SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,739 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 69 of 501

CVESummaryPriorityPublished
CVE-2018-0835Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".EXPLOITHIGH 7.5EPSS 65.3%15 February 2018
CVE-2018-0834Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".EXPLOITHIGH 7.5EPSS 54.9%15 February 2018
CVE-2018-0833The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service vulnerability due to how specially crafted requests are handled, aka "SMBv2/SMBv3 Null Dereference Denial…EXPLOITMEDIUM 5.3EPSS 39.9%15 February 2018
CVE-2018-0832The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how objects in memory are…EXPLOITMEDIUM 4.7EPSS 2.34%15 February 2018
CVE-2018-0826Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services…EXPLOITHIGH 7.0EPSS 3.10%15 February 2018
CVE-2018-0823The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Named Pipe File System handles objects, aka "Named Pipe File System Elevation of Privilege…EXPLOITHIGH 7.0EPSS 2.63%15 February 2018
CVE-2018-0822NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way NTFS handles objects, aka "Windows NTFS Global Reparse Point Elevation of Privilege…EXPLOITHIGH 7.0EPSS 2.63%15 February 2018
CVE-2018-0821AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way constrained impersonations are handled, aka "Windows AppContainer Elevation Of…EXPLOITHIGH 7.0EPSS 2.30%15 February 2018
CVE-2018-6911The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).EXPLOITCRITICAL 9.8EPSS 12.8%13 February 2018
CVE-2017-13236In the KeyStore service, there is a permissions bypass that allows access to protected resources.EXPLOITHIGH 7.8EPSS 0.55%12 February 2018
CVE-2016-8742The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation.EXPLOITHIGH 7.8EPSS 1.96%12 February 2018
CVE-2018-6889It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.EXPLOITHIGH 8.8EPSS 6.69%12 February 2018
CVE-2018-6888The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF…EXPLOITHIGH 8.0EPSS 1.93%12 February 2018
CVE-2018-6845PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field.EXPLOITMEDIUM 6.1EPSS 2.51%12 February 2018
CVE-2018-6892An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition.EXPLOIT ×4CRITICAL 9.8EPSS 93.4%11 February 2018
CVE-2018-1000049Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API.EXPLOIT ×2HIGH 7.5EPSS 76.9%9 February 2018
CVE-2015-1862The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.EXPLOIT ×2HIGH 7.0EPSS 3.02%9 February 2018
CVE-2018-6871LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.EXPLOITCRITICAL 9.8EPSS 22.8%9 February 2018
CVE-2018-6789Exim Buffer Overflow VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 82.1%8 February 2018
CVE-2018-6180A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts.EXPLOITCRITICAL 9.8EPSS 3.99%8 February 2018
CVE-2017-17417This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.EXPLOITCRITICAL 9.8EPSS 9.82%8 February 2018
CVE-2017-5124Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.EXPLOITMEDIUM 6.1EPSS 5.15%7 February 2018
CVE-2018-6794Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c.EXPLOITMEDIUM 5.3EPSS 24.3%7 February 2018
CVE-2018-4878Adobe Flash Player Use-After-Free VulnerabilityKEVEXPLOIT ×3HIGH 7.8EPSS 89.5%6 February 2018
CVE-2018-6389In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many…EXPLOITHIGH 7.5EPSS 72.7%6 February 2018
CVE-2018-6610Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.EXPLOITHIGH 7.5EPSS 7.92%5 February 2018
CVE-2018-6609SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action.EXPLOITCRITICAL 9.8EPSS 2.65%5 February 2018
CVE-2018-6605SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.EXPLOITCRITICAL 9.8EPSS 57.7%5 February 2018
CVE-2018-6604SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetails request.EXPLOITCRITICAL 9.8EPSS 2.65%5 February 2018
CVE-2018-6582SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.EXPLOITCRITICAL 9.8EPSS 2.71%5 February 2018
CVE-2017-9414Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that conduct cross-site scripting (XSS) attacks or possibly…EXPLOITHIGH 8.8EPSS 15.4%5 February 2018
CVE-2018-6606Improper access control in zam32.sys and zam64.sys allows a non-privileged process to register itself with the driver by sending IOCTL 0x80002010 and then using IOCTL 0x8000204C to \\.\ZemanaAntiMalware to elevate privileges.EXPLOITHIGH 7.8EPSS 1.19%4 February 2018
CVE-2018-6593Improper access control in zam32.sys and zam64.sys allows a non-privileged process to register itself with the driver by connecting to the filter communication port and then using IOCTL 0x8000204C to \\.\ZemanaAntiMalware to elevate privileges.EXPLOITHIGH 7.8EPSS 1.11%3 February 2018
CVE-2018-1185Command injection vulnerability in Admin CLI may allow a malicious user with admin privileges to escape from the restricted shell to an interactive shell and run arbitrary commands with root privileges.EXPLOITMEDIUM 6.7EPSS 6.31%3 February 2018
CVE-2018-6317The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remote attackers to read memory or cause a denial of service.EXPLOITCRITICAL 9.1EPSS 43.7%2 February 2018
CVE-2018-6581SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.EXPLOITCRITICAL 9.8EPSS 2.65%2 February 2018
CVE-2018-6580Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.EXPLOITCRITICAL 9.8EPSS 36.3%2 February 2018
CVE-2018-6579SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.EXPLOITCRITICAL 9.8EPSS 3.80%2 February 2018
CVE-2018-6578SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.EXPLOITCRITICAL 9.8EPSS 3.80%2 February 2018
CVE-2018-6577SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.EXPLOITCRITICAL 9.8EPSS 1.98%2 February 2018
CVE-2018-6576SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.EXPLOITCRITICAL 9.8EPSS 2.65%2 February 2018
CVE-2018-6575SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.EXPLOITCRITICAL 9.8EPSS 2.65%2 February 2018
CVE-2017-1000409A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable.EXPLOITHIGH 7.0EPSS 1.21%1 February 2018
CVE-2017-1000408A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable.EXPLOITHIGH 7.8EPSS 1.45%1 February 2018
CVE-2017-16945The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted restore path.EXPLOITHIGH 7.8EPSS 0.99%31 January 2018
CVE-2017-16928The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted update URL, as demonstrated by file:///tmp/blah/Arq.zip.EXPLOITHIGH 7.8EPSS 0.99%31 January 2018
CVE-2018-5701In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerability due to not validating input values from IOCtl 0x00226003.EXPLOIT ×2CRITICAL 9.8EPSS 18.5%31 January 2018
CVE-2014-1632htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.EXPLOITHIGH 8.1EPSS 10.5%31 January 2018
CVE-2014-1631Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.EXPLOIT ×2HIGH 7.5EPSS 9.30%31 January 2018
CVE-2018-6460User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter func=$_APPLOG.Rfunc and extract sensitive information about the machine, including whether the user is connected to…EXPLOITHIGH 7.5EPSS 11.0%31 January 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.