Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 59 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-12912 | There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI. | EXPLOIT ✓HIGH 7.2EPSS 2.65% | 27 June 2018 |
| CVE-2018-12908 | Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for the /dashboard/deposit URI, as demonstrated by discovering database credentials. | EXPLOITCRITICAL 9.8EPSS 10.5% | 27 June 2018 |
| CVE-2018-12904 | In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL. | EXPLOIT ✓MEDIUM 4.9EPSS 1.18% | 27 June 2018 |
| CVE-2018-10594 | This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 68.6% | 26 June 2018 |
| CVE-2018-10662 | There is an Exposed Insecure Interface. | EXPLOIT ✓CRITICAL 9.8EPSS 79.5% | 26 June 2018 |
| CVE-2018-10661 | There is a bypass of access control. | EXPLOIT ✓CRITICAL 9.8EPSS 86.5% | 26 June 2018 |
| CVE-2018-10660 | There is Shell Command Injection. | EXPLOIT ✓CRITICAL 9.8EPSS 82.1% | 26 June 2018 |
| CVE-2018-12603 | Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114. | EXPLOITHIGH 8.8EPSS 3.49% | 25 June 2018 |
| CVE-2018-12602 | A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily. | EXPLOITHIGH 8.8EPSS 3.00% | 25 June 2018 |
| CVE-2018-10956 | IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal. | EXPLOITHIGH 7.5EPSS 55.0% | 25 June 2018 |
| CVE-2018-12706 | DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header. | EXPLOITCRITICAL 9.8EPSS 9.91% | 24 June 2018 |
| CVE-2018-12705 | DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side). | EXPLOITMEDIUM 6.1EPSS 2.29% | 24 June 2018 |
| CVE-2018-12636 | The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page. | EXPLOITHIGH 7.2EPSS 29.8% | 22 June 2018 |
| CVE-2018-12634 | CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI. | EXPLOITCRITICAL 9.8EPSS 56.4% | 22 June 2018 |
| CVE-2018-12613 | An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. | EXPLOIT ×4 ✓HIGH 8.8EPSS 98.4% | 21 June 2018 |
| CVE-2018-12617 | qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. | EXPLOITHIGH 7.5EPSS 25.1% | 21 June 2018 |
| CVE-2018-12604 | GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log. | EXPLOITHIGH 7.5EPSS 13.2% | 20 June 2018 |
| CVE-2018-6563 | Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change… | EXPLOITHIGH 8.8EPSS 2.31% | 20 June 2018 |
| CVE-2018-12327 | Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. | EXPLOITCRITICAL 9.8EPSS 28.7% | 20 June 2018 |
| CVE-2018-1120 | By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w) or any other program which makes a read() call to the… | EXPLOITMEDIUM 5.3EPSS 7.20% | 20 June 2018 |
| CVE-2018-12519 | The vulnerability allows a remote attacker to upload any malicious file to a Node.js application. | EXPLOITHIGH 8.8EPSS 7.76% | 19 June 2018 |
| CVE-2018-12293 | The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer… | EXPLOITHIGH 8.8EPSS 10.4% | 19 June 2018 |
| CVE-2018-11526 | The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. | EXPLOITHIGH 7.8EPSS 5.14% | 19 June 2018 |
| CVE-2018-11525 | The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection. | EXPLOITHIGH 7.8EPSS 5.14% | 19 June 2018 |
| CVE-2018-9022 | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file. | EXPLOIT ✓CRITICAL 9.8EPSS 12.8% | 18 June 2018 |
| CVE-2018-9021 | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests. | EXPLOIT ✓CRITICAL 9.8EPSS 9.61% | 18 June 2018 |
| CVE-2015-4664 | An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands. | EXPLOITCRITICAL 9.8EPSS 20.6% | 18 June 2018 |
| CVE-2018-12525 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. | EXPLOITMEDIUM 5.3EPSS 7.13% | 18 June 2018 |
| CVE-2018-12524 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. | EXPLOITMEDIUM 5.3EPSS 7.13% | 18 June 2018 |
| CVE-2018-12523 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. | EXPLOITMEDIUM 5.3EPSS 7.13% | 18 June 2018 |
| CVE-2018-12522 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. | EXPLOITMEDIUM 5.3EPSS 7.13% | 18 June 2018 |
| CVE-2018-10969 | SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid. | EXPLOITCRITICAL 9.8EPSS 5.26% | 17 June 2018 |
| CVE-2018-12326 | Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. | EXPLOITHIGH 8.4EPSS 2.68% | 17 June 2018 |
| CVE-2018-12453 | Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream. | EXPLOITHIGH 7.5EPSS 23.9% | 16 June 2018 |
| CVE-2018-5756 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to… | EXPLOITMEDIUM 4.3EPSS 5.59% | 16 June 2018 |
| CVE-2018-5755 | Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.x before 7.8.2-rev4, 7.8.3 before 7.8.3-rev5, and 7.8.4 before 7.8.4-rev4 allows remote attackers to read arbitrary files via a full… | EXPLOITMEDIUM 5.5EPSS 7.90% | 16 June 2018 |
| CVE-2018-5754 | Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to… | EXPLOITMEDIUM 5.4EPSS 2.98% | 16 June 2018 |
| CVE-2018-5753 | The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev20 allows remote attackers to spoof the origin of e-mails via unicode characters in the "personal part"… | EXPLOITMEDIUM 6.5EPSS 8.28% | 16 June 2018 |
| CVE-2018-5752 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving… | EXPLOITHIGH 8.8EPSS 4.56% | 16 June 2018 |
| CVE-2018-5751 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote authenticated users to obtain sensitive information about external guest users via… | EXPLOITMEDIUM 6.5EPSS 9.12% | 16 June 2018 |
| CVE-2017-17062 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes by leveraging improper privilege… | EXPLOITMEDIUM 6.5EPSS 3.61% | 16 June 2018 |
| CVE-2018-6671 | Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially… | EXPLOITMEDIUM 6.5EPSS 2.58% | 15 June 2018 |
| CVE-2018-12114 | Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts. | EXPLOITHIGH 8.8EPSS 2.94% | 14 June 2018 |
| CVE-2018-8229 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | EXPLOIT ✓HIGH 7.5EPSS 71.0% | 14 June 2018 |
| CVE-2018-8214 | An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10… | EXPLOIT ✓HIGH 7.0EPSS 3.31% | 14 June 2018 |
| CVE-2018-8208 | An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10… | EXPLOIT ✓HIGH 7.0EPSS 3.15% | 14 June 2018 |
| CVE-2018-0982 | An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | EXPLOIT ✓HIGH 7.0EPSS 2.57% | 14 June 2018 |
| CVE-2018-1121 | procps-ng, procps is vulnerable to a process hiding through race condition. | EXPLOITMEDIUM 5.9EPSS 4.19% | 13 June 2018 |
| CVE-2018-12292 | A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3. | EXPLOITCRITICAL 9.8EPSS 9.07% | 13 June 2018 |
| CVE-2018-12254 | router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI. | EXPLOITHIGH 8.8EPSS 2.58% | 12 June 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.