Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2018-11409 Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key. MEDIUM 5.3 98.31% cvelistv5 2026-06-17
cve-2018-11329 CVE-2018-11329 HIGH N/A 0.88% cvelistv5
cve-2018-11239 An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets by providing a _to argument in conjunction with a large _value argument, as exploited in the wild in May 2018, aka the "burnOverflow" issue. HIGH 7.5 0.93% cvelistv5 2026-06-17
cve-2018-11222 Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint. HIGH 7.5 6.53% cvelistv5 2026-06-17
cve-2018-11138 Quest KACE System Management Appliance Remote Command Execution Vulnerability CRITICAL N/A 91.78% cvelistv5 2022-03-25
cve-2018-10942 modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file. CRITICAL 9.8 12.55% cvelistv5 2026-06-17
cve-2018-10823 CVE-2018-10823 HIGH N/A 77.70% cvelistv5
cve-2018-10737 A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter. HIGH 7.2 42.05% cvelistv5 2026-06-17
cve-2018-10657 SUSE CVE CVE-2018-10657 UNKNOWN N/A 1.52% cvelistv5 2026-05-31
cve-2018-10562 Dasan GPON Routers Command Injection Vulnerability CRITICAL N/A 99.95% cvelistv5 2022-03-31
cve-2018-10561 Dasan GPON Routers Authentication Bypass Vulnerability HIGH N/A 92.89% cvelistv5 2022-03-31
cve-2018-10468 The transferFrom function of a smart contract implementation for Useless Ethereum Token (UET), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer all victims' balances into their account) because certain computations involving _value are incorrect, as exploited in the wild starting in December 2017, aka the "transferFlaw" issue. HIGH 7.5 1.57% cvelistv5 2026-06-17
cve-2018-10376 An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets via crafted _fee and _value parameters, as exploited in the wild in April 2018, aka the "proxyOverflow" issue. HIGH 7.5 1.80% cvelistv5 2026-06-17
cve-2018-10299 An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the "batchOverflow" issue. HIGH 7.5 2.67% cvelistv5 2026-06-17
cve-2018-1000861 Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability HIGH N/A 98.33% cvelistv5 2022-02-10
cve-2018-1000130 jolokia: JMX proxy mode vulnerable to remote code execution HIGH 8.1 73.98% cvelistv5 2026-05-14
cve-2018-0824 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability HIGH 7.5 73.19% cvelistv5 2024-08-05
cve-2018-0802 Microsoft Office Memory Corruption Vulnerability HIGH 7.8 93.29% cvelistv5 2021-11-03
cve-2018-0798 Microsoft Office Memory Corruption Vulnerability HIGH 8.8 95.12% cvelistv5 2021-11-03
cve-2018-0296 Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability HIGH 7.5 99.91% cvelistv5 2021-11-03
cve-2018-0180 Cisco IOS Software Denial-of-Service Vulnerability HIGH N/A 4.93% cvelistv5 2022-03-03
cve-2018-0179 Cisco IOS Software Denial-of-Service Vulnerability HIGH N/A 4.93% cvelistv5 2022-03-03
cve-2018-0175 Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability HIGH N/A 3.48% cvelistv5 2022-03-03
cve-2018-0174 Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability HIGH N/A 7.61% cvelistv5 2022-03-03
cve-2018-0173 Cisco IOS and IOS XE Software Improper Input Validation Vulnerability HIGH N/A 7.61% cvelistv5 2022-03-03
cve-2018-0172 Cisco IOS and IOS XE Software Improper Input Validation Vulnerability HIGH N/A 7.82% cvelistv5 2022-03-03
cve-2018-0171 Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability HIGH N/A 99.48% cvelistv5 2021-11-03
cve-2018-0167 Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability HIGH N/A 3.35% cvelistv5 2022-03-03
cve-2018-0161 Cisco IOS Software Resource Management Errors Vulnerability HIGH N/A 4.12% cvelistv5 2022-03-03
cve-2018-0159 Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability HIGH N/A 6.87% cvelistv5 2022-03-03