Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 53 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-18793 | School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. | EXPLOITCRITICAL 9.8EPSS 9.50% | 16 November 2018 |
| CVE-2018-18763 | SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. | EXPLOITCRITICAL 9.8EPSS 3.21% | 16 November 2018 |
| CVE-2018-18761 | SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. | EXPLOITCRITICAL 9.8EPSS 16.5% | 16 November 2018 |
| CVE-2018-18760 | RhinOS 3.0 build 1190 allows CSRF. | EXPLOITMEDIUM 6.5EPSS 2.63% | 16 November 2018 |
| CVE-2018-18759 | Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow. | EXPLOITHIGH 7.5EPSS 8.75% | 16 November 2018 |
| CVE-2018-18755 | K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter. | EXPLOITCRITICAL 9.8EPSS 3.10% | 16 November 2018 |
| CVE-2018-5407 | Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. | EXPLOITMEDIUM 4.7EPSS 3.42% | 15 November 2018 |
| CVE-2018-19287 | XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter. | EXPLOITMEDIUM 6.1EPSS 8.86% | 15 November 2018 |
| CVE-2018-15710 | Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php. | EXPLOIT ×2 ✓HIGH 7.8EPSS 44.1% | 14 November 2018 |
| CVE-2018-15708 | Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 89.4% | 14 November 2018 |
| CVE-2018-7358 | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations. | EXPLOIT ✓HIGH 8.8EPSS 89.6% | 14 November 2018 |
| CVE-2018-7357 | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access. | EXPLOIT ✓HIGH 8.8EPSS 87.9% | 14 November 2018 |
| CVE-2018-6065 | Google Chromium V8 Integer Overflow Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 60.3% | 14 November 2018 |
| CVE-2018-6064 | Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | EXPLOIT ✓HIGH 8.8EPSS 6.89% | 14 November 2018 |
| CVE-2018-17463 | Google Chromium V8 Remote Code Execution Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 84.6% | 14 November 2018 |
| CVE-2018-19277 | securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file | EXPLOITHIGH 8.8EPSS 7.79% | 14 November 2018 |
| CVE-2018-8584 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019,… | EXPLOIT ✓HIGH 7.8EPSS 2.70% | 14 November 2018 |
| CVE-2018-8552 | An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory… | EXPLOIT ✓HIGH 7.5EPSS 51.0% | 14 November 2018 |
| CVE-2018-8550 | An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012,… | EXPLOIT ✓HIGH 7.8EPSS 3.29% | 14 November 2018 |
| CVE-2018-8544 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server… | EXPLOIT ✓HIGH 8.8EPSS 47.6% | 14 November 2018 |
| CVE-2018-19246 | PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their web server) is used. | EXPLOITHIGH 7.5EPSS 22.0% | 13 November 2018 |
| CVE-2018-19135 | ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). | EXPLOITHIGH 8.8EPSS 2.96% | 11 November 2018 |
| CVE-2018-19138 | WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI. | EXPLOITHIGH 8.8EPSS 2.25% | 9 November 2018 |
| CVE-2018-19136 | DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter. | EXPLOITMEDIUM 6.1EPSS 6.62% | 9 November 2018 |
| CVE-2018-19126 | PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload. | EXPLOITCRITICAL 9.8EPSS 22.5% | 9 November 2018 |
| CVE-2018-19125 | PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory. | EXPLOITHIGH 7.5EPSS 10.8% | 9 November 2018 |
| CVE-2018-15437 | A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Windows could allow a local attacker to disable the scanning functionality of the product. | EXPLOIT ✓MEDIUM 5.5EPSS 0.97% | 8 November 2018 |
| CVE-2018-8021 | Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. | EXPLOITCRITICAL 9.8EPSS 52.8% | 7 November 2018 |
| CVE-2018-9488 | In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. | EXPLOIT ✓HIGH 7.8EPSS 0.43% | 6 November 2018 |
| CVE-2018-9445 | In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. | EXPLOIT ✓MEDIUM 6.8EPSS 0.82% | 6 November 2018 |
| CVE-2018-18957 | It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c. | EXPLOITCRITICAL 9.8EPSS 11.6% | 5 November 2018 |
| CVE-2018-18924 | The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the server, with predictable filenames, after a "This file is not a valid image"… | EXPLOITHIGH 8.8EPSS 9.49% | 4 November 2018 |
| CVE-2018-18777 | Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. | EXPLOITMEDIUM 4.3EPSS 22.8% | 1 November 2018 |
| CVE-2018-18776 | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. | EXPLOITMEDIUM 6.1EPSS 2.32% | 1 November 2018 |
| CVE-2018-18775 | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. | EXPLOITMEDIUM 6.1EPSS 7.90% | 1 November 2018 |
| CVE-2018-15707 | Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. | EXPLOITMEDIUM 5.4EPSS 1.88% | 31 October 2018 |
| CVE-2018-15705 | WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. | EXPLOITMEDIUM 6.5EPSS 12.2% | 31 October 2018 |
| CVE-2018-10712 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read/write data from/to IO ports. | EXPLOITHIGH 7.8EPSS 1.35% | 30 October 2018 |
| CVE-2018-10711 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write Machine Specific Registers (MSRs). | EXPLOITHIGH 7.8EPSS 1.54% | 30 October 2018 |
| CVE-2018-10710 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitrary physical memory. | EXPLOITHIGH 7.1EPSS 0.98% | 30 October 2018 |
| CVE-2018-10709 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write CR register values. | EXPLOITHIGH 7.8EPSS 1.17% | 30 October 2018 |
| CVE-2018-15687 | A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. | EXPLOIT ✓HIGH 7.0EPSS 1.06% | 26 October 2018 |
| CVE-2018-15686 | A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. | EXPLOIT ✓HIGH 7.8EPSS 2.26% | 26 October 2018 |
| CVE-2018-14665 | X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges. | EXPLOIT ×8 ✓MEDIUM 6.6EPSS 27.0% | 25 October 2018 |
| CVE-2018-18548 | ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager. | EXPLOITMEDIUM 6.1EPSS 3.59% | 24 October 2018 |
| CVE-2018-12650 | Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSearch page via 'prntDDLCntrlName' and 'prntFrmName'. | EXPLOITMEDIUM 6.1EPSS 2.61% | 24 October 2018 |
| CVE-2018-15442 | A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. | EXPLOIT ×2 ✓HIGH 7.8EPSS 16.0% | 24 October 2018 |
| CVE-2018-18437 | In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc parameter. | EXPLOITMEDIUM 6.1EPSS 2.27% | 23 October 2018 |
| CVE-2018-18557 | LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring… | EXPLOIT ✓HIGH 8.8EPSS 15.0% | 22 October 2018 |
| CVE-2018-18428 | TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI. | EXPLOITHIGH 7.5EPSS 11.5% | 19 October 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.