Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2018-19207 The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018. CRITICAL 9.8 88.06% cvelistv5 2026-06-17
cve-2018-18956 SUSE CVE CVE-2018-18956 UNKNOWN N/A 2.79% cvelistv5 2025-02-18
cve-2018-18852 Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018. HIGH 8.8 63.80% cvelistv5 2026-06-17
cve-2018-18809 TIBCO JasperReports Library Directory Traversal Vulnerability CRITICAL 9.9 79.06% cvelistv5 2022-12-29
cve-2018-18325 DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability HIGH 7.5 74.05% cvelistv5 2021-11-03
cve-2018-17532 Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges. CRITICAL 9.8 70.66% cvelistv5 2026-06-17
cve-2018-17480 Google Chromium V8 Out-of-Bounds Write Vulnerability HIGH N/A 35.64% cvelistv5 2022-06-08
cve-2018-17463 Google Chromium V8 Remote Code Execution Vulnerability HIGH N/A 84.56% cvelistv5 2022-06-08
cve-2018-17431 CVE-2018-17431 HIGH N/A 83.91% cvelistv5
cve-2018-17283 Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter. HIGH 7.5 66.35% cvelistv5 2026-06-17
cve-2018-17254 CVE-2018-17254 HIGH N/A 82.98% cvelistv5
cve-2018-17246 kibana: Arbitrary file inclusion vulnerability in the Console plugin MEDIUM 6.3 82.25% cvelistv5 2026-06-27
cve-2018-17173 LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. CRITICAL 9.8 56.24% cvelistv5 2026-06-17
cve-2018-16763 CVE-2018-16763 HIGH N/A 82.94% cvelistv5
cve-2018-16159 The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request. CRITICAL 9.8 49.92% cvelistv5 2026-06-17
cve-2018-16059 Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter. MEDIUM 5.3 29.82% cvelistv5 2026-06-17
cve-2018-15982 Adobe Flash Player Use-After-Free Vulnerability CRITICAL N/A 89.15% cvelistv5 2022-02-15
cve-2018-15961 Adobe ColdFusion Unrestricted File Upload Vulnerability CRITICAL 9.8 99.95% cvelistv5 2021-11-03
cve-2018-15811 DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability HIGH 7.5 74.05% cvelistv5 2021-11-03
cve-2018-15517 The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI. HIGH 8.6 44.10% cvelistv5 2026-06-17
cve-2018-15138 Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs. HIGH 7.5 12.85% cvelistv5 2026-06-17
cve-2018-15133 Laravel Deserialization of Untrusted Data Vulnerability HIGH 8.1 76.81% cvelistv5 2024-01-16
cve-2018-14933 NUUO NVRmini Devices OS Command Injection Vulnerability CRITICAL 9.8 94.88% cvelistv5 2024-12-18
cve-2018-14918 LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal. HIGH 7.5 18.61% cvelistv5 2026-06-17
cve-2018-14912 cgit: directory traversal vulnerability in cgit < 1.2.1 HIGH 7.5 92.88% cvelistv5 2026-01-13
cve-2018-14847 MikroTik Router OS Directory Traversal Vulnerability CRITICAL 9.1 96.09% cvelistv5 2021-12-01
cve-2018-14839 LG N1A1 NAS Remote Command Execution Vulnerability CRITICAL 9.8 89.35% cvelistv5 2022-03-25
cve-2018-14667 Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability HIGH N/A 74.17% cvelistv5 2023-09-28
cve-2018-14634 Linux Kernel Integer Overflow Vulnerability HIGH N/A 14.69% cvelistv5 2026-01-26
cve-2018-14558 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability HIGH N/A 8.74% cvelistv5 2021-11-03