Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 61 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-10751 | A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. | EXPLOIT ✓MEDIUM 5.3EPSS 8.64% | 29 May 2018 |
| CVE-2018-1235 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. | EXPLOITCRITICAL 9.8EPSS 42.9% | 29 May 2018 |
| CVE-2018-11535 | The parameter "my_item_search" in users.php is exploitable using SQL injection. | EXPLOITCRITICAL 9.8EPSS 3.24% | 29 May 2018 |
| CVE-2018-11532 | An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field. | EXPLOITMEDIUM 6.1EPSS 2.44% | 29 May 2018 |
| CVE-2018-11523 | upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files. | EXPLOITCRITICAL 9.8EPSS 9.80% | 29 May 2018 |
| CVE-2018-11512 | Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by… | EXPLOITMEDIUM 4.8EPSS 2.18% | 28 May 2018 |
| CVE-2018-11508 | The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex. | EXPLOITMEDIUM 5.5EPSS 1.72% | 28 May 2018 |
| CVE-2018-6411 | If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection. | EXPLOIT ✓CRITICAL 9.8EPSS 5.81% | 26 May 2018 |
| CVE-2018-6410 | There is a download.php SQL injection via the q parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 4.91% | 26 May 2018 |
| CVE-2018-6409 | Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter. | EXPLOIT ✓MEDIUM 5.3EPSS 14.6% | 26 May 2018 |
| CVE-2018-11505 | The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output. | EXPLOITHIGH 7.5EPSS 9.05% | 26 May 2018 |
| CVE-2018-11479 | Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService named pipe endpoint that allows the Windscribe VPN process to connect and execute an OpenVPN process or other processes (like taskkill, etc.). | EXPLOIT ✓HIGH 7.8EPSS 9.90% | 25 May 2018 |
| CVE-2018-11445 | A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. | EXPLOITHIGH 8.8EPSS 2.40% | 25 May 2018 |
| CVE-2018-11444 | A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0. | EXPLOITCRITICAL 9.8EPSS 3.24% | 25 May 2018 |
| CVE-2018-11443 | The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0. | EXPLOITMEDIUM 6.1EPSS 2.73% | 25 May 2018 |
| CVE-2018-11442 | A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation. | EXPLOITHIGH 8.8EPSS 2.40% | 25 May 2018 |
| CVE-2018-1133 | A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection. | EXPLOITHIGH 8.8EPSS 31.9% | 25 May 2018 |
| CVE-2018-11415 | SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. | EXPLOITMEDIUM 6.1EPSS 8.30% | 24 May 2018 |
| CVE-2018-11412 | In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a… | EXPLOITMEDIUM 5.9EPSS 16.2% | 24 May 2018 |
| CVE-2018-11332 | Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the… | EXPLOITMEDIUM 4.8EPSS 1.88% | 24 May 2018 |
| CVE-2018-11404 | DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter. | EXPLOITMEDIUM 6.1EPSS 2.34% | 24 May 2018 |
| CVE-2018-11403 | DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter. | EXPLOITMEDIUM 5.4EPSS 1.80% | 24 May 2018 |
| CVE-2018-10653 | There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | EXPLOITCRITICAL 9.8EPSS 6.80% | 23 May 2018 |
| CVE-2018-8898 | A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read,… | EXPLOITCRITICAL 9.8EPSS 12.8% | 23 May 2018 |
| CVE-2018-1123 | procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. | EXPLOITHIGH 7.5EPSS 9.08% | 23 May 2018 |
| CVE-2018-1122 | procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. | EXPLOITHIGH 7.0EPSS 1.30% | 23 May 2018 |
| CVE-2018-1124 | procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. | EXPLOITHIGH 7.8EPSS 1.94% | 23 May 2018 |
| CVE-2018-10094 | SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes. | EXPLOIT ✓CRITICAL 9.8EPSS 70.7% | 22 May 2018 |
| CVE-2018-3639 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a… | EXPLOIT ✓MEDIUM 5.5EPSS 60.6% | 22 May 2018 |
| CVE-2018-11339 | An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment. | EXPLOITMEDIUM 6.1EPSS 3.98% | 22 May 2018 |
| CVE-2018-11311 | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials. | EXPLOITCRITICAL 9.1EPSS 15.7% | 20 May 2018 |
| CVE-2018-11242 | The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files. | EXPLOITMEDIUM 6.5EPSS 4.08% | 20 May 2018 |
| CVE-2018-4937 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. | EXPLOIT ✓HIGH 8.8EPSS 26.2% | 19 May 2018 |
| CVE-2018-4936 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. | EXPLOIT ✓MEDIUM 6.5EPSS 28.7% | 19 May 2018 |
| CVE-2018-4935 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. | EXPLOIT ✓HIGH 8.8EPSS 26.2% | 19 May 2018 |
| CVE-2018-4934 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. | EXPLOIT ✓MEDIUM 6.5EPSS 23.2% | 19 May 2018 |
| CVE-2018-1111 | DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. | EXPLOIT ×2 ✓HIGH 7.5EPSS 98.0% | 17 May 2018 |
| CVE-2018-9958 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. | EXPLOIT ×3 ✓HIGH 8.8EPSS 62.9% | 17 May 2018 |
| CVE-2018-9948 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 63.7% | 17 May 2018 |
| CVE-2018-10123 | p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via requests on TCP port 9100. | EXPLOITHIGH 8.8EPSS 10.8% | 16 May 2018 |
| CVE-2018-11094 | An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. | EXPLOITCRITICAL 9.8EPSS 34.4% | 15 May 2018 |
| CVE-2018-11034 | In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x8000200D. | EXPLOITHIGH 7.8EPSS 0.98% | 14 May 2018 |
| CVE-2018-6023 | Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc. | EXPLOITHIGH 8.8EPSS 2.31% | 11 May 2018 |
| CVE-2018-10832 | ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. | EXPLOITMEDIUM 5.5EPSS 5.82% | 11 May 2018 |
| CVE-2018-10580 | The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field. | EXPLOITMEDIUM 5.4EPSS 1.61% | 11 May 2018 |
| CVE-2018-10655 | DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH). | EXPLOITHIGH 7.8EPSS 16.2% | 10 May 2018 |
| CVE-2018-10314 | Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List… | EXPLOITMEDIUM 5.4EPSS 1.80% | 10 May 2018 |
| CVE-2018-8174 | Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability | KEVEXPLOITHIGH 7.5EPSS 88.3% | 9 May 2018 |
| CVE-2018-8145 | An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory… | EXPLOIT ✓HIGH 7.5EPSS 67.2% | 9 May 2018 |
| CVE-2018-8139 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | EXPLOIT ✓HIGH 7.5EPSS 66.8% | 9 May 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.