|
cve-2018-7841
|
Schneider Electric U.motion Builder SQL Injection Vulnerability |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2022-04-15 |
|
cve-2018-7700
|
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code. |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2018-7602
|
drupal: Remote code execution vulnerability SA-CORE-2018-004 |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
2025-11-21 |
|
cve-2018-7600
|
drupal: Unsanitized requests allow remote attackers to execute arbitrary code |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2025-11-21 |
|
cve-2018-7445
|
MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2022-09-08 |
|
cve-2018-6961
|
VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability |
HIGH
|
8.1
|
N/A
|
cvelistv5 |
2022-03-25 |
|
cve-2018-6882
|
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability |
CRITICAL
|
N/A
|
N/A
|
cvelistv5 |
2022-04-19 |
|
cve-2018-6789
|
exim: buffer overflow in b64decode() function, possibly leading to remote code execution |
HIGH
|
8.1
|
N/A
|
cvelistv5 |
2026-01-09 |
|
cve-2018-6605
|
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request. |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2018-6530
|
D-Link Multiple Routers OS Command Injection Vulnerability |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2022-09-08 |
|
cve-2018-6065
|
Google Chromium V8 Integer Overflow Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-06-08 |
|
cve-2018-5430
|
TIBCO JasperReports Server Information Disclosure Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-12-29 |
|
cve-2018-5002
|
flash-plugin: Arbitrary Code Execution vulnerability (APSB18-19) |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
2026-06-28 |
|
cve-2018-4990
|
Adobe Acrobat and Reader Double Free Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-06-08 |
|
cve-2018-4939
|
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2021-11-03 |
|
cve-2018-4878
|
flash-plugin: use-after-free causing remote code execution (APSB18-03) |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
2026-06-28 |
|
cve-2018-4344
|
Apple Multiple Products Memory Corruption Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-06-27 |
|
cve-2018-4063
|
Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
2025-12-12 |
|
cve-2018-3810
|
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code. |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2018-3760
|
rubygem-sprockets: Path traversal in forbidden_request?() can allow remote attackers to read arbitrary files |
HIGH
|
7.5
|
N/A
|
cvelistv5 |
2026-06-28 |
|
cve-2018-2894
|
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2018-2628
|
Oracle WebLogic Server Unspecified Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-09-08 |
|
cve-2018-25126
|
CVE-2018-25126 |
CRITICAL
|
9.3
|
N/A
|
cvelistv5 |
|
|
cve-2018-25124
|
CVE-2018-25124 |
HIGH
|
8.7
|
N/A
|
cvelistv5 |
|
|
cve-2018-25120
|
CVE-2018-25120 |
CRITICAL
|
9.3
|
N/A
|
cvelistv5 |
|
|
cve-2018-25118
|
GeoVision Command Injection RCE via /PictureCatch.cgi |
CRITICAL
|
10.0
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2018-25114
|
osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution |
CRITICAL
|
9.3
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2018-2380
|
SAP Customer Relationship Management (CRM) Path Traversal Vulnerability |
MEDIUM
|
6.6
|
N/A
|
cvelistv5 |
2021-11-03 |
|
cve-2018-20841
|
HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request. |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2018-20753
|
Kaseya VSA Remote Code Execution Vulnerability |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2022-04-13 |