Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 52 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-19913 | DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field. | EXPLOITMEDIUM 4.8EPSS 1.76% | 6 December 2018 |
| CVE-2018-19908 | This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import. | EXPLOITHIGH 8.8EPSS 17.3% | 6 December 2018 |
| CVE-2018-19877 | login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field. | EXPLOITMEDIUM 6.1EPSS 18.6% | 5 December 2018 |
| CVE-2018-1002105 | In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to… | EXPLOIT ×2CRITICAL 9.8EPSS 87.0% | 5 December 2018 |
| CVE-2018-19864 | NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device. | EXPLOITCRITICAL 9.8EPSS 24.8% | 5 December 2018 |
| CVE-2018-6092 | An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | EXPLOIT ✓HIGH 8.8EPSS 9.19% | 4 December 2018 |
| CVE-2018-1002009 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | EXPLOITMEDIUM 4.8EPSS 2.60% | 3 December 2018 |
| CVE-2018-1002008 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | EXPLOITMEDIUM 4.8EPSS 2.58% | 3 December 2018 |
| CVE-2018-1002007 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | EXPLOITMEDIUM 4.8EPSS 2.58% | 3 December 2018 |
| CVE-2018-1002006 | These vulnerabilities require administrative privileges to exploit. | EXPLOITMEDIUM 4.8EPSS 2.58% | 3 December 2018 |
| CVE-2018-1002005 | These vulnerabilities require administrative privileges to exploit. | EXPLOITMEDIUM 4.8EPSS 3.14% | 3 December 2018 |
| CVE-2018-1002004 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | EXPLOITMEDIUM 4.8EPSS 2.92% | 3 December 2018 |
| CVE-2018-1002003 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | EXPLOITMEDIUM 4.8EPSS 2.92% | 3 December 2018 |
| CVE-2018-1002002 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | EXPLOITMEDIUM 4.8EPSS 2.92% | 3 December 2018 |
| CVE-2018-1002001 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | EXPLOITMEDIUM 4.8EPSS 2.95% | 3 December 2018 |
| CVE-2018-1002000 | There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. | EXPLOITHIGH 7.2EPSS 4.35% | 3 December 2018 |
| CVE-2018-15716 | NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. | EXPLOITHIGH 8.8EPSS 18.5% | 30 November 2018 |
| CVE-2018-18860 | A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. | EXPLOITHIGH 7.8EPSS 1.18% | 30 November 2018 |
| CVE-2018-15768 | Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due to insecure default configuration setting for the embedded MySQL database. | EXPLOIT ✓MEDIUM 6.5EPSS 9.05% | 30 November 2018 |
| CVE-2018-15767 | The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file. | EXPLOIT ✓HIGH 8.8EPSS 12.3% | 30 November 2018 |
| CVE-2018-19752 | DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar. | EXPLOITMEDIUM 4.8EPSS 3.32% | 29 November 2018 |
| CVE-2018-19751 | DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields. | EXPLOITMEDIUM 4.8EPSS 3.32% | 29 November 2018 |
| CVE-2018-19750 | DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields. | EXPLOITMEDIUM 5.4EPSS 1.80% | 29 November 2018 |
| CVE-2018-19749 | DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field. | EXPLOITMEDIUM 4.8EPSS 3.32% | 29 November 2018 |
| CVE-2018-18619 | internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the… | EXPLOITCRITICAL 9.8EPSS 4.18% | 29 November 2018 |
| CVE-2018-19627 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. | EXPLOIT ✓HIGH 7.5EPSS 17.7% | 29 November 2018 |
| CVE-2018-18982 | NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution. | EXPLOIT ✓HIGH 8.8EPSS 60.8% | 27 November 2018 |
| CVE-2018-19550 | Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/temp/surveys/ URI. | EXPLOITHIGH 8.8EPSS 5.99% | 26 November 2018 |
| CVE-2018-19518 | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without… | EXPLOIT ✓HIGH 7.5EPSS 95.2% | 25 November 2018 |
| CVE-2018-19459 | Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file. | EXPLOITHIGH 7.8EPSS 4.00% | 22 November 2018 |
| CVE-2018-19458 | In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246. | EXPLOITHIGH 7.5EPSS 32.9% | 22 November 2018 |
| CVE-2018-19423 | Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file. | EXPLOITHIGH 7.2EPSS 18.1% | 21 November 2018 |
| CVE-2018-19422 | /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these. | EXPLOITHIGH 7.2EPSS 64.3% | 21 November 2018 |
| CVE-2018-18865 | The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure. | EXPLOITHIGH 8.1EPSS 8.00% | 20 November 2018 |
| CVE-2018-18859 | Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. | EXPLOITHIGH 7.8EPSS 1.57% | 20 November 2018 |
| CVE-2018-18858 | Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. | EXPLOITHIGH 7.8EPSS 1.57% | 20 November 2018 |
| CVE-2018-18857 | Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. | EXPLOITHIGH 7.8EPSS 1.60% | 20 November 2018 |
| CVE-2018-18856 | Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. | EXPLOITHIGH 7.8EPSS 1.61% | 20 November 2018 |
| CVE-2018-18774 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter. | EXPLOITMEDIUM 6.1EPSS 4.75% | 20 November 2018 |
| CVE-2018-18773 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password. | EXPLOITHIGH 8.8EPSS 3.41% | 20 November 2018 |
| CVE-2018-18772 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command. | EXPLOITHIGH 8.8EPSS 3.48% | 20 November 2018 |
| CVE-2018-18955 | In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. | EXPLOIT ×6 ✓HIGH 7.0EPSS 7.61% | 16 November 2018 |
| CVE-2018-18805 | Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb. | EXPLOITCRITICAL 9.8EPSS 5.20% | 16 November 2018 |
| CVE-2018-18804 | Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb. | EXPLOITCRITICAL 9.8EPSS 3.21% | 16 November 2018 |
| CVE-2018-18803 | Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb. | EXPLOITCRITICAL 9.8EPSS 3.21% | 16 November 2018 |
| CVE-2018-18801 | The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL]. | EXPLOITCRITICAL 9.8EPSS 3.21% | 16 November 2018 |
| CVE-2018-18799 | School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos. | EXPLOITHIGH 8.8EPSS 2.38% | 16 November 2018 |
| CVE-2018-18797 | School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php. | EXPLOITHIGH 8.8EPSS 2.38% | 16 November 2018 |
| CVE-2018-18795 | School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. | EXPLOITCRITICAL 9.8EPSS 3.21% | 16 November 2018 |
| CVE-2018-18794 | School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. | EXPLOITHIGH 8.8EPSS 2.38% | 16 November 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.