SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 51 of 501

CVESummaryPriorityPublished
CVE-2019-0567A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.EXPLOITHIGH 7.5EPSS 80.1%8 January 2019
CVE-2019-0566An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.EXPLOITHIGH 8.8EPSS 18.6%8 January 2019
CVE-2019-0555An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows…EXPLOITHIGH 7.8EPSS 2.65%8 January 2019
CVE-2019-0552An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10…EXPLOITHIGH 8.8EPSS 2.54%8 January 2019
CVE-2019-0543Microsoft Windows Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 4.72%8 January 2019
CVE-2019-0541Microsoft MSHTML Remote Code Execution VulnerabilityKEVEXPLOITHIGH 8.8EPSS 53.2%8 January 2019
CVE-2019-0539A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.EXPLOIT ×3HIGH 7.5EPSS 82.9%8 January 2019
CVE-2018-5410Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys driver.EXPLOITHIGH 7.8EPSS 1.59%7 January 2019
CVE-2019-5009Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40.EXPLOITHIGH 7.2EPSS 9.94%4 January 2019
CVE-2018-19862Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request.EXPLOITCRITICAL 9.8EPSS 12.6%3 January 2019
CVE-2018-19861Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request.EXPLOITCRITICAL 9.8EPSS 12.6%3 January 2019
CVE-2018-20326ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter.EXPLOITMEDIUM 6.1EPSS 4.82%2 January 2019
CVE-2018-20166A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishandles extension checking.EXPLOITHIGH 8.8EPSS 7.12%2 January 2019
CVE-2018-19371The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.EXPLOITMEDIUM 6.5EPSS 6.02%2 January 2019
CVE-2018-13045SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.EXPLOITCRITICAL 9.8EPSS 3.21%2 January 2019
CVE-2018-20658The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.EXPLOITHIGH 7.5EPSS 8.49%2 January 2019
CVE-2019-3501The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards page or in a user profile.EXPLOITMEDIUM 4.8EPSS 2.35%2 January 2019
CVE-2018-1000888PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class.EXPLOITHIGH 8.8EPSS 19.1%28 December 2018
CVE-2018-19799Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.EXPLOITMEDIUM 6.1EPSS 4.48%26 December 2018
CVE-2018-19616An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000.EXPLOITHIGH 8.1EPSS 30.3%26 December 2018
CVE-2018-11742NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.EXPLOITCRITICAL 9.8EPSS 14.3%26 December 2018
CVE-2018-11741NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs.EXPLOITCRITICAL 9.8EPSS 17.9%26 December 2018
CVE-2018-20485Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.EXPLOITMEDIUM 6.1EPSS 5.27%26 December 2018
CVE-2018-20484Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.EXPLOITMEDIUM 6.1EPSS 5.27%26 December 2018
CVE-2018-20448Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.EXPLOITMEDIUM 5.4EPSS 1.68%25 December 2018
CVE-2018-20418index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.EXPLOITMEDIUM 4.8EPSS 3.70%24 December 2018
CVE-2018-18629An untrusted search path vulnerability in the keybase-redirector application allows a local, unprivileged user on Linux to gain root privileges via a Trojan horse binary.EXPLOITHIGH 7.8EPSS 1.49%20 December 2018
CVE-2018-1160Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c.EXPLOIT ×3CRITICAL 9.8EPSS 86.5%20 December 2018
CVE-2018-1000811bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution.EXPLOITHIGH 8.8EPSS 47.6%20 December 2018
CVE-2018-19829Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known.EXPLOITMEDIUM 6.5EPSS 1.92%18 December 2018
CVE-2018-19933Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.EXPLOITMEDIUM 6.1EPSS 3.47%17 December 2018
CVE-2018-19828Artica Integria IMS 5.0.83 has XSS via the search_string parameter.EXPLOITMEDIUM 6.1EPSS 2.27%17 December 2018
CVE-2018-20159i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled.EXPLOITHIGH 7.2EPSS 9.89%15 December 2018
CVE-2018-18923AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and…EXPLOITCRITICAL 9.8EPSS 3.21%13 December 2018
CVE-2018-1821IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.EXPLOITCRITICAL 9.1EPSS 15.8%13 December 2018
CVE-2018-7691A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized AccessEXPLOITMEDIUM 6.5EPSS 7.23%13 December 2018
CVE-2018-7690A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized AccessEXPLOITMEDIUM 6.5EPSS 7.41%13 December 2018
CVE-2018-8631A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.EXPLOITHIGH 7.5EPSS 68.5%12 December 2018
CVE-2018-8625A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.EXPLOITHIGH 7.5EPSS 43.8%12 December 2018
CVE-2018-8619A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer…EXPLOITHIGH 7.5EPSS 44.8%12 December 2018
CVE-2018-8617A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.EXPLOITHIGH 7.5EPSS 62.5%12 December 2018
CVE-2018-20062ThinkPHP "noneCms" Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.5%11 December 2018
CVE-2018-20011DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.EXPLOITMEDIUM 4.8EPSS 4.43%10 December 2018
CVE-2018-20010DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.EXPLOITMEDIUM 4.8EPSS 4.43%10 December 2018
CVE-2018-20009DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.EXPLOITMEDIUM 4.8EPSS 4.43%10 December 2018
CVE-2018-6757Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware.EXPLOITHIGH 7.8EPSS 1.14%6 December 2018
CVE-2018-6756Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute unauthorized commands via specially crafted malware.EXPLOITHIGH 7.8EPSS 1.03%6 December 2018
CVE-2018-6755Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware.EXPLOITHIGH 7.8EPSS 0.98%6 December 2018
CVE-2018-19915DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.EXPLOITMEDIUM 4.8EPSS 4.01%6 December 2018
CVE-2018-19914DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.EXPLOITMEDIUM 4.8EPSS 3.32%6 December 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.