|
cve-2018-17246
|
SUSE CVE CVE-2018-17246 |
UNKNOWN
|
N/A
|
82.25%
|
cvelistv5 |
2025-04-25 |
|
cve-2018-17173
|
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. |
CRITICAL
|
9.8
|
56.24%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-16763
|
CVE-2018-16763 |
HIGH
|
N/A
|
82.94%
|
cvelistv5 |
|
|
cve-2018-16159
|
The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request. |
CRITICAL
|
9.8
|
49.92%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-16059
|
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter. |
MEDIUM
|
5.3
|
29.82%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-15961
|
Adobe ColdFusion Unrestricted File Upload Vulnerability |
CRITICAL
|
9.8
|
99.95%
|
cvelistv5 |
2021-11-03 |
|
cve-2018-15138
|
Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs. |
HIGH
|
7.5
|
12.85%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-14912
|
SUSE CVE CVE-2018-14912 |
HIGH
|
7.5
|
92.88%
|
cvelistv5 |
2025-03-15 |
|
cve-2018-14839
|
LG N1A1 NAS Remote Command Execution Vulnerability |
CRITICAL
|
9.8
|
89.35%
|
cvelistv5 |
2022-03-25 |
|
cve-2018-14558
|
Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability |
HIGH
|
N/A
|
8.74%
|
cvelistv5 |
2021-11-03 |
|
cve-2018-13379
|
Fortinet FortiOS SSL VPN Path Traversal Vulnerability |
CRITICAL
|
9.1
|
100.00%
|
cvelistv5 |
2021-11-03 |
|
cve-2018-1335
|
tika: Command injection in tika-server can allow remote attackers to execute arbitrary commands via crafted headers |
HIGH
|
8.8
|
93.76%
|
cvelistv5 |
2026-08-04 |
|
cve-2018-1273
|
VMware Tanzu Spring Data Commons Property Binder Vulnerability |
CRITICAL
|
N/A
|
96.96%
|
cvelistv5 |
2022-03-25 |
|
cve-2018-12296
|
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests. |
HIGH
|
7.5
|
11.34%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-1217
|
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager may not be able to connect to Dell EMC Online Support web site successfully. The remote unauthenticated attacker can also read and use the credentials to login to Dell EMC Online Support, impersonating the AVI service actions using those credentials. |
CRITICAL
|
9.8
|
50.87%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-12031
|
Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action. |
CRITICAL
|
9.8
|
19.76%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-11759
|
SUSE CVE CVE-2018-11759 |
HIGH
|
7.5
|
90.65%
|
cvelistv5 |
2026-08-27 |
|
cve-2018-11686
|
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. |
CRITICAL
|
9.8
|
52.54%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-11511
|
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI. |
CRITICAL
|
9.8
|
11.27%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-10942
|
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file. |
CRITICAL
|
9.8
|
12.55%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-10737
|
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter. |
HIGH
|
7.2
|
42.05%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-10562
|
Dasan GPON Routers Command Injection Vulnerability |
CRITICAL
|
N/A
|
99.95%
|
cvelistv5 |
2022-03-31 |
|
cve-2018-1000130
|
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server. |
HIGH
|
8.1
|
72.70%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-0296
|
Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability |
HIGH
|
7.5
|
99.91%
|
cvelistv5 |
2021-11-03 |
|
cve-2017-9841
|
PHPUnit Command Injection Vulnerability |
HIGH
|
N/A
|
100.00%
|
cvelistv5 |
2022-02-15 |
|
cve-2017-9833
|
CVE-2017-9833 |
HIGH
|
N/A
|
68.46%
|
cvelistv5 |
|
|
cve-2017-9805
|
SUSE CVE CVE-2017-9805 |
UNKNOWN
|
N/A
|
99.40%
|
cvelistv5 |
2025-10-07 |
|
cve-2017-9506
|
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF). |
MEDIUM
|
6.1
|
71.60%
|
cvelistv5 |
2026-06-17 |
|
cve-2017-7927
|
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password. |
HIGH
|
7.3
|
36.75%
|
cvelistv5 |
2026-06-17 |
|
cve-2017-7921
|
Hikvision Multiple Products Improper Authentication Vulnerability |
CRITICAL
|
9.8
|
100.00%
|
cvelistv5 |
2026-03-05 |