← Global Threat Landscape

CVE-2018-8298

CWE-843

High

89.8

RPS

Description

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-2018-8296.

Source: NVD

Signals

CVSS
7.5
High · v3.1
EPSS
74.69%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Mar 2022
Fix commit
Fix commit known
Sources: MoreFixes, FreshFixes
Weakness
CWE-843
Published
11 Jul 2018
Last modified 28 Oct 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2018-8298

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2018-8298 · RPS 89.8 · DevSecure Intelligence