SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 62 of 501

CVESummaryPriorityPublished
CVE-2018-8134An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1,…EXPLOITHIGH 7.0EPSS 2.99%9 May 2018
CVE-2018-8133A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.EXPLOITHIGH 7.5EPSS 50.9%9 May 2018
CVE-2018-8120Microsoft Win32k Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.0EPSS 73.4%9 May 2018
CVE-2018-0953A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.EXPLOITHIGH 7.5EPSS 66.8%9 May 2018
CVE-2018-0946A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.EXPLOITHIGH 7.5EPSS 51.8%9 May 2018
CVE-2018-0824Microsoft COM for Windows Deserialization of Untrusted Data VulnerabilityKEVEXPLOITHIGH 8.8EPSS 73.2%9 May 2018
CVE-2018-10828ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mapping Object" section.EXPLOITMEDIUM 5.5EPSS 1.35%9 May 2018
CVE-2018-10830In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x002220e0.EXPLOITHIGH 7.8EPSS 0.98%9 May 2018
CVE-2015-1503Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) ..EXPLOITHIGH 7.5EPSS 57.6%8 May 2018
CVE-2018-8897A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are…EXPLOIT ×2HIGH 7.8EPSS 18.5%8 May 2018
CVE-2018-1247RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability.EXPLOITHIGH 7.1EPSS 16.0%8 May 2018
CVE-2018-10809In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222040.EXPLOITHIGH 7.8EPSS 1.11%8 May 2018
CVE-2018-0494GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.EXPLOITMEDIUM 6.5EPSS 16.8%6 May 2018
CVE-2018-10757CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.EXPLOITCRITICAL 9.8EPSS 5.50%5 May 2018
CVE-2018-10752The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.EXPLOITMEDIUM 4.8EPSS 1.84%5 May 2018
CVE-2018-10562Dasan GPON Routers Command Injection VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.9%4 May 2018
CVE-2018-10561Dasan GPON Routers Authentication Bypass VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 92.9%4 May 2018
CVE-2018-10718Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets.EXPLOITCRITICAL 10.0EPSS 30.2%3 May 2018
CVE-2018-10577File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root.EXPLOITHIGH 8.8EPSS 6.49%2 May 2018
CVE-2018-9302SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter.EXPLOITCRITICAL 9.1EPSS 8.51%2 May 2018
CVE-2018-10260A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.EXPLOITHIGH 8.8EPSS 5.64%1 May 2018
CVE-2018-10259An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.EXPLOITMEDIUM 5.4EPSS 1.58%1 May 2018
CVE-2018-10258A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.EXPLOITHIGH 8.8EPSS 7.31%1 May 2018
CVE-2018-10257A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.EXPLOITHIGH 8.8EPSS 4.25%1 May 2018
CVE-2018-10256A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.EXPLOITHIGH 8.8EPSS 2.53%1 May 2018
CVE-2018-10255A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.EXPLOITHIGH 8.8EPSS 6.96%1 May 2018
CVE-2016-10036Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary…EXPLOITCRITICAL 9.8EPSS 25.6%1 May 2018
CVE-2018-10583An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within…EXPLOITHIGH 7.5EPSS 78.3%1 May 2018
CVE-2018-10365An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB.EXPLOITMEDIUM 5.4EPSS 1.52%1 May 2018
CVE-2017-17020On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before 1.15.01, command injection in alphapd (binary responsible for running the camera's web server)…EXPLOITHIGH 8.8EPSS 14.8%1 May 2018
CVE-2018-10371A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web browser via a page title.EXPLOITMEDIUM 6.1EPSS 6.18%1 May 2018
CVE-2018-10576Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user).EXPLOITHIGH 7.8EPSS 1.50%30 April 2018
CVE-2018-10575Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false.EXPLOITCRITICAL 9.8EPSS 8.54%30 April 2018
CVE-2018-5234The Norton Core router prior to v237 may be susceptible to a command injection exploit.EXPLOITHIGH 8.0EPSS 16.4%30 April 2018
CVE-2018-10517In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.EXPLOITHIGH 7.2EPSS 11.8%27 April 2018
CVE-2018-7669The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from the host Operating System using a sitecore/shell/default.aspx?xmlcontrol=LogViewerDetails&file= URI.EXPLOITHIGH 7.5EPSS 17.2%27 April 2018
CVE-2018-10504The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.EXPLOITHIGH 7.8EPSS 4.51%27 April 2018
CVE-2018-7465An XSS issue was discovered in VirtueMart before 3.2.14.EXPLOITMEDIUM 5.4EPSS 2.29%26 April 2018
CVE-2018-1418IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution.EXPLOITHIGH 8.8EPSS 51.4%26 April 2018
CVE-2018-1335From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server.EXPLOIT ×2HIGH 8.1EPSS 93.8%25 April 2018
CVE-2018-8716WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.EXPLOITMEDIUM 5.4EPSS 38.7%25 April 2018
CVE-2018-10366XSS exists in the name field.EXPLOITMEDIUM 6.1EPSS 2.47%25 April 2018
CVE-2018-10310A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for WordPress that allows the execution of arbitrary HTML/script code in the context of a victim's browser.EXPLOITMEDIUM 5.4EPSS 3.81%25 April 2018
CVE-2018-9131Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —24 April 2018
CVE-2016-9587Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems.EXPLOITHIGH 8.1EPSS 17.4%24 April 2018
CVE-2018-10321Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.EXPLOITMEDIUM 4.8EPSS 1.88%24 April 2018
CVE-2018-10313WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.EXPLOITMEDIUM 5.4EPSS 2.16%24 April 2018
CVE-2018-10312index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.EXPLOITHIGH 8.8EPSS 2.39%24 April 2018
CVE-2018-10311A vulnerability was discovered in WUZHI CMS 4.1.0.EXPLOITMEDIUM 6.1EPSS 2.49%24 April 2018
CVE-2018-10309The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.EXPLOITMEDIUM 5.4EPSS 2.75%24 April 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.