SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 65 of 501

CVESummaryPriorityPublished
CVE-2018-9160SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.EXPLOITCRITICAL 9.8EPSS 75.6%31 March 2018
CVE-2018-7203Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.EXPLOITMEDIUM 6.1EPSS 2.33%30 March 2018
CVE-2018-7171Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a ..EXPLOITHIGH 7.5EPSS 27.9%30 March 2018
CVE-2018-5708An issue was discovered on D-Link DIR-601 B1 2.02NA devices.EXPLOITHIGH 8.0EPSS 5.99%30 March 2018
CVE-2018-7600Drupal Core Remote Code Execution VulnerabilityKEVEXPLOIT ×3CRITICAL 9.8EPSS 100.0%29 March 2018
CVE-2018-0171Cisco IOS and IOS XE Software Smart Install Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.5%28 March 2018
CVE-2018-9107CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.EXPLOITHIGH 8.8EPSS 7.03%28 March 2018
CVE-2018-9106CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export.EXPLOITHIGH 8.8EPSS 6.44%28 March 2018
CVE-2018-9092There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.EXPLOITHIGH 8.8EPSS 2.73%27 March 2018
CVE-2018-8718Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.EXPLOITHIGH 8.0EPSS 6.52%27 March 2018
CVE-2018-9032An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version : 1.02-2.06) devices potentially allows attackers to bypass SharePort Web Access Portal by directly…EXPLOITCRITICAL 9.8EPSS 27.7%27 March 2018
CVE-2018-7658NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exactly 11 bytes.EXPLOITHIGH 7.5EPSS 38.5%26 March 2018
CVE-2018-7543Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.EXPLOITMEDIUM 6.1EPSS 3.35%26 March 2018
CVE-2018-1213Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.2 is affected by a cross-site request forgery vulnerability.EXPLOITHIGH 8.8EPSS 1.93%26 March 2018
CVE-2018-1204Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a path traversal vulnerability in the isi_phone_home tool.EXPLOITMEDIUM 6.7EPSS 2.32%26 March 2018
CVE-2018-1203In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, the tcpdump binary, being run with sudo, may potentially be used by compadmin to execute arbitrary code with root privileges.EXPLOITMEDIUM 6.7EPSS 2.11%26 March 2018
CVE-2018-1202Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the NDMP Page within the OneFS web administration interface.EXPLOITMEDIUM 4.8EPSS 2.13%26 March 2018
CVE-2018-1201Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Job Operations Page within the OneFS web administration…EXPLOITMEDIUM 4.8EPSS 1.83%26 March 2018
CVE-2018-1189Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Antivirus Page within the OneFS web administration interface.EXPLOITMEDIUM 4.8EPSS 27.7%26 March 2018
CVE-2018-1188Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and versions 7.2.1.x is affected by a cross-site scripting vulnerability in the Authorization Providers page within the OneFS web administration interface.EXPLOITMEDIUM 4.8EPSS 1.83%26 March 2018
CVE-2018-1187Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6 is affected by a cross-site scripting vulnerability in the Network Configuration page within the OneFS web administration interface.EXPLOITMEDIUM 4.8EPSS 1.79%26 March 2018
CVE-2018-1186Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface.EXPLOITMEDIUM 4.8EPSS 1.79%26 March 2018
CVE-2018-8979Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.EXPLOITHIGH 8.8EPSS 1.24%25 March 2018
CVE-2018-8817Wampserver before 3.1.3 has CSRF in add_vhost.php.EXPLOITHIGH 8.8EPSS 3.09%25 March 2018
CVE-2018-9010Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page parameter, aka absolute path traversal.EXPLOITHIGH 7.2EPSS 9.70%25 March 2018
CVE-2018-8947rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.EXPLOITHIGH 7.5EPSS 11.0%25 March 2018
CVE-2018-7719Acrolinx Server before 5.2.5 on Windows allows Directory Traversal.EXPLOITHIGH 7.5EPSS 46.9%25 March 2018
CVE-2018-1207Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code.EXPLOITCRITICAL 9.8EPSS 90.1%23 March 2018
CVE-2018-8903Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.EXPLOITMEDIUM 5.4EPSS 1.55%22 March 2018
CVE-2014-4912An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.EXPLOITCRITICAL 9.8EPSS 8.06%22 March 2018
CVE-2014-1665Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.EXPLOITMEDIUM 5.4EPSS 3.03%20 March 2018
CVE-2018-1322An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.EXPLOITMEDIUM 4.9EPSS 19.9%20 March 2018
CVE-2018-1321An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations,…EXPLOITHIGH 7.2EPSS 17.5%20 March 2018
CVE-2017-17215Huawei HG532 with some customized versions has a remote code execution vulnerability.EXPLOITHIGH 8.8EPSS 78.3%20 March 2018
CVE-2018-8815Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web script or HTML via a malicious SVG image.EXPLOITMEDIUM 4.6EPSS 1.33%20 March 2018
CVE-2018-8811Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers to hijack the authentication of administrative users for requests that perform privilege escalation.EXPLOITHIGH 8.8EPSS 2.11%20 March 2018
CVE-2018-7445MikroTik RouterOS Stack-Based Buffer Overflow VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 60.8%19 March 2018
CVE-2014-2674Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 15.2%19 March 2018
CVE-2018-8732Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter.EXPLOITMEDIUM 5.4EPSS 1.65%19 March 2018
CVE-2018-1218In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer overflow condition when handling certain messages.EXPLOITHIGH 7.5EPSS 15.7%19 March 2018
CVE-2018-7422A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php, aka absolute…EXPLOITHIGH 7.5EPSS 62.3%19 March 2018
CVE-2018-8770Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, controllers/posterrorTest.php, controllers/posteventTest.php,…EXPLOITMEDIUM 5.3EPSS 59.2%18 March 2018
CVE-2014-4613Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that add users via a pwg.users.add action in a request to ws.php.EXPLOITMEDIUM 6.5EPSS 3.10%16 March 2018
CVE-2018-6230A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.EXPLOITMEDIUM 6.8EPSS 3.28%15 March 2018
CVE-2018-6229A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.EXPLOITCRITICAL 9.8EPSS 10.2%15 March 2018
CVE-2018-6228A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.EXPLOITCRITICAL 9.8EPSS 10.2%15 March 2018
CVE-2018-6227A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject client-side scripts into vulnerable systems.EXPLOITMEDIUM 5.4EPSS 1.57%15 March 2018
CVE-2018-6226Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files could allow an attacker to inject client-side scripts into vulnerable systems.EXPLOITMEDIUM 5.4EPSS 1.57%15 March 2018
CVE-2018-6225An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenticated user to expose a normally protected configuration script.EXPLOITMEDIUM 4.3EPSS 3.91%15 March 2018
CVE-2018-6224A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to submit authenticated requests to a user browsing an attacker-controlled domain.EXPLOITHIGH 8.8EPSS 2.11%15 March 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.