Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 55 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-17793 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 30 September 2018 |
| CVE-2018-17776 | PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users to gain privileges by replacing an executable file with a Trojan horse. | EXPLOIT ✓HIGH 7.8EPSS 3.39% | 28 September 2018 |
| CVE-2018-17397 | SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter. | EXPLOITCRITICAL 9.8EPSS 3.21% | 28 September 2018 |
| CVE-2018-17394 | SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter. | EXPLOITCRITICAL 9.8EPSS 3.21% | 28 September 2018 |
| CVE-2018-17391 | SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 3.21% | 28 September 2018 |
| CVE-2018-17385 | SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 3.21% | 28 September 2018 |
| CVE-2018-17384 | SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 3.28% | 28 September 2018 |
| CVE-2018-17383 | SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter. | EXPLOITCRITICAL 9.8EPSS 3.21% | 28 September 2018 |
| CVE-2018-17382 | SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 3.21% | 28 September 2018 |
| CVE-2018-17380 | SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 3.28% | 28 September 2018 |
| CVE-2018-17379 | SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 3.28% | 28 September 2018 |
| CVE-2018-17378 | SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 3.28% | 28 September 2018 |
| CVE-2018-17377 | SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter. | EXPLOITCRITICAL 9.8EPSS 3.21% | 28 September 2018 |
| CVE-2018-17376 | SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 3.21% | 28 September 2018 |
| CVE-2018-17375 | SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 3.28% | 28 September 2018 |
| CVE-2018-16659 | The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. | EXPLOITCRITICAL 9.8EPSS 2.74% | 28 September 2018 |
| CVE-2018-17313 | On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi. | EXPLOITMEDIUM 6.1EPSS 2.32% | 26 September 2018 |
| CVE-2018-17310 | On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi. | EXPLOITMEDIUM 6.1EPSS 2.32% | 26 September 2018 |
| CVE-2018-14327 | The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before EE40_00_02.00_45 sets weak permissions (Everyone:Full Control) for the "Web Connecton\EE40" and "Web… | EXPLOITHIGH 7.8EPSS 4.39% | 26 September 2018 |
| CVE-2018-7355 | All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. | EXPLOITMEDIUM 6.1EPSS 1.90% | 26 September 2018 |
| CVE-2018-14634 | Linux Kernel Integer Overflow Vulnerability | KEVEXPLOITHIGH 7.8EPSS 14.7% | 25 September 2018 |
| CVE-2018-15961 | Adobe ColdFusion Unrestricted File Upload Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 100.0% | 25 September 2018 |
| CVE-2018-16299 | The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter. | EXPLOITHIGH 7.5EPSS 44.4% | 24 September 2018 |
| CVE-2018-16283 | The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. | EXPLOITCRITICAL 9.8EPSS 63.1% | 24 September 2018 |
| CVE-2018-17173 | LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. | EXPLOIT ×2CRITICAL 9.8EPSS 56.2% | 21 September 2018 |
| CVE-2018-14592 | The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php. | EXPLOITCRITICAL 9.8EPSS 3.11% | 20 September 2018 |
| CVE-2018-17255 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 20 September 2018 |
| CVE-2018-17254 | The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 83.0% | 20 September 2018 |
| CVE-2018-17182 | The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. | EXPLOIT ✓HIGH 7.8EPSS 3.21% | 19 September 2018 |
| CVE-2018-17128 | A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode. | EXPLOITMEDIUM 5.4EPSS 74.8% | 17 September 2018 |
| CVE-2018-16288 | LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs. | EXPLOITHIGH 8.6EPSS 35.8% | 14 September 2018 |
| CVE-2018-10814 | Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials. | EXPLOITHIGH 7.8EPSS 1.43% | 14 September 2018 |
| CVE-2018-10763 | Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Partial Branding configuration page. | EXPLOITMEDIUM 4.8EPSS 1.65% | 14 September 2018 |
| CVE-2018-17057 | Attackers can trigger deserialization of arbitrary data via the phar:// wrapper. | EXPLOITCRITICAL 9.8EPSS 26.2% | 14 September 2018 |
| CVE-2018-8474 | A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync. | EXPLOIT ✓HIGH 7.5EPSS 38.2% | 13 September 2018 |
| CVE-2018-8469 | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. | EXPLOIT ✓HIGH 7.4EPSS 15.4% | 13 September 2018 |
| CVE-2018-8468 | An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows… | EXPLOIT ✓MEDIUM 4.7EPSS 11.8% | 13 September 2018 |
| CVE-2018-8467 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | EXPLOIT ✓HIGH 7.5EPSS 69.0% | 13 September 2018 |
| CVE-2018-8466 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | EXPLOIT ✓HIGH 7.5EPSS 69.0% | 13 September 2018 |
| CVE-2018-8463 | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. | EXPLOIT ✓HIGH 7.4EPSS 15.4% | 13 September 2018 |
| CVE-2018-8449 | A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | EXPLOIT ✓LOW 3.3EPSS 3.11% | 13 September 2018 |
| CVE-2018-8410 | An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | EXPLOIT ✓HIGH 7.8EPSS 3.98% | 13 September 2018 |
| CVE-2018-8269 | A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Service Vulnerability." This affects Microsoft.Data.OData. | EXPLOITHIGH 7.5EPSS 26.8% | 13 September 2018 |
| CVE-2018-7921 | Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. | EXPLOITMEDIUM 6.5EPSS 13.2% | 12 September 2018 |
| CVE-2017-1085 | A specially crafted executable could be exploited to execute arbitrary code in the user context. | EXPLOIT ✓HIGH 7.8EPSS 1.85% | 12 September 2018 |
| CVE-2017-1084 | This results in the possibility a poorly written process could be cause a stack overflow. | EXPLOIT ×2 ✓HIGH 7.5EPSS 15.3% | 12 September 2018 |
| CVE-2018-16946 | Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. | EXPLOITHIGH 7.5EPSS 9.35% | 12 September 2018 |
| CVE-2018-16836 | Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a… | EXPLOITCRITICAL 9.8EPSS 61.4% | 11 September 2018 |
| CVE-2018-16763 | FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. | EXPLOIT ×3CRITICAL 9.8EPSS 82.9% | 9 September 2018 |
| CVE-2018-16736 | In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings). | EXPLOITMEDIUM 5.4EPSS 2.60% | 9 September 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.