SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 63 of 501

CVESummaryPriorityPublished
CVE-2018-8880Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which leads to internal network information disclosure.EXPLOITHIGH 7.5EPSS 13.6%23 April 2018
CVE-2018-9245The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.EXPLOITCRITICAL 9.8EPSS 3.98%22 April 2018
CVE-2018-10286The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests.EXPLOITHIGH 8.8EPSS 6.41%22 April 2018
CVE-2018-10285Since the app does not use any sort of session ID, an attacker might bypass authentication.EXPLOITCRITICAL 9.8EPSS 12.8%22 April 2018
CVE-2018-10253Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.EXPLOITHIGH 7.5EPSS 7.36%21 April 2018
CVE-2018-9059Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code via a malicious login request to forum.ghp.EXPLOIT ×2CRITICAL 9.8EPSS 77.6%20 April 2018
CVE-2018-7747Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or…EXPLOITMEDIUM 4.8EPSS 4.49%20 April 2018
CVE-2018-10079Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data by updating (1) config.xml or (2) servers.xml.EXPLOITHIGH 7.8EPSS 0.77%20 April 2018
CVE-2018-10078Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a server description.EXPLOITMEDIUM 4.8EPSS 2.03%20 April 2018
CVE-2018-10077XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files via crafted XML data.EXPLOITMEDIUM 4.9EPSS 8.13%20 April 2018
CVE-2018-10201It is possible to read arbitrary files outside the root directory of the web server.EXPLOITHIGH 7.5EPSS 44.4%20 April 2018
CVE-2018-10188phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.EXPLOITHIGH 8.8EPSS 4.13%19 April 2018
CVE-2018-9137Open-AudIT before 2.2 has CSV Injection.EXPLOITMEDIUM 6.8EPSS 2.74%19 April 2018
CVE-2018-2791Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).EXPLOITHIGH 8.2EPSS 38.8%19 April 2018
CVE-2018-2628Oracle WebLogic Server Unspecified VulnerabilityKEVEXPLOIT ×3CRITICAL 9.8EPSS 99.4%19 April 2018
CVE-2018-10110D-Link DIR-615 T1 devices allow XSS via the Add User feature.EXPLOITMEDIUM 4.8EPSS 3.43%18 April 2018
CVE-2018-8831A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist.EXPLOITMEDIUM 6.1EPSS 52.7%18 April 2018
CVE-2015-9222In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820,…EXPLOITHIGH 7.5EPSS 4.35%18 April 2018
CVE-2018-8736A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.EXPLOIT ×2HIGH 8.8EPSS 46.3%18 April 2018
CVE-2018-8735Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.EXPLOIT ×2HIGH 8.8EPSS 63.6%18 April 2018
CVE-2018-8734SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.EXPLOIT ×2CRITICAL 9.8EPSS 52.6%18 April 2018
CVE-2018-8733Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.EXPLOIT ×2CRITICAL 9.8EPSS 27.0%18 April 2018
CVE-2018-5430TIBCO JasperReports Server Information Disclosure VulnerabilityKEVEXPLOITHIGH 8.8EPSS 49.6%17 April 2018
CVE-2017-6020Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are not calling for absolute path sequences outside of their privilege level.EXPLOITMEDIUM 5.3EPSS 8.62%17 April 2018
CVE-2018-10070A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on port 21 that begins with many '\0' characters, preventing the affected…EXPLOITHIGH 7.5EPSS 12.7%16 April 2018
CVE-2018-10118Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI, related to plugins/box/pages/pages.admin.php.EXPLOITMEDIUM 4.8EPSS 2.79%16 April 2018
CVE-2018-10109Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a new page in the blog catalog.EXPLOITMEDIUM 4.8EPSS 2.12%16 April 2018
CVE-2014-2069Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to FileManager.aspx.EXPLOITHIGH 7.5EPSS 15.7%16 April 2018
CVE-2018-6546plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes code at a user-defined (local or SMB) path as SYSTEM when the execute_installer parameter is used in an…EXPLOITCRITICAL 9.8EPSS 17.5%13 April 2018
CVE-2017-0358Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges.EXPLOIT ×2HIGH 7.8EPSS 2.23%13 April 2018
CVE-2018-5511On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.EXPLOITHIGH 7.2EPSS 14.5%13 April 2018
CVE-2018-10063The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file.EXPLOITHIGH 7.8EPSS 9.23%12 April 2018
CVE-2018-10068The jDownloads extension before 3.2.59 for Joomla! has XSS.EXPLOITMEDIUM 6.1EPSS 3.93%12 April 2018
CVE-2018-9843The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialized .NET object in an Authorization HTTP header.EXPLOITCRITICAL 9.8EPSS 17.0%12 April 2018
CVE-2018-9842CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message.EXPLOIT ×3MEDIUM 5.3EPSS 16.2%12 April 2018
CVE-2018-9155Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the…EXPLOITMEDIUM 5.4EPSS 1.14%12 April 2018
CVE-2018-9118exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.EXPLOITHIGH 7.5EPSS 46.9%12 April 2018
CVE-2018-0980A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.EXPLOITHIGH 7.5EPSS 66.8%12 April 2018
CVE-2018-0975An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure…EXPLOITMEDIUM 5.5EPSS 2.98%12 April 2018
CVE-2018-0974An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure…EXPLOITMEDIUM 5.5EPSS 3.51%12 April 2018
CVE-2018-0973An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure…EXPLOITMEDIUM 5.5EPSS 3.51%12 April 2018
CVE-2018-0972An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure…EXPLOITMEDIUM 5.5EPSS 3.51%12 April 2018
CVE-2018-0971An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure…EXPLOITMEDIUM 5.5EPSS 3.51%12 April 2018
CVE-2018-0970An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure…EXPLOITMEDIUM 5.5EPSS 3.51%12 April 2018
CVE-2018-0969An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure…EXPLOITMEDIUM 5.5EPSS 3.51%12 April 2018
CVE-2018-0968An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure…EXPLOITMEDIUM 5.5EPSS 3.62%12 April 2018
CVE-2018-0966A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.EXPLOITLOW 3.3EPSS 2.31%12 April 2018
CVE-2017-14459An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current).EXPLOITCRITICAL 9.8EPSS 12.6%11 April 2018
CVE-2016-10258Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles.EXPLOITMEDIUM 6.8EPSS 4.84%11 April 2018
CVE-2018-9995TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass…EXPLOITCRITICAL 9.8EPSS 82.3%10 April 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.