Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,739 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 68 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-7177 | SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-6585 | SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-6584 | SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request. | EXPLOIT ✓CRITICAL 9.8EPSS 3.80% | 17 February 2018 |
| CVE-2018-6583 | SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request. | EXPLOIT ✓CRITICAL 9.8EPSS 19.1% | 17 February 2018 |
| CVE-2018-6396 | SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action. | EXPLOIT ✓CRITICAL 9.8EPSS 23.6% | 17 February 2018 |
| CVE-2018-6394 | SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-6373 | SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action. | EXPLOIT ✓CRITICAL 9.8EPSS 1.93% | 17 February 2018 |
| CVE-2018-6372 | SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-6370 | SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-6368 | SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-6006 | SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter. | EXPLOITCRITICAL 9.8EPSS 19.1% | 17 February 2018 |
| CVE-2018-6005 | SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-6004 | SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5994 | SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resume request. | EXPLOITCRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5993 | SQL Injection exists in the Aist through 2.0 component for Joomla! via the id parameter in a view=showvacancy request. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5992 | SQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff request. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5991 | SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5990 | SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5989 | SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099. | EXPLOIT ✓CRITICAL 9.8EPSS 2.59% | 17 February 2018 |
| CVE-2018-5987 | SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action, the ends parameter in a view=gift action, the category parameter in a view=home action, the uid… | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5983 | SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5982 | SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= request. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5981 | SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5980 | SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action. | EXPLOITCRITICAL 9.8EPSS 3.80% | 17 February 2018 |
| CVE-2018-5975 | SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5974 | SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5971 | SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-5970 | SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 17 February 2018 |
| CVE-2018-7176 | FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page). | EXPLOITHIGH 8.8EPSS 2.35% | 16 February 2018 |
| CVE-2017-14537 | trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php. | EXPLOITMEDIUM 6.5EPSS 39.3% | 16 February 2018 |
| CVE-2017-14535 | trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php. | EXPLOITHIGH 8.8EPSS 50.1% | 16 February 2018 |
| CVE-2018-5767 | A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header. | EXPLOITCRITICAL 9.8EPSS 47.4% | 15 February 2018 |
| CVE-2017-8982 | A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found. | EXPLOITHIGH 7.5EPSS 14.2% | 15 February 2018 |
| CVE-2017-5817 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 82.6% | 15 February 2018 |
| CVE-2017-5816 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 86.2% | 15 February 2018 |
| CVE-2017-5815 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | EXPLOITCRITICAL 9.8EPSS 33.7% | 15 February 2018 |
| CVE-2017-5799 | A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. | EXPLOIT ✓HIGH 8.8EPSS 15.2% | 15 February 2018 |
| CVE-2017-5798 | A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. | EXPLOIT ✓MEDIUM 6.1EPSS 7.99% | 15 February 2018 |
| CVE-2017-5792 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found. | EXPLOITCRITICAL 9.8EPSS 34.3% | 15 February 2018 |
| CVE-2017-12557 | A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. | EXPLOIT ✓CRITICAL 9.8EPSS 79.8% | 15 February 2018 |
| CVE-2017-12542 | A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found. | EXPLOITCRITICAL 10.0EPSS 99.3% | 15 February 2018 |
| CVE-2017-12500 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. | EXPLOITHIGH 8.8EPSS 14.7% | 15 February 2018 |
| CVE-2016-8523 | A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found. | EXPLOIT ✓HIGH 8.8EPSS 16.7% | 15 February 2018 |
| CVE-2018-1041 | A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. | EXPLOITHIGH 7.5EPSS 15.5% | 15 February 2018 |
| CVE-2017-12718 | A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. | EXPLOITHIGH 8.1EPSS 12.8% | 15 February 2018 |
| CVE-2018-0866 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the… | EXPLOIT ✓HIGH 7.5EPSS 43.6% | 15 February 2018 |
| CVE-2018-0860 | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | EXPLOIT ✓HIGH 7.5EPSS 65.3% | 15 February 2018 |
| CVE-2018-0840 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows… | EXPLOIT ✓HIGH 7.5EPSS 53.1% | 15 February 2018 |
| CVE-2018-0838 | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | EXPLOIT ✓HIGH 7.5EPSS 65.3% | 15 February 2018 |
| CVE-2018-0837 | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | EXPLOIT ✓HIGH 7.5EPSS 65.3% | 15 February 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.