Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 62 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-8134 | An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1,… | EXPLOIT ✓HIGH 7.0EPSS 2.99% | 9 May 2018 |
| CVE-2018-8133 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | EXPLOIT ✓HIGH 7.5EPSS 50.9% | 9 May 2018 |
| CVE-2018-8120 | Microsoft Win32k Privilege Escalation Vulnerability | KEVEXPLOIT ✓HIGH 7.0EPSS 73.4% | 9 May 2018 |
| CVE-2018-0953 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | EXPLOIT ✓HIGH 7.5EPSS 66.8% | 9 May 2018 |
| CVE-2018-0946 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | EXPLOIT ✓HIGH 7.5EPSS 51.8% | 9 May 2018 |
| CVE-2018-0824 | Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability | KEVEXPLOITHIGH 8.8EPSS 73.2% | 9 May 2018 |
| CVE-2018-10828 | ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mapping Object" section. | EXPLOITMEDIUM 5.5EPSS 1.35% | 9 May 2018 |
| CVE-2018-10830 | In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x002220e0. | EXPLOITHIGH 7.8EPSS 0.98% | 9 May 2018 |
| CVE-2015-1503 | Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. | EXPLOITHIGH 7.5EPSS 57.6% | 8 May 2018 |
| CVE-2018-8897 | A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are… | EXPLOIT ×2 ✓HIGH 7.8EPSS 18.5% | 8 May 2018 |
| CVE-2018-1247 | RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. | EXPLOITHIGH 7.1EPSS 16.0% | 8 May 2018 |
| CVE-2018-10809 | In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222040. | EXPLOITHIGH 7.8EPSS 1.11% | 8 May 2018 |
| CVE-2018-0494 | GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line. | EXPLOITMEDIUM 6.5EPSS 16.8% | 6 May 2018 |
| CVE-2018-10757 | CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt. | EXPLOITCRITICAL 9.8EPSS 5.50% | 5 May 2018 |
| CVE-2018-10752 | The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action. | EXPLOITMEDIUM 4.8EPSS 1.84% | 5 May 2018 |
| CVE-2018-10562 | Dasan GPON Routers Command Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.9% | 4 May 2018 |
| CVE-2018-10561 | Dasan GPON Routers Authentication Bypass Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 92.9% | 4 May 2018 |
| CVE-2018-10718 | Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets. | EXPLOITCRITICAL 10.0EPSS 30.2% | 3 May 2018 |
| CVE-2018-10577 | File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root. | EXPLOITHIGH 8.8EPSS 6.49% | 2 May 2018 |
| CVE-2018-9302 | SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. | EXPLOITCRITICAL 9.1EPSS 8.51% | 2 May 2018 |
| CVE-2018-10260 | A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user. | EXPLOITHIGH 8.8EPSS 5.64% | 1 May 2018 |
| CVE-2018-10259 | An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user. | EXPLOITMEDIUM 5.4EPSS 1.58% | 1 May 2018 |
| CVE-2018-10258 | A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | EXPLOITHIGH 8.8EPSS 7.31% | 1 May 2018 |
| CVE-2018-10257 | A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | EXPLOITHIGH 8.8EPSS 4.25% | 1 May 2018 |
| CVE-2018-10256 | A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query. | EXPLOITHIGH 8.8EPSS 2.53% | 1 May 2018 |
| CVE-2018-10255 | A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | EXPLOITHIGH 8.8EPSS 6.96% | 1 May 2018 |
| CVE-2016-10036 | Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary… | EXPLOITCRITICAL 9.8EPSS 25.6% | 1 May 2018 |
| CVE-2018-10583 | An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within… | EXPLOITHIGH 7.5EPSS 78.3% | 1 May 2018 |
| CVE-2018-10365 | An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. | EXPLOITMEDIUM 5.4EPSS 1.52% | 1 May 2018 |
| CVE-2017-17020 | On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before 1.15.01, command injection in alphapd (binary responsible for running the camera's web server)… | EXPLOITHIGH 8.8EPSS 14.8% | 1 May 2018 |
| CVE-2018-10371 | A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web browser via a page title. | EXPLOITMEDIUM 6.1EPSS 6.18% | 1 May 2018 |
| CVE-2018-10576 | Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user). | EXPLOITHIGH 7.8EPSS 1.50% | 30 April 2018 |
| CVE-2018-10575 | Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false. | EXPLOITCRITICAL 9.8EPSS 8.54% | 30 April 2018 |
| CVE-2018-5234 | The Norton Core router prior to v237 may be susceptible to a command injection exploit. | EXPLOITHIGH 8.0EPSS 16.4% | 30 April 2018 |
| CVE-2018-10517 | In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element. | EXPLOITHIGH 7.2EPSS 11.8% | 27 April 2018 |
| CVE-2018-7669 | The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from the host Operating System using a sitecore/shell/default.aspx?xmlcontrol=LogViewerDetails&file= URI. | EXPLOITHIGH 7.5EPSS 17.2% | 27 April 2018 |
| CVE-2018-10504 | The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. | EXPLOIT ✓HIGH 7.8EPSS 4.51% | 27 April 2018 |
| CVE-2018-7465 | An XSS issue was discovered in VirtueMart before 3.2.14. | EXPLOITMEDIUM 5.4EPSS 2.29% | 26 April 2018 |
| CVE-2018-1418 | IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. | EXPLOIT ✓HIGH 8.8EPSS 51.4% | 26 April 2018 |
| CVE-2018-1335 | From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. | EXPLOIT ×2 ✓HIGH 8.1EPSS 93.8% | 25 April 2018 |
| CVE-2018-8716 | WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers. | EXPLOITMEDIUM 5.4EPSS 38.7% | 25 April 2018 |
| CVE-2018-10366 | XSS exists in the name field. | EXPLOITMEDIUM 6.1EPSS 2.47% | 25 April 2018 |
| CVE-2018-10310 | A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for WordPress that allows the execution of arbitrary HTML/script code in the context of a victim's browser. | EXPLOITMEDIUM 5.4EPSS 3.81% | 25 April 2018 |
| CVE-2018-9131 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 24 April 2018 |
| CVE-2016-9587 | Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. | EXPLOITHIGH 8.1EPSS 17.4% | 24 April 2018 |
| CVE-2018-10321 | Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings. | EXPLOITMEDIUM 4.8EPSS 1.88% | 24 April 2018 |
| CVE-2018-10313 | WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI. | EXPLOITMEDIUM 5.4EPSS 2.16% | 24 April 2018 |
| CVE-2018-10312 | index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member. | EXPLOITHIGH 8.8EPSS 2.39% | 24 April 2018 |
| CVE-2018-10311 | A vulnerability was discovered in WUZHI CMS 4.1.0. | EXPLOITMEDIUM 6.1EPSS 2.49% | 24 April 2018 |
| CVE-2018-10309 | The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS. | EXPLOITMEDIUM 5.4EPSS 2.75% | 24 April 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.