|
cve-2018-19207
|
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018. |
CRITICAL
|
9.8
|
88.06%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-18956
|
SUSE CVE CVE-2018-18956 |
UNKNOWN
|
N/A
|
2.79%
|
cvelistv5 |
2025-02-18 |
|
cve-2018-18852
|
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018. |
HIGH
|
8.8
|
63.80%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-18809
|
TIBCO JasperReports Library Directory Traversal Vulnerability |
CRITICAL
|
9.9
|
79.06%
|
cvelistv5 |
2022-12-29 |
|
cve-2018-18325
|
DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability |
HIGH
|
7.5
|
74.05%
|
cvelistv5 |
2021-11-03 |
|
cve-2018-17532
|
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges. |
CRITICAL
|
9.8
|
70.66%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-17480
|
Google Chromium V8 Out-of-Bounds Write Vulnerability |
HIGH
|
N/A
|
35.64%
|
cvelistv5 |
2022-06-08 |
|
cve-2018-17463
|
Google Chromium V8 Remote Code Execution Vulnerability |
HIGH
|
N/A
|
84.56%
|
cvelistv5 |
2022-06-08 |
|
cve-2018-17431
|
CVE-2018-17431 |
HIGH
|
N/A
|
83.91%
|
cvelistv5 |
|
|
cve-2018-17283
|
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter. |
HIGH
|
7.5
|
66.35%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-17254
|
CVE-2018-17254 |
HIGH
|
N/A
|
82.98%
|
cvelistv5 |
|
|
cve-2018-17246
|
kibana: Arbitrary file inclusion vulnerability in the Console plugin |
MEDIUM
|
6.3
|
82.25%
|
cvelistv5 |
2026-06-27 |
|
cve-2018-17173
|
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. |
CRITICAL
|
9.8
|
56.24%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-16763
|
CVE-2018-16763 |
HIGH
|
N/A
|
82.94%
|
cvelistv5 |
|
|
cve-2018-16159
|
The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request. |
CRITICAL
|
9.8
|
49.92%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-16059
|
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter. |
MEDIUM
|
5.3
|
29.82%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-15982
|
Adobe Flash Player Use-After-Free Vulnerability |
CRITICAL
|
N/A
|
89.15%
|
cvelistv5 |
2022-02-15 |
|
cve-2018-15961
|
Adobe ColdFusion Unrestricted File Upload Vulnerability |
CRITICAL
|
9.8
|
99.95%
|
cvelistv5 |
2021-11-03 |
|
cve-2018-15811
|
DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability |
HIGH
|
7.5
|
74.05%
|
cvelistv5 |
2021-11-03 |
|
cve-2018-15517
|
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI. |
HIGH
|
8.6
|
44.10%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-15138
|
Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs. |
HIGH
|
7.5
|
12.85%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-15133
|
Laravel Deserialization of Untrusted Data Vulnerability |
HIGH
|
8.1
|
76.81%
|
cvelistv5 |
2024-01-16 |
|
cve-2018-14933
|
NUUO NVRmini Devices OS Command Injection Vulnerability |
CRITICAL
|
9.8
|
94.88%
|
cvelistv5 |
2024-12-18 |
|
cve-2018-14918
|
LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal. |
HIGH
|
7.5
|
18.61%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-14912
|
cgit: directory traversal vulnerability in cgit < 1.2.1 |
HIGH
|
7.5
|
92.88%
|
cvelistv5 |
2026-01-13 |
|
cve-2018-14847
|
MikroTik Router OS Directory Traversal Vulnerability |
CRITICAL
|
9.1
|
96.09%
|
cvelistv5 |
2021-12-01 |
|
cve-2018-14839
|
LG N1A1 NAS Remote Command Execution Vulnerability |
CRITICAL
|
9.8
|
89.35%
|
cvelistv5 |
2022-03-25 |
|
cve-2018-14667
|
Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability |
HIGH
|
N/A
|
74.17%
|
cvelistv5 |
2023-09-28 |
|
cve-2018-14634
|
Linux Kernel Integer Overflow Vulnerability |
HIGH
|
N/A
|
14.69%
|
cvelistv5 |
2026-01-26 |
|
cve-2018-14558
|
Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability |
HIGH
|
N/A
|
8.74%
|
cvelistv5 |
2021-11-03 |