SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 61 of 501

CVESummaryPriorityPublished
CVE-2018-10751A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload.EXPLOITMEDIUM 5.3EPSS 8.64%29 May 2018
CVE-2018-1235Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability.EXPLOITCRITICAL 9.8EPSS 42.9%29 May 2018
CVE-2018-11535The parameter "my_item_search" in users.php is exploitable using SQL injection.EXPLOITCRITICAL 9.8EPSS 3.24%29 May 2018
CVE-2018-11532An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.EXPLOITMEDIUM 6.1EPSS 2.44%29 May 2018
CVE-2018-11523upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.EXPLOITCRITICAL 9.8EPSS 9.80%29 May 2018
CVE-2018-11512Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by…EXPLOITMEDIUM 4.8EPSS 2.18%28 May 2018
CVE-2018-11508The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.EXPLOITMEDIUM 5.5EPSS 1.72%28 May 2018
CVE-2018-6411If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.EXPLOITCRITICAL 9.8EPSS 5.81%26 May 2018
CVE-2018-6410There is a download.php SQL injection via the q parameter.EXPLOITCRITICAL 9.8EPSS 4.91%26 May 2018
CVE-2018-6409Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.EXPLOITMEDIUM 5.3EPSS 14.6%26 May 2018
CVE-2018-11505The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.EXPLOITHIGH 7.5EPSS 9.05%26 May 2018
CVE-2018-11479Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService named pipe endpoint that allows the Windscribe VPN process to connect and execute an OpenVPN process or other processes (like taskkill, etc.).EXPLOITHIGH 7.8EPSS 9.90%25 May 2018
CVE-2018-11445A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0.EXPLOITHIGH 8.8EPSS 2.40%25 May 2018
CVE-2018-11444A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.EXPLOITCRITICAL 9.8EPSS 3.24%25 May 2018
CVE-2018-11443The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.EXPLOITMEDIUM 6.1EPSS 2.73%25 May 2018
CVE-2018-11442A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation.EXPLOITHIGH 8.8EPSS 2.40%25 May 2018
CVE-2018-1133A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.EXPLOITHIGH 8.8EPSS 31.9%25 May 2018
CVE-2018-11415SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs.EXPLOITMEDIUM 6.1EPSS 8.30%24 May 2018
CVE-2018-11412In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a…EXPLOITMEDIUM 5.9EPSS 16.2%24 May 2018
CVE-2018-11332Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the…EXPLOITMEDIUM 4.8EPSS 1.88%24 May 2018
CVE-2018-11404DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.EXPLOITMEDIUM 6.1EPSS 2.34%24 May 2018
CVE-2018-11403DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.EXPLOITMEDIUM 5.4EPSS 1.80%24 May 2018
CVE-2018-10653There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.EXPLOITCRITICAL 9.8EPSS 6.80%23 May 2018
CVE-2018-8898A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read,…EXPLOITCRITICAL 9.8EPSS 12.8%23 May 2018
CVE-2018-1123procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow.EXPLOITHIGH 7.5EPSS 9.08%23 May 2018
CVE-2018-1122procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top.EXPLOITHIGH 7.0EPSS 1.30%23 May 2018
CVE-2018-1124procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function.EXPLOITHIGH 7.8EPSS 1.94%23 May 2018
CVE-2018-10094SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.EXPLOITCRITICAL 9.8EPSS 70.7%22 May 2018
CVE-2018-3639Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a…EXPLOITMEDIUM 5.5EPSS 60.6%22 May 2018
CVE-2018-11339An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.EXPLOITMEDIUM 6.1EPSS 3.98%22 May 2018
CVE-2018-11311A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.EXPLOITCRITICAL 9.1EPSS 15.7%20 May 2018
CVE-2018-11242The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.EXPLOITMEDIUM 6.5EPSS 4.08%20 May 2018
CVE-2018-4937Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability.EXPLOITHIGH 8.8EPSS 26.2%19 May 2018
CVE-2018-4936Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability.EXPLOITMEDIUM 6.5EPSS 28.7%19 May 2018
CVE-2018-4935Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability.EXPLOITHIGH 8.8EPSS 26.2%19 May 2018
CVE-2018-4934Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability.EXPLOITMEDIUM 6.5EPSS 23.2%19 May 2018
CVE-2018-1111DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client.EXPLOIT ×2HIGH 7.5EPSS 98.0%17 May 2018
CVE-2018-9958This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049.EXPLOIT ×3HIGH 8.8EPSS 62.9%17 May 2018
CVE-2018-9948This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935.EXPLOIT ×2MEDIUM 6.5EPSS 63.7%17 May 2018
CVE-2018-10123p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via requests on TCP port 9100.EXPLOITHIGH 8.8EPSS 10.8%16 May 2018
CVE-2018-11094An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication.EXPLOITCRITICAL 9.8EPSS 34.4%15 May 2018
CVE-2018-11034In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x8000200D.EXPLOITHIGH 7.8EPSS 0.98%14 May 2018
CVE-2018-6023Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc.EXPLOITHIGH 8.8EPSS 2.31%11 May 2018
CVE-2018-10832ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack.EXPLOITMEDIUM 5.5EPSS 5.82%11 May 2018
CVE-2018-10580The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.EXPLOITMEDIUM 5.4EPSS 1.61%11 May 2018
CVE-2018-10655DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).EXPLOITHIGH 7.8EPSS 16.2%10 May 2018
CVE-2018-10314Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List…EXPLOITMEDIUM 5.4EPSS 1.80%10 May 2018
CVE-2018-8174Microsoft Windows VBScript Engine Out-of-Bounds Write VulnerabilityKEVEXPLOITHIGH 7.5EPSS 88.3%9 May 2018
CVE-2018-8145An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory…EXPLOITHIGH 7.5EPSS 67.2%9 May 2018
CVE-2018-8139A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.EXPLOITHIGH 7.5EPSS 66.8%9 May 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.