Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2018-7841 Schneider Electric U.motion Builder SQL Injection Vulnerability CRITICAL 9.8 N/A cvelistv5 2022-04-15
cve-2018-7700 DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code. HIGH 8.8 N/A cvelistv5 2026-06-17
cve-2018-7602 drupal: Remote code execution vulnerability SA-CORE-2018-004 HIGH 8.8 N/A cvelistv5 2025-11-21
cve-2018-7600 drupal: Unsanitized requests allow remote attackers to execute arbitrary code CRITICAL 9.8 N/A cvelistv5 2025-11-21
cve-2018-7445 MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability CRITICAL 9.8 N/A cvelistv5 2022-09-08
cve-2018-6961 VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability HIGH 8.1 N/A cvelistv5 2022-03-25
cve-2018-6882 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability CRITICAL N/A N/A cvelistv5 2022-04-19
cve-2018-6789 exim: buffer overflow in b64decode() function, possibly leading to remote code execution HIGH 8.1 N/A cvelistv5 2026-01-09
cve-2018-6605 SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request. CRITICAL 9.8 N/A cvelistv5 2026-06-17
cve-2018-6530 D-Link Multiple Routers OS Command Injection Vulnerability CRITICAL 9.8 N/A cvelistv5 2022-09-08
cve-2018-6065 Google Chromium V8 Integer Overflow Vulnerability HIGH N/A N/A cvelistv5 2022-06-08
cve-2018-5430 TIBCO JasperReports Server Information Disclosure Vulnerability HIGH N/A N/A cvelistv5 2022-12-29
cve-2018-5002 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-19) HIGH 8.8 N/A cvelistv5 2026-06-28
cve-2018-4990 Adobe Acrobat and Reader Double Free Vulnerability HIGH N/A N/A cvelistv5 2022-06-08
cve-2018-4939 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability HIGH N/A N/A cvelistv5 2021-11-03
cve-2018-4878 flash-plugin: use-after-free causing remote code execution (APSB18-03) HIGH 8.8 N/A cvelistv5 2026-06-28
cve-2018-4344 Apple Multiple Products Memory Corruption Vulnerability HIGH N/A N/A cvelistv5 2022-06-27
cve-2018-4063 Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability HIGH 8.8 N/A cvelistv5 2025-12-12
cve-2018-3810 Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code. CRITICAL 9.8 N/A cvelistv5 2026-06-17
cve-2018-3760 rubygem-sprockets: Path traversal in forbidden_request?() can allow remote attackers to read arbitrary files HIGH 7.5 N/A cvelistv5 2026-06-28
cve-2018-2894 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). CRITICAL 9.8 N/A cvelistv5 2026-06-17
cve-2018-2628 Oracle WebLogic Server Unspecified Vulnerability HIGH N/A N/A cvelistv5 2022-09-08
cve-2018-25126 CVE-2018-25126 CRITICAL 9.3 N/A cvelistv5
cve-2018-25124 CVE-2018-25124 HIGH 8.7 N/A cvelistv5
cve-2018-25120 CVE-2018-25120 CRITICAL 9.3 N/A cvelistv5
cve-2018-25118 GeoVision Command Injection RCE via /PictureCatch.cgi CRITICAL 10.0 N/A cvelistv5 2026-06-17
cve-2018-25114 osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution CRITICAL 9.3 N/A cvelistv5 2026-06-17
cve-2018-2380 SAP Customer Relationship Management (CRM) Path Traversal Vulnerability MEDIUM 6.6 N/A cvelistv5 2021-11-03
cve-2018-20841 HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request. CRITICAL 9.8 N/A cvelistv5 2026-06-17
cve-2018-20753 Kaseya VSA Remote Code Execution Vulnerability CRITICAL 9.8 N/A cvelistv5 2022-04-13