Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2019-12986 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). CRITICAL 9.8 39.54% cvelistv5 2026-06-17
cve-2019-12985 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). CRITICAL 9.8 39.54% cvelistv5 2026-06-17
cve-2019-12780 The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication. CRITICAL 9.8 72.44% cvelistv5 2026-06-17
cve-2019-12593 IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal. HIGH 7.5 40.97% cvelistv5 2026-06-17
cve-2019-12314 Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/etc/passwd URI. CRITICAL 9.8 84.22% cvelistv5 2026-06-17
cve-2019-12276 A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40. HIGH 7.5 57.10% cvelistv5 2026-06-17
cve-2019-11581 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability CRITICAL 9.8 84.62% cvelistv5 2022-03-07
cve-2019-11580 Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability CRITICAL 9.8 95.36% cvelistv5 2021-11-03
cve-2019-11510 Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability CRITICAL 9.9 100.00% cvelistv5 2021-11-03
cve-2019-11370 Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field. MEDIUM 5.4 5.03% cvelistv5 2026-06-17
cve-2019-11248 kubernetes: /debug/pprof endpoint exposed on kubelet's healthz port MEDIUM 6.5 75.06% cvelistv5 2026-01-13
cve-2019-10758 MongoDB mongo-express Remote Code Execution Vulnerability HIGH N/A 84.73% cvelistv5 2021-12-10
cve-2019-0193 Apache Solr DataImportHandler Code Injection Vulnerability HIGH N/A 83.55% cvelistv5 2021-12-10
cve-2018-9995 TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response. CRITICAL 9.8 82.32% cvelistv5 2026-06-17
cve-2018-9205 Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. HIGH 7.5 55.08% cvelistv5 2026-06-17
cve-2018-7841 Schneider Electric U.motion Builder SQL Injection Vulnerability CRITICAL 9.8 72.67% cvelistv5 2022-04-15
cve-2018-7700 DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code. HIGH 8.8 74.12% cvelistv5 2026-06-17
cve-2018-7600 Drupal Core Remote Code Execution Vulnerability CRITICAL N/A 99.99% cvelistv5 2021-11-03
cve-2018-6961 VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability HIGH 8.1 86.25% cvelistv5 2022-03-25
cve-2018-6605 SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request. CRITICAL 9.8 57.70% cvelistv5 2026-06-17
cve-2018-6530 D-Link Multiple Routers OS Command Injection Vulnerability CRITICAL 9.8 96.68% cvelistv5 2022-09-08
cve-2018-3810 Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code. CRITICAL 9.8 91.14% cvelistv5 2026-06-17
cve-2018-3760 SUSE CVE CVE-2018-3760 HIGH 7.5 26.72% cvelistv5 2026-09-05
cve-2018-2894 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). CRITICAL 9.8 50.22% cvelistv5 2026-06-17
cve-2018-25114 osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution CRITICAL 9.3 4.15% cvelistv5 2026-06-17
cve-2018-19410 Paessler PRTG Network Monitor Local File Inclusion Vulnerability HIGH N/A 97.94% cvelistv5 2025-02-04
cve-2018-19365 CVE-2018-19365 HIGH N/A 22.29% cvelistv5
cve-2018-19276 CVE-2018-19276 CRITICAL 10.0 98.71% cvelistv5
cve-2018-17532 Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges. CRITICAL 9.8 70.66% cvelistv5 2026-06-17
cve-2018-17431 CVE-2018-17431 HIGH N/A 83.91% cvelistv5