SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 57 of 501

CVESummaryPriorityPublished
CVE-2018-8384A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore.EXPLOITHIGH 7.5EPSS 62.1%15 August 2018
CVE-2018-8355A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge.EXPLOITHIGH 7.5EPSS 68.2%15 August 2018
CVE-2018-8353A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet…EXPLOITHIGH 7.5EPSS 67.7%15 August 2018
CVE-2018-15172TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.EXPLOITHIGH 7.5EPSS 8.30%15 August 2018
CVE-2018-15152Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4)…EXPLOITCRITICAL 9.1EPSS 25.9%15 August 2018
CVE-2018-0952An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability." This affects Windows Server 2016, Windows…EXPLOITHIGH 7.8EPSS 6.23%15 August 2018
CVE-2018-14888inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject.EXPLOITMEDIUM 6.1EPSS 3.68%14 August 2018
CVE-2018-15142Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to execute arbitrary PHP code by writing a file with a PHP extension via the "docid" and "content"…EXPLOITHIGH 8.8EPSS 18.2%13 August 2018
CVE-2018-15141Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to delete arbitrary files via the "docid" parameter when the mode is set to delete.EXPLOITMEDIUM 6.5EPSS 14.5%13 August 2018
CVE-2018-15140Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to read arbitrary files via the "docid" parameter when the mode is set to get.EXPLOITMEDIUM 6.5EPSS 16.7%13 August 2018
CVE-2018-15139Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and…EXPLOIT ×2HIGH 8.8EPSS 19.3%13 August 2018
CVE-2018-13417In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.EXPLOITCRITICAL 9.8EPSS 20.7%13 August 2018
CVE-2018-13415In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.EXPLOITCRITICAL 9.8EPSS 31.8%13 August 2018
CVE-2018-11492ASUS HG100 devices allow denial of service via an IPv4 packet flood.EXPLOITHIGH 7.5EPSS 11.4%10 August 2018
CVE-2018-15181JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS payload in the SSID name and Security Key fields.EXPLOITMEDIUM 6.5EPSS 5.28%9 August 2018
CVE-2018-15133Laravel Deserialization of Untrusted Data VulnerabilityKEVEXPLOITHIGH 8.1EPSS 76.8%9 August 2018
CVE-2018-15137CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well.EXPLOITCRITICAL 9.8EPSS 18.2%8 August 2018
CVE-2018-14869PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile.EXPLOITMEDIUM 5.4EPSS 1.60%6 August 2018
CVE-2018-14716A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.EXPLOITHIGH 7.5EPSS 33.0%6 August 2018
CVE-2016-8527Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS).EXPLOITMEDIUM 6.1EPSS 13.2%6 August 2018
CVE-2016-8526Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE).EXPLOITHIGH 8.8EPSS 9.81%6 August 2018
CVE-2018-14933NUUO NVRmini Devices OS Command Injection Vulnerability KEVEXPLOITCRITICAL 9.8EPSS 94.9%4 August 2018
CVE-2018-14497Tenda D152 ADSL routers allow XSS via a crafted SSID.EXPLOITMEDIUM 5.4EPSS 1.64%4 August 2018
CVE-2018-14417A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3.EXPLOITCRITICAL 9.8EPSS 89.6%4 August 2018
CVE-2018-14912cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.EXPLOITHIGH 7.5EPSS 92.9%3 August 2018
CVE-2018-14728upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.EXPLOITCRITICAL 9.8EPSS 76.5%3 August 2018
CVE-2017-15358Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privileges via vectors involving the --self-repair option.EXPLOITHIGH 7.0EPSS 0.76%3 August 2018
CVE-2018-13416In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.EXPLOITCRITICAL 9.8EPSS 20.2%3 August 2018
CVE-2018-14847MikroTik Router OS Directory Traversal VulnerabilityKEVEXPLOITCRITICAL 9.1EPSS 96.1%2 August 2018
CVE-2018-14840uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).EXPLOITMEDIUM 6.1EPSS 3.67%2 August 2018
CVE-2018-10618The device generates a weak password hash that is easily cracked, allowing a remote attacker to obtain the password for the device.EXPLOITCRITICAL 9.8EPSS 10.1%1 August 2018
CVE-2016-8641A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards.EXPLOITHIGH 7.8EPSS 1.14%1 August 2018
CVE-2018-14533read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /var is a symlink to /tmp.EXPLOITHIGH 7.8EPSS 1.49%31 July 2018
CVE-2017-15118A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack…EXPLOITCRITICAL 9.8EPSS 11.9%27 July 2018
CVE-2018-10900Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack.EXPLOITHIGH 7.8EPSS 5.06%26 July 2018
CVE-2018-14493Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name.EXPLOITMEDIUM 6.1EPSS 40.9%25 July 2018
CVE-2018-10906In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active.EXPLOITHIGH 7.8EPSS 1.41%24 July 2018
CVE-2018-14335Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.EXPLOITMEDIUM 6.5EPSS 13.4%24 July 2018
CVE-2018-10608SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, which may cause denial of service via 100% CPU utilization.EXPLOITHIGH 7.5EPSS 7.82%24 July 2018
CVE-2018-14328Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for /dashboard/addplan, /dashboard/paywithcard/charge, /dashboard/withdrawal, or /privacy&terms,…EXPLOITCRITICAL 9.8EPSS 10.7%23 July 2018
CVE-2018-1999002A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the…EXPLOITHIGH 7.5EPSS 86.6%23 July 2018
CVE-2018-1513IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting.EXPLOITMEDIUM 5.4EPSS 2.94%23 July 2018
CVE-2018-1563IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting.EXPLOITMEDIUM 5.4EPSS 2.84%20 July 2018
CVE-2018-14418In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.EXPLOITCRITICAL 9.8EPSS 9.08%20 July 2018
CVE-2018-14336TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses.EXPLOITHIGH 7.5EPSS 8.30%19 July 2018
CVE-2018-7602Drupal Core Remote Code Execution VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 99.2%19 July 2018
CVE-2018-14392The New Threads plugin before 1.2 for MyBB has XSS.EXPLOITMEDIUM 6.1EPSS 48.6%19 July 2018
CVE-2018-2892Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service).EXPLOITHIGH 7.8EPSS 1.77%18 July 2018
CVE-2018-1612IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information.EXPLOITMEDIUM 5.8EPSS 57.0%17 July 2018
CVE-2018-13862Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attackers to reset the authentication via the "/xml/system/setAttribute.xml" URL, using the GET request "?id=0&attr=protectAccess&newValue=0"…EXPLOITCRITICAL 9.8EPSS 50.6%17 July 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.