Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 64 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-9038 | Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request. | EXPLOITMEDIUM 6.5EPSS 9.30% | 10 April 2018 |
| CVE-2018-8772 | Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen. | EXPLOITMEDIUM 6.1EPSS 1.79% | 10 April 2018 |
| CVE-2014-1889 | The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check. | EXPLOITMEDIUM 6.5EPSS 10.4% | 10 April 2018 |
| CVE-2018-9926 | There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add. | EXPLOITHIGH 8.8EPSS 2.93% | 10 April 2018 |
| CVE-2018-1217 | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote… | EXPLOITCRITICAL 9.8EPSS 50.9% | 9 April 2018 |
| CVE-2018-9857 | PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen). | EXPLOIT ✓MEDIUM 6.1EPSS 2.15% | 9 April 2018 |
| CVE-2018-9844 | The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS. | EXPLOITMEDIUM 6.1EPSS 3.64% | 7 April 2018 |
| CVE-2018-9233 | Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware… | EXPLOITHIGH 7.8EPSS 1.65% | 5 April 2018 |
| CVE-2018-4863 | Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key. | EXPLOITMEDIUM 5.5EPSS 1.18% | 5 April 2018 |
| CVE-2016-8380 | The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication. | EXPLOITHIGH 7.3EPSS 10.9% | 5 April 2018 |
| CVE-2016-8371 | The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled. | EXPLOITHIGH 7.3EPSS 10.9% | 5 April 2018 |
| CVE-2016-8366 | Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. | EXPLOITHIGH 7.3EPSS 5.66% | 5 April 2018 |
| CVE-2018-9126 | The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI. | EXPLOITCRITICAL 9.8EPSS 48.9% | 4 April 2018 |
| CVE-2018-9115 | An attacker can freeze the Situational Layer, which means that the Situational Picture is no longer updated. | EXPLOITMEDIUM 5.3EPSS 5.79% | 4 April 2018 |
| CVE-2018-9035 | CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form. | EXPLOITCRITICAL 9.6EPSS 7.30% | 4 April 2018 |
| CVE-2018-9034 | Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter. | EXPLOITMEDIUM 5.4EPSS 1.90% | 4 April 2018 |
| CVE-2018-8719 | For example, these files are indexed by Google and allows for attackers to possibly find sensitive information. | EXPLOITMEDIUM 5.3EPSS 15.6% | 4 April 2018 |
| CVE-2018-0986 | A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This… | EXPLOIT ✓HIGH 8.8EPSS 63.3% | 4 April 2018 |
| CVE-2017-13262 | In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. | EXPLOIT ×2MEDIUM 6.5EPSS 8.02% | 4 April 2018 |
| CVE-2017-13261 | In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. | EXPLOIT ×2HIGH 7.5EPSS 7.15% | 4 April 2018 |
| CVE-2017-13260 | In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. | EXPLOIT ×2HIGH 7.5EPSS 7.29% | 4 April 2018 |
| CVE-2017-13258 | In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. | EXPLOIT ×2HIGH 7.5EPSS 7.12% | 4 April 2018 |
| CVE-2017-13253 | In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. | EXPLOITHIGH 7.8EPSS 2.81% | 4 April 2018 |
| CVE-2018-9248 | FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header. | EXPLOITCRITICAL 9.8EPSS 14.5% | 4 April 2018 |
| CVE-2018-9205 | Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. | EXPLOITHIGH 7.5EPSS 55.1% | 4 April 2018 |
| CVE-2018-8814 | Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settings by crafting a malicious request. | EXPLOITMEDIUM 6.5EPSS 2.99% | 4 April 2018 |
| CVE-2018-8813 | Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL. | EXPLOITMEDIUM 4.8EPSS 3.22% | 4 April 2018 |
| CVE-2018-9238 | proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter. | EXPLOITMEDIUM 6.1EPSS 2.15% | 4 April 2018 |
| CVE-2018-9237 | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field. | EXPLOITMEDIUM 5.4EPSS 1.78% | 4 April 2018 |
| CVE-2018-9236 | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field. | EXPLOITMEDIUM 5.4EPSS 1.78% | 4 April 2018 |
| CVE-2018-9235 | iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. | EXPLOITMEDIUM 6.1EPSS 2.47% | 4 April 2018 |
| CVE-2017-18256 | Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaScript code, because window dialogs are mishandled. | EXPLOITMEDIUM 6.5EPSS 4.84% | 4 April 2018 |
| CVE-2016-10718 | Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service. | EXPLOITHIGH 7.5EPSS 12.2% | 4 April 2018 |
| CVE-2018-0492 | Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation. | EXPLOITHIGH 7.0EPSS 1.56% | 3 April 2018 |
| CVE-2018-4139 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 4.40% | 3 April 2018 |
| CVE-2018-4121 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 13.1% | 3 April 2018 |
| CVE-2018-4090 | It allows attackers to bypass intended memory-read restrictions via a crafted app. | EXPLOIT ✓MEDIUM 5.5EPSS 3.62% | 3 April 2018 |
| CVE-2018-4089 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 6.41% | 3 April 2018 |
| CVE-2018-4087 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 7.08% | 3 April 2018 |
| CVE-2018-4083 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 3.71% | 3 April 2018 |
| CVE-2017-7005 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 6.54% | 3 April 2018 |
| CVE-2017-7004 | A race condition allows attackers to bypass intended entitlement restrictions for sending XPC messages via a crafted app. | EXPLOIT ✓HIGH 7.0EPSS 2.76% | 3 April 2018 |
| CVE-2018-9183 | The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS. | EXPLOITMEDIUM 5.4EPSS 2.19% | 2 April 2018 |
| CVE-2018-1038 | The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." | EXPLOITHIGH 7.8EPSS 8.51% | 2 April 2018 |
| CVE-2018-9163 | A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field… | EXPLOITMEDIUM 5.4EPSS 4.80% | 2 April 2018 |
| CVE-2018-9173 | Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter. | EXPLOITMEDIUM 6.1EPSS 2.36% | 2 April 2018 |
| CVE-2018-9172 | The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. | EXPLOITMEDIUM 5.4EPSS 3.07% | 1 April 2018 |
| CVE-2018-6849 | In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request. | EXPLOITMEDIUM 4.3EPSS 28.7% | 1 April 2018 |
| CVE-2018-9128 | DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068. | EXPLOIT ×2HIGH 7.8EPSS 4.73% | 1 April 2018 |
| CVE-2018-8908 | The application's add user functionality suffers from CSRF. | EXPLOITHIGH 8.8EPSS 2.23% | 31 March 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.