|
cve-2018-14013
|
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients. |
MEDIUM
|
6.1
|
7.44%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-13383
|
Fortinet FortiOS and FortiProxy Out-of-bounds Write |
MEDIUM
|
4.3
|
33.65%
|
cvelistv5 |
2022-01-10 |
|
cve-2018-13382
|
Fortinet FortiOS and FortiProxy Improper Authorization |
CRITICAL
|
9.1
|
81.69%
|
cvelistv5 |
2022-01-10 |
|
cve-2018-13379
|
Fortinet FortiOS SSL VPN Path Traversal Vulnerability |
CRITICAL
|
9.1
|
100.00%
|
cvelistv5 |
2021-11-03 |
|
cve-2018-13374
|
Fortinet FortiOS and FortiADC Improper Access Control Vulnerability |
MEDIUM
|
4.3
|
37.83%
|
cvelistv5 |
2022-09-08 |
|
cve-2018-13350
|
SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter. |
CRITICAL
|
9.8
|
16.66%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-1335
|
tika: Command injection in tika-server can allow remote attackers to execute arbitrary commands via crafted headers |
HIGH
|
8.8
|
93.76%
|
cvelistv5 |
2026-08-04 |
|
cve-2018-13315
|
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request. |
CRITICAL
|
9.8
|
1.55%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-13307
|
System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable. |
CRITICAL
|
9.8
|
3.19%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-1273
|
VMware Tanzu Spring Data Commons Property Binder Vulnerability |
CRITICAL
|
N/A
|
96.96%
|
cvelistv5 |
2022-03-25 |
|
cve-2018-12296
|
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests. |
HIGH
|
7.5
|
11.34%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-1217
|
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager may not be able to connect to Dell EMC Online Support web site successfully. The remote unauthenticated attacker can also read and use the credentials to login to Dell EMC Online Support, impersonating the AVI service actions using those credentials. |
CRITICAL
|
9.8
|
50.87%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-12031
|
Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action. |
CRITICAL
|
9.8
|
19.76%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-11776
|
Apache Struts Remote Code Execution Vulnerability |
HIGH
|
N/A
|
99.99%
|
cvelistv5 |
2021-11-03 |
|
cve-2018-11759
|
mod_jk: connector path traversal due to mishandled HTTP requests in httpd |
HIGH
|
7.5
|
90.65%
|
cvelistv5 |
2026-06-28 |
|
cve-2018-11714
|
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action. |
CRITICAL
|
9.8
|
68.05%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-11686
|
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. |
CRITICAL
|
9.8
|
52.54%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-11511
|
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI. |
CRITICAL
|
9.8
|
11.27%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-11409
|
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key. |
MEDIUM
|
5.3
|
98.31%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-11329
|
CVE-2018-11329 |
HIGH
|
N/A
|
0.88%
|
cvelistv5 |
|
|
cve-2018-11239
|
An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets by providing a _to argument in conjunction with a large _value argument, as exploited in the wild in May 2018, aka the "burnOverflow" issue. |
HIGH
|
7.5
|
0.93%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-11222
|
Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint. |
HIGH
|
7.5
|
6.53%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-11138
|
Quest KACE System Management Appliance Remote Command Execution Vulnerability |
CRITICAL
|
N/A
|
91.78%
|
cvelistv5 |
2022-03-25 |
|
cve-2018-10942
|
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file. |
CRITICAL
|
9.8
|
12.55%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-10823
|
CVE-2018-10823 |
HIGH
|
N/A
|
77.70%
|
cvelistv5 |
|
|
cve-2018-10737
|
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter. |
HIGH
|
7.2
|
42.05%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-10657
|
matrix-synapse: Injection of malicious events with a depth size of 2^63-1 can cause a denial of service to making rooms unusable |
MEDIUM
|
6.5
|
1.52%
|
cvelistv5 |
2026-06-27 |
|
cve-2018-10562
|
Dasan GPON Routers Command Injection Vulnerability |
CRITICAL
|
N/A
|
99.95%
|
cvelistv5 |
2022-03-31 |
|
cve-2018-10561
|
Dasan GPON Routers Authentication Bypass Vulnerability |
HIGH
|
N/A
|
92.89%
|
cvelistv5 |
2022-03-31 |
|
cve-2018-10468
|
The transferFrom function of a smart contract implementation for Useless Ethereum Token (UET), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer all victims' balances into their account) because certain computations involving _value are incorrect, as exploited in the wild starting in December 2017, aka the "transferFlaw" issue. |
HIGH
|
7.5
|
1.57%
|
cvelistv5 |
2026-06-17 |