Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,739 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 70 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-1000001 | In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution. | EXPLOIT ×2 ✓HIGH 7.8EPSS 13.4% | 31 January 2018 |
| CVE-2016-6599 | 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. | EXPLOITCRITICAL 9.8EPSS 12.3% | 30 January 2018 |
| CVE-2016-6598 | 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. | EXPLOITCRITICAL 9.8EPSS 19.2% | 30 January 2018 |
| CVE-2018-6398 | SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action. | EXPLOITCRITICAL 9.8EPSS 2.65% | 30 January 2018 |
| CVE-2018-6397 | Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter. | EXPLOITHIGH 7.5EPSS 11.9% | 30 January 2018 |
| CVE-2018-6395 | SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action. | EXPLOITCRITICAL 9.8EPSS 2.65% | 30 January 2018 |
| CVE-2018-0101 | A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. | EXPLOITCRITICAL 10.0EPSS 86.8% | 29 January 2018 |
| CVE-2018-6388 | iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping test arguments on the Diagnostics page. | EXPLOITHIGH 8.8EPSS 5.88% | 29 January 2018 |
| CVE-2018-6383 | Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbitrary PHP code by uploading a… | EXPLOITHIGH 8.8EPSS 13.5% | 29 January 2018 |
| CVE-2017-1000353 | Jenkins Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.7% | 29 January 2018 |
| CVE-2018-6367 | SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php category parameter. | EXPLOITCRITICAL 9.8EPSS 3.05% | 29 January 2018 |
| CVE-2018-6365 | SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php. | EXPLOITCRITICAL 9.8EPSS 3.05% | 29 January 2018 |
| CVE-2018-6364 | SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter. | EXPLOITCRITICAL 9.8EPSS 3.05% | 29 January 2018 |
| CVE-2018-6363 | SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter. | EXPLOITCRITICAL 9.8EPSS 2.98% | 29 January 2018 |
| CVE-2018-6008 | Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter. | EXPLOITHIGH 7.5EPSS 36.8% | 29 January 2018 |
| CVE-2018-6007 | CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket. | EXPLOITHIGH 8.8EPSS 2.26% | 29 January 2018 |
| CVE-2018-5720 | A Cross-site request forgery (CSRF) vulnerability allows remote attackers to hijack the authentication of users for requests that modify all the settings. | EXPLOITHIGH 8.8EPSS 2.71% | 29 January 2018 |
| CVE-2017-18078 | systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a… | EXPLOITHIGH 7.8EPSS 1.06% | 29 January 2018 |
| CVE-2017-17976 | In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. | EXPLOITCRITICAL 9.8EPSS 12.5% | 26 January 2018 |
| CVE-2017-14523 | WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. | EXPLOITHIGH 7.5EPSS 8.04% | 26 January 2018 |
| CVE-2017-14521 | In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload. | EXPLOIT ✓HIGH 8.8EPSS 7.30% | 26 January 2018 |
| CVE-2018-6323 | The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigned integer overflow because bfd_size_type multiplication is not used. | EXPLOITHIGH 7.8EPSS 5.83% | 26 January 2018 |
| CVE-2018-5997 | Due to an unrestricted upload feature and a path traversal vulnerability, it is possible to upload a file on a filesystem with root privileges: this will lead to remote code execution as root. | EXPLOITCRITICAL 9.8EPSS 23.5% | 25 January 2018 |
| CVE-2018-5973 | SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryID or CategoryID parameter. | EXPLOITCRITICAL 9.8EPSS 20.1% | 25 January 2018 |
| CVE-2018-5954 | phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands. | EXPLOITHIGH 7.5EPSS 8.93% | 25 January 2018 |
| CVE-2018-1000006 | GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in… | EXPLOIT ×2 ✓HIGH 8.8EPSS 84.5% | 24 January 2018 |
| CVE-2017-1000474 | Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php scripts resulting in the expose of… | EXPLOITCRITICAL 9.8EPSS 2.13% | 24 January 2018 |
| CVE-2018-6193 | A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph action to cgi-bin/routers2.pl. | EXPLOIT ✓MEDIUM 4.7EPSS 2.12% | 24 January 2018 |
| CVE-2018-6191 | The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation. | EXPLOITMEDIUM 5.5EPSS 5.20% | 24 January 2018 |
| CVE-2018-6190 | Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page. | EXPLOITMEDIUM 5.4EPSS 1.58% | 24 January 2018 |
| CVE-2018-5759 | jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows remote attackers to cause a denial of service (excessive recursion) via a crafted file. | EXPLOITMEDIUM 5.5EPSS 5.06% | 24 January 2018 |
| CVE-2018-5705 | Reservo Image Hosting 1.6 is vulnerable to XSS attacks. | EXPLOITMEDIUM 6.1EPSS 1.46% | 24 January 2018 |
| CVE-2018-5319 | RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request. | EXPLOITHIGH 7.5EPSS 12.4% | 24 January 2018 |
| CVE-2018-5988 | SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php. | EXPLOITCRITICAL 9.8EPSS 19.1% | 24 January 2018 |
| CVE-2018-5986 | SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php. | EXPLOITCRITICAL 9.8EPSS 2.59% | 24 January 2018 |
| CVE-2018-5985 | SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request. | EXPLOITCRITICAL 9.8EPSS 19.1% | 24 January 2018 |
| CVE-2018-5984 | SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI. | EXPLOITCRITICAL 9.8EPSS 2.65% | 24 January 2018 |
| CVE-2018-5979 | SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field. | EXPLOITCRITICAL 9.8EPSS 19.1% | 24 January 2018 |
| CVE-2018-5978 | SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field. | EXPLOITCRITICAL 9.8EPSS 2.65% | 24 January 2018 |
| CVE-2018-5977 | SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= request. | EXPLOITCRITICAL 9.8EPSS 1.92% | 24 January 2018 |
| CVE-2018-5976 | Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modifying the admin password. | EXPLOITHIGH 8.8EPSS 2.13% | 24 January 2018 |
| CVE-2018-5972 | SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI. | EXPLOITCRITICAL 9.8EPSS 19.1% | 24 January 2018 |
| CVE-2018-5969 | Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demonstrated by adding an admin account. | EXPLOITHIGH 8.8EPSS 1.39% | 24 January 2018 |
| CVE-2018-5359 | The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system-level access because of a Buffer Overflow. | EXPLOITHIGH 8.1EPSS 9.00% | 23 January 2018 |
| CVE-2017-17999 | SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_article_suggestion/. | EXPLOITCRITICAL 9.8EPSS 3.34% | 23 January 2018 |
| CVE-2017-2741 | A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 84.6% | 23 January 2018 |
| CVE-2018-6000 | The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and… | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 85.2% | 22 January 2018 |
| CVE-2018-5999 | An issue was discovered in AsusWRT before 3.0.0.4.384_10007. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 87.3% | 22 January 2018 |
| CVE-2018-1042 | Moodle 3.x has Server Side Request Forgery in the filepicker. | EXPLOITMEDIUM 6.5EPSS 16.7% | 22 January 2018 |
| CVE-2018-5955 | User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a user to the server via the username and password fields to the rest/user/ URI. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 81.4% | 21 January 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.