE-2018-8719

    Last Modified: 30 Mar 2018

    An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.

    Source:Colette Chamberland
    Published:4 Apr 2018
    8
    High

    CVE-2018-8718

    Last Modified: 15 Jun 2018

    Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.

    Source:Kl3_GMjq6
    Published:26 Mar 2018
    5.4
    Medium

    CVE-2018-8716

    Last Modified: 24 Apr 2018

    WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.

    Source:SEC Consult
    Published:25 Apr 2018
    8.4
    High

    CVE-2018-8639

    Last Modified: 29 Oct 2025

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8641.

    Published:12 Dec 2018
    7.5
    High

    CVE-2018-8631

    Last Modified: 18 Dec 2018

    A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.

    Source:Google Security Research
    Published:12 Dec 2018
    7.5
    High

    CVE-2018-8625

    Last Modified: 20 Dec 2018

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.

    Source:Google Security Research
    Published:12 Dec 2018
    7.5
    High

    CVE-2018-8619

    Last Modified: 20 Dec 2018

    A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.

    Source:Google Security Research
    Published:12 Dec 2018
    7.5
    High

    CVE-2018-8617

    Last Modified: 18 Jan 2019

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8583, CVE-2018-8618, CVE-2018-8624, CVE-2018-8629.

    Source:Google Security Research
    Published:12 Dec 2018
    7.8
    High

    CVE-2018-8611

    Last Modified: 29 Oct 2025

    An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Published:12 Dec 2018
    7.8
    High

    CVE-2018-8587

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.

    Published:12 Dec 2018
    7.8
    High

    CVE-2018-8584

    Last Modified: 9 Jan 2019

    An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.

    Source:Google Security Research
    Published:14 Nov 2018
    7.4
    High

    CVE-2018-8581

    Last Modified: 28 Oct 2025

    An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

    Published:14 Nov 2018
    7.5
    High

    CVE-2018-8552

    Last Modified: 30 Nov 2018

    An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.

    Source:Google Security Research
    Published:14 Nov 2018
    7.8
    High

    CVE-2018-8550

    Last Modified: 20 Nov 2018

    An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Source:Google Security Research
    Published:14 Nov 2018
    8.8
    High

    CVE-2018-8544

    Last Modified: 30 Nov 2018

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Source:Google Security Research
    Published:14 Nov 2018
    5.5
    Medium

    CVE-2018-8533

    Last Modified: 25 Oct 2018

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8532.

    Source:hyp3rlinx
    Published:10 Oct 2018
    5.5
    Medium

    CVE-2018-8532

    Last Modified: 15 Oct 2018

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8533.

    Source:hyp3rlinx
    Published:10 Oct 2018
    5.5
    Medium

    CVE-2018-8527

    Last Modified: 15 Oct 2018

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8532, CVE-2018-8533.

    Source:hyp3rlinx
    Published:10 Oct 2018
    7.5
    High

    CVE-2018-8495

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

    Published:10 Oct 2018
    7.5
    High

    CVE-2018-8474

    Last Modified: 4 Dec 2018

    A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync.

    Source:nyxgeek
    Published:13 Sept 2018
    7.4
    High

    CVE-2018-8469

    Last Modified: 28 Sept 2018

    An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8463.

    Source:Google Security Research
    Published:13 Sept 2018
    4.7
    Medium

    CVE-2018-8468

    Last Modified: 28 Sept 2018

    An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Source:Google Security Research
    Published:13 Sept 2018
    7.5
    High

    CVE-2018-8467

    Last Modified: 9 Oct 2018

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8367, CVE-2018-8465, CVE-2018-8466.

    Source:Google Security Research
    Published:13 Sept 2018
    7.5
    High

    CVE-2018-8466

    Last Modified: 9 Oct 2018

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8367, CVE-2018-8465, CVE-2018-8467.

    Source:Google Security Research
    Published:13 Sept 2018
    7.4
    High

    CVE-2018-8463

    Last Modified: 28 Sept 2018

    An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8469.

    Source:Google Security Research
    Published:13 Sept 2018
    7.8
    High

    CVE-2018-8453

    Last Modified: 17 Jul 2019

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Source:Metasploit
    Published:10 Oct 2018
    3.3
    Low

    CVE-2018-8449

    Last Modified: 19 Sept 2018

    A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

    Source:Google Security Research
    Published:13 Sept 2018
    7.8
    High

    CVE-2018-8440

    Last Modified: 28 Oct 2025

    An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Published:13 Sept 2018
    8.8
    High

    CVE-2018-8420

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Published:13 Sept 2018
    8.8
    High

    CVE-2018-8414

    Last Modified: 28 Oct 2025

    A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

    Published:15 Aug 2018
    7.8
    High

    CVE-2018-8413

    Last Modified: 29 Jan 2020

    A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows Theme API Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Source:Eduardo Braun Prado
    Published:10 Oct 2018
    7.8
    High

    CVE-2018-8411

    Last Modified: 16 Oct 2018

    An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Source:Google Security Research
    Published:10 Oct 2018
    7.8
    High

    CVE-2018-8410

    Last Modified: 19 Sept 2018

    An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Source:Google Security Research
    Published:13 Sept 2018
    7.5
    High

    CVE-2018-8389

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8390.

    Published:15 Aug 2018
    7.5
    High

    CVE-2018-8384

    Last Modified: 18 Sept 2018

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8266, CVE-2018-8380, CVE-2018-8381.

    Source:Google Security Research
    Published:15 Aug 2018
    7.5
    High

    CVE-2018-8355

    Last Modified: 18 Sept 2018

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8353, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390.

    Source:Google Security Research
    Published:15 Aug 2018
    7.5
    High

    CVE-2018-8353

    Last Modified: 28 Aug 2018

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390.

    Source:Google Security Research
    Published:15 Aug 2018
    7.5
    High

    CVE-2018-8298

    Last Modified: 17 Aug 2018

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-2018-8296.

    Source:Google Security Research
    Published:11 Jul 2018
    7.5
    High

    CVE-2018-8291

    Last Modified: 17 Aug 2018

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8296, CVE-2018-8298.

    Source:Google Security Research
    Published:11 Jul 2018
    7.5
    High

    CVE-2018-8288

    Last Modified: 17 Aug 2018

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8291, CVE-2018-8296, CVE-2018-8298.

    Source:Google Security Research
    Published:11 Jul 2018
    8.1
    High

    CVE-2018-8284

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.

    Published:11 Jul 2018
    7.5
    High

    CVE-2018-8279

    Last Modified: 19 Aug 2018

    A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8125, CVE-2018-8262, CVE-2018-8274, CVE-2018-8275, CVE-2018-8301.

    Source:Google Security Research
    Published:11 Jul 2018
    7.5
    High

    CVE-2018-8269

    Last Modified: 9 Jan 2019

    A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Service Vulnerability." This affects Microsoft.Data.OData.

    Source:Gal Zror
    Published:13 Sept 2018