Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2018-15961 Adobe ColdFusion Unrestricted File Upload Vulnerability CRITICAL 9.8 99.95% cvelistv5 2021-11-03
cve-2018-15811 DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability HIGH N/A 76.30% cvelistv5 2021-11-03
cve-2018-15517 The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI. HIGH 8.6 44.10% cvelistv5 2026-06-17
cve-2018-15138 Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs. HIGH 7.5 12.85% cvelistv5 2026-06-17
cve-2018-15133 Laravel Deserialization of Untrusted Data Vulnerability HIGH 8.1 76.81% cvelistv5 2024-01-16
cve-2018-14933 NUUO NVRmini Devices OS Command Injection Vulnerability CRITICAL 9.8 94.88% cvelistv5 2024-12-18
cve-2018-14918 LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal. HIGH 7.5 18.61% cvelistv5 2026-06-17
cve-2018-14912 SUSE CVE CVE-2018-14912 HIGH 7.5 92.03% cvelistv5 2025-03-15
cve-2018-14847 MikroTik Router OS Directory Traversal Vulnerability CRITICAL 9.1 96.09% cvelistv5 2021-12-01
cve-2018-14839 LG N1A1 NAS Remote Command Execution Vulnerability CRITICAL 9.8 89.35% cvelistv5 2022-03-25
cve-2018-14667 Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability HIGH N/A 74.20% cvelistv5 2023-09-28
cve-2018-14634 Linux Kernel Integer Overflow Vulnerability HIGH N/A 14.69% cvelistv5 2026-01-26
cve-2018-14558 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability HIGH N/A 8.74% cvelistv5 2021-11-03
cve-2018-13383 Fortinet FortiOS and FortiProxy Out-of-bounds Write MEDIUM 4.3 33.65% cvelistv5 2022-01-10
cve-2018-13382 Fortinet FortiOS and FortiProxy Improper Authorization CRITICAL 9.1 81.69% cvelistv5 2022-01-10
cve-2018-13379 Fortinet FortiOS SSL VPN Path Traversal Vulnerability CRITICAL 9.1 100.00% cvelistv5 2021-11-03
cve-2018-13374 Fortinet FortiOS and FortiADC Improper Access Control Vulnerability MEDIUM 4.3 37.83% cvelistv5 2022-09-08
cve-2018-13350 SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter. CRITICAL 9.8 16.66% cvelistv5 2026-06-17
cve-2018-1335 tika: Command injection in tika-server can allow remote attackers to execute arbitrary commands via crafted headers HIGH 8.8 93.76% cvelistv5 2026-08-04
cve-2018-13315 Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request. CRITICAL 9.8 1.55% cvelistv5 2026-06-17
cve-2018-13307 System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable. CRITICAL 9.8 3.19% cvelistv5 2026-06-17
cve-2018-1273 VMware Tanzu Spring Data Commons Property Binder Vulnerability CRITICAL N/A 96.96% cvelistv5 2022-03-25
cve-2018-12296 Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests. HIGH 7.5 11.34% cvelistv5 2026-06-17
cve-2018-1217 Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager may not be able to connect to Dell EMC Online Support web site successfully. The remote unauthenticated attacker can also read and use the credentials to login to Dell EMC Online Support, impersonating the AVI service actions using those credentials. CRITICAL 9.8 50.87% cvelistv5 2026-06-17
cve-2018-12031 Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action. CRITICAL 9.8 19.76% cvelistv5 2026-06-17
cve-2018-11776 Apache Struts Remote Code Execution Vulnerability HIGH N/A 99.99% cvelistv5 2021-11-03
cve-2018-11759 SUSE CVE CVE-2018-11759 HIGH 7.5 90.65% cvelistv5 2026-08-27
cve-2018-11714 An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action. CRITICAL 9.8 68.05% cvelistv5 2026-06-17
cve-2018-11686 The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. CRITICAL 9.8 52.54% cvelistv5 2026-06-17
cve-2018-11511 The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI. CRITICAL 9.8 11.27% cvelistv5 2026-06-17