Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 56 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-16059 | Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter. | EXPLOITMEDIUM 5.3EPSS 29.8% | 7 September 2018 |
| CVE-2018-12897 | SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow. | EXPLOITHIGH 7.8EPSS 1.67% | 7 September 2018 |
| CVE-2018-1756 | IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. | EXPLOIT ✓HIGH 7.5EPSS 10.6% | 7 September 2018 |
| CVE-2018-16517 | asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file. | EXPLOITMEDIUM 5.5EPSS 5.17% | 6 September 2018 |
| CVE-2018-12234 | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. | EXPLOITMEDIUM 6.1EPSS 2.95% | 6 September 2018 |
| CVE-2018-16606 | In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Organization, and Position) by changing the value of… | EXPLOITMEDIUM 6.5EPSS 5.95% | 6 September 2018 |
| CVE-2018-16252 | FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection. | EXPLOITLOW 3.3EPSS 2.50% | 5 September 2018 |
| CVE-2018-15918 | SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate. | EXPLOIT ✓MEDIUM 5.4EPSS 2.87% | 5 September 2018 |
| CVE-2018-15917 | Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language. | EXPLOITMEDIUM 5.4EPSS 5.89% | 5 September 2018 |
| CVE-2015-9266 | The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. | EXPLOIT ✓CRITICAL 9.8EPSS 74.0% | 5 September 2018 |
| CVE-2018-16509 | Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. | EXPLOIT ✓HIGH 7.8EPSS 92.5% | 5 September 2018 |
| CVE-2018-16323 | If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data. | EXPLOITMEDIUM 6.5EPSS 49.3% | 1 September 2018 |
| CVE-2018-16302 | MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file. | EXPLOITHIGH 7.8EPSS 4.32% | 1 September 2018 |
| CVE-2018-15745 | Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter. | EXPLOIT ✓HIGH 7.5EPSS 97.7% | 30 August 2018 |
| CVE-2018-15691 | Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code. | EXPLOITCRITICAL 9.8EPSS 16.8% | 30 August 2018 |
| CVE-2018-16134 | Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI. | EXPLOIT ✓MEDIUM 6.1EPSS 3.99% | 29 August 2018 |
| CVE-2018-16133 | Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI. | EXPLOIT ✓MEDIUM 5.3EPSS 39.3% | 29 August 2018 |
| CVE-2018-12710 | Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML. | EXPLOITHIGH 8.0EPSS 76.5% | 29 August 2018 |
| CVE-2018-12827 | Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. | EXPLOIT ✓HIGH 7.5EPSS 32.0% | 29 August 2018 |
| CVE-2018-15884 | RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter. | EXPLOITHIGH 8.8EPSS 2.50% | 28 August 2018 |
| CVE-2018-15740 | Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen. | EXPLOITMEDIUM 6.1EPSS 6.14% | 28 August 2018 |
| CVE-2018-15608 | Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen. | EXPLOITMEDIUM 6.1EPSS 2.47% | 28 August 2018 |
| CVE-2018-15596 | The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS. | EXPLOITMEDIUM 6.1EPSS 2.26% | 28 August 2018 |
| CVE-2018-15839 | D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header. | EXPLOITCRITICAL 9.8EPSS 45.3% | 28 August 2018 |
| CVE-2014-6050 | phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request. | EXPLOITMEDIUM 5.3EPSS 4.55% | 28 August 2018 |
| CVE-2014-6049 | phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter. | EXPLOITLOW 2.7EPSS 3.19% | 28 August 2018 |
| CVE-2014-6048 | phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request. | EXPLOITMEDIUM 5.3EPSS 5.68% | 28 August 2018 |
| CVE-2014-6047 | phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks. | EXPLOITMEDIUM 5.3EPSS 5.68% | 28 August 2018 |
| CVE-2014-6046 | Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecified users for requests that (1) delete active users by leveraging improper validation of CSRF tokens or… | EXPLOITHIGH 8.8EPSS 1.93% | 28 August 2018 |
| CVE-2014-6045 | SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function. | EXPLOITHIGH 7.2EPSS 2.09% | 28 August 2018 |
| CVE-2018-0715 | Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application. | EXPLOITMEDIUM 6.1EPSS 3.12% | 27 August 2018 |
| CVE-2018-15877 | The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip parameter of a wp-admin/admin.php?page=plainview_activity_monitor&tab=activity_tools request. | EXPLOIT ×2 ✓HIGH 8.8EPSS 77.0% | 26 August 2018 |
| CVE-2018-15845 | There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add. | EXPLOITHIGH 8.8EPSS 2.35% | 25 August 2018 |
| CVE-2018-15844 | There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit. | EXPLOITHIGH 8.8EPSS 2.47% | 25 August 2018 |
| CVE-2018-14059 | Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions. | EXPLOITMEDIUM 5.4EPSS 3.12% | 24 August 2018 |
| CVE-2018-15576 | Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key. | EXPLOIT ✓HIGH 8.1EPSS 9.68% | 24 August 2018 |
| CVE-2018-11502 | It allows moderators to save notes and display them in a list in the modCP. | EXPLOITMEDIUM 6.5EPSS 1.92% | 24 August 2018 |
| CVE-2018-15536 | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal. | EXPLOIT ✓MEDIUM 5.5EPSS 6.41% | 24 August 2018 |
| CVE-2018-15535 | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to… | EXPLOIT ✓HIGH 7.5EPSS 45.2% | 24 August 2018 |
| CVE-2018-15120 | libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences. | EXPLOITMEDIUM 6.5EPSS 11.5% | 24 August 2018 |
| CVE-2018-15685 | GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code… | EXPLOIT ✓HIGH 8.1EPSS 10.4% | 23 August 2018 |
| CVE-2018-11776 | Apache Struts Remote Code Execution Vulnerability | KEVEXPLOIT ×3 ✓HIGH 8.1EPSS 100.0% | 22 August 2018 |
| CVE-2018-15534 | Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a direct request for /statistics/gscsetup.xml on TCP port 12003. | EXPLOITCRITICAL 9.8EPSS 32.4% | 21 August 2018 |
| CVE-2018-15533 | A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query string to /modifychannel/exec or /images/*.png on TCP port 12005. | EXPLOITMEDIUM 6.1EPSS 2.61% | 21 August 2018 |
| CVE-2018-1000638 | MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection. | EXPLOITMEDIUM 6.1EPSS 2.19% | 20 August 2018 |
| CVE-2018-15473 | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and… | EXPLOIT ×3 ✓MEDIUM 5.3EPSS 98.6% | 17 August 2018 |
| CVE-2018-14058 | Pimcore before 5.3.0 allows SQL Injection via the REST web service API. | EXPLOITMEDIUM 6.5EPSS 28.9% | 17 August 2018 |
| CVE-2018-14057 | Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function. | EXPLOITHIGH 8.8EPSS 3.34% | 17 August 2018 |
| CVE-2018-11511 | The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI. | EXPLOITCRITICAL 9.8EPSS 11.3% | 16 August 2018 |
| CVE-2018-11509 | This may allow an attacker to login and upload a webshell. | EXPLOITCRITICAL 9.8EPSS 12.6% | 16 August 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.