Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 51 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-0567 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | EXPLOIT ✓HIGH 7.5EPSS 80.1% | 8 January 2019 |
| CVE-2019-0566 | An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. | EXPLOIT ✓HIGH 8.8EPSS 18.6% | 8 January 2019 |
| CVE-2019-0555 | An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows… | EXPLOIT ✓HIGH 7.8EPSS 2.65% | 8 January 2019 |
| CVE-2019-0552 | An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10… | EXPLOIT ✓HIGH 8.8EPSS 2.54% | 8 January 2019 |
| CVE-2019-0543 | Microsoft Windows Privilege Escalation Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 4.72% | 8 January 2019 |
| CVE-2019-0541 | Microsoft MSHTML Remote Code Execution Vulnerability | KEVEXPLOITHIGH 8.8EPSS 53.2% | 8 January 2019 |
| CVE-2019-0539 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | EXPLOIT ×3 ✓HIGH 7.5EPSS 82.9% | 8 January 2019 |
| CVE-2018-5410 | Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys driver. | EXPLOIT ✓HIGH 7.8EPSS 1.59% | 7 January 2019 |
| CVE-2019-5009 | Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. | EXPLOITHIGH 7.2EPSS 9.94% | 4 January 2019 |
| CVE-2018-19862 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. | EXPLOITCRITICAL 9.8EPSS 12.6% | 3 January 2019 |
| CVE-2018-19861 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. | EXPLOITCRITICAL 9.8EPSS 12.6% | 3 January 2019 |
| CVE-2018-20326 | ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter. | EXPLOITMEDIUM 6.1EPSS 4.82% | 2 January 2019 |
| CVE-2018-20166 | A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishandles extension checking. | EXPLOITHIGH 8.8EPSS 7.12% | 2 January 2019 |
| CVE-2018-19371 | The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system. | EXPLOITMEDIUM 6.5EPSS 6.02% | 2 January 2019 |
| CVE-2018-13045 | SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter. | EXPLOITCRITICAL 9.8EPSS 3.21% | 2 January 2019 |
| CVE-2018-20658 | The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command. | EXPLOITHIGH 7.5EPSS 8.49% | 2 January 2019 |
| CVE-2019-3501 | The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards page or in a user profile. | EXPLOITMEDIUM 4.8EPSS 2.35% | 2 January 2019 |
| CVE-2018-1000888 | PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. | EXPLOITHIGH 8.8EPSS 19.1% | 28 December 2018 |
| CVE-2018-19799 | Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS. | EXPLOITMEDIUM 6.1EPSS 4.48% | 26 December 2018 |
| CVE-2018-19616 | An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. | EXPLOITHIGH 8.1EPSS 30.3% | 26 December 2018 |
| CVE-2018-11742 | NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI. | EXPLOITCRITICAL 9.8EPSS 14.3% | 26 December 2018 |
| CVE-2018-11741 | NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs. | EXPLOITCRITICAL 9.8EPSS 17.9% | 26 December 2018 |
| CVE-2018-20485 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. | EXPLOITMEDIUM 6.1EPSS 5.27% | 26 December 2018 |
| CVE-2018-20484 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. | EXPLOITMEDIUM 6.1EPSS 5.27% | 26 December 2018 |
| CVE-2018-20448 | Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI. | EXPLOITMEDIUM 5.4EPSS 1.68% | 25 December 2018 |
| CVE-2018-20418 | index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. | EXPLOITMEDIUM 4.8EPSS 3.70% | 24 December 2018 |
| CVE-2018-18629 | An untrusted search path vulnerability in the keybase-redirector application allows a local, unprivileged user on Linux to gain root privileges via a Trojan horse binary. | EXPLOITHIGH 7.8EPSS 1.49% | 20 December 2018 |
| CVE-2018-1160 | Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. | EXPLOIT ×3 ✓CRITICAL 9.8EPSS 86.5% | 20 December 2018 |
| CVE-2018-1000811 | bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. | EXPLOITHIGH 8.8EPSS 47.6% | 20 December 2018 |
| CVE-2018-19829 | Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known. | EXPLOITMEDIUM 6.5EPSS 1.92% | 18 December 2018 |
| CVE-2018-19933 | Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry. | EXPLOITMEDIUM 6.1EPSS 3.47% | 17 December 2018 |
| CVE-2018-19828 | Artica Integria IMS 5.0.83 has XSS via the search_string parameter. | EXPLOITMEDIUM 6.1EPSS 2.27% | 17 December 2018 |
| CVE-2018-20159 | i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. | EXPLOITHIGH 7.2EPSS 9.89% | 15 December 2018 |
| CVE-2018-18923 | AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and… | EXPLOITCRITICAL 9.8EPSS 3.21% | 13 December 2018 |
| CVE-2018-1821 | IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. | EXPLOIT ✓CRITICAL 9.1EPSS 15.8% | 13 December 2018 |
| CVE-2018-7691 | A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access | EXPLOIT ✓MEDIUM 6.5EPSS 7.23% | 13 December 2018 |
| CVE-2018-7690 | A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access | EXPLOIT ✓MEDIUM 6.5EPSS 7.41% | 13 December 2018 |
| CVE-2018-8631 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. | EXPLOIT ✓HIGH 7.5EPSS 68.5% | 12 December 2018 |
| CVE-2018-8625 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. | EXPLOIT ✓HIGH 7.5EPSS 43.8% | 12 December 2018 |
| CVE-2018-8619 | A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer… | EXPLOIT ✓HIGH 7.5EPSS 44.8% | 12 December 2018 |
| CVE-2018-8617 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | EXPLOIT ✓HIGH 7.5EPSS 62.5% | 12 December 2018 |
| CVE-2018-20062 | ThinkPHP "noneCms" Remote Code Execution Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 99.5% | 11 December 2018 |
| CVE-2018-20011 | DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field. | EXPLOIT ✓MEDIUM 4.8EPSS 4.43% | 10 December 2018 |
| CVE-2018-20010 | DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field. | EXPLOIT ✓MEDIUM 4.8EPSS 4.43% | 10 December 2018 |
| CVE-2018-20009 | DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field. | EXPLOIT ✓MEDIUM 4.8EPSS 4.43% | 10 December 2018 |
| CVE-2018-6757 | Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware. | EXPLOIT ✓HIGH 7.8EPSS 1.14% | 6 December 2018 |
| CVE-2018-6756 | Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute unauthorized commands via specially crafted malware. | EXPLOIT ✓HIGH 7.8EPSS 1.03% | 6 December 2018 |
| CVE-2018-6755 | Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware. | EXPLOIT ✓HIGH 7.8EPSS 0.98% | 6 December 2018 |
| CVE-2018-19915 | DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field. | EXPLOIT ✓MEDIUM 4.8EPSS 4.01% | 6 December 2018 |
| CVE-2018-19914 | DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field. | EXPLOIT ✓MEDIUM 4.8EPSS 3.32% | 6 December 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.