Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 27 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-8653 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 29.6% | 20 December 2018 |
| CVE-2018-8639 | Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability | KEVHIGH 7.8EPSS 22.2% | 12 December 2018 |
| CVE-2018-8611 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 4.20% | 12 December 2018 |
| CVE-2018-20062 | ThinkPHP "noneCms" Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.5% | 11 December 2018 |
| CVE-2018-17480 | Google Chromium V8 Out-of-Bounds Write Vulnerability | KEVHIGH 8.8EPSS 35.6% | 11 December 2018 |
| CVE-2018-1000861 | Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 10 December 2018 |
| CVE-2018-19410 | Paessler PRTG Network Monitor Local File Inclusion Vulnerability | KEVCRITICAL 9.8EPSS 97.9% | 21 November 2018 |
| CVE-2018-6065 | Google Chromium V8 Integer Overflow Vulnerability | KEVHIGH 8.8EPSS 60.3% | 14 November 2018 |
| CVE-2018-17463 | Google Chromium V8 Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 84.6% | 14 November 2018 |
| CVE-2018-8589 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 3.02% | 14 November 2018 |
| CVE-2018-8581 | Microsoft Exchange Server Privilege Escalation Vulnerability | KEVHIGH 7.4EPSS 27.4% | 14 November 2018 |
| CVE-2018-14667 | Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability | KEVCRITICAL 9.8EPSS 74.2% | 6 November 2018 |
| CVE-2018-14558 | Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 8.74% | 30 October 2018 |
| CVE-2018-8453 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 70.0% | 10 October 2018 |
| CVE-2018-14634 | Linux Kernel Integer Overflow Vulnerability | KEVHIGH 7.8EPSS 14.7% | 25 September 2018 |
| CVE-2018-15961 | Adobe ColdFusion Unrestricted File Upload Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 25 September 2018 |
| CVE-2018-8440 | Microsoft Windows Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 18.4% | 13 September 2018 |
| CVE-2018-11776 | Apache Struts Remote Code Execution Vulnerability | KEVHIGH 8.1EPSS 100.0% | 22 August 2018 |
| CVE-2018-8414 | Microsoft Windows Shell Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 74.0% | 15 August 2018 |
| CVE-2018-8406 | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 3.44% | 15 August 2018 |
| CVE-2018-8405 | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 3.44% | 15 August 2018 |
| CVE-2018-8373 | Microsoft Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 61.9% | 15 August 2018 |
| CVE-2018-15133 | Laravel Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.1EPSS 76.8% | 9 August 2018 |
| CVE-2018-14933 | NUUO NVRmini Devices OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 94.9% | 4 August 2018 |
| CVE-2018-14847 | MikroTik Router OS Directory Traversal Vulnerability | KEVCRITICAL 9.1EPSS 96.1% | 2 August 2018 |
| CVE-2018-7602 | Drupal Core Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.2% | 19 July 2018 |
| CVE-2018-8298 | ChakraCore Scripting Engine Type Confusion Vulnerability | KEVHIGH 7.5EPSS 74.5% | 11 July 2018 |
| CVE-2018-5002 | Adobe Flash Player Stack-based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 25.1% | 9 July 2018 |
| CVE-2018-4990 | Adobe Acrobat and Reader Double Free Vulnerability | KEVHIGH 8.8EPSS 36.2% | 9 July 2018 |
| CVE-2018-9276 | Paessler PRTG Network Monitor OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 87.0% | 2 July 2018 |
| CVE-2018-6961 | VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability | KEVHIGH 8.1EPSS 86.3% | 11 June 2018 |
| CVE-2016-9079 | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability | KEVHIGH 7.5EPSS 87.4% | 11 June 2018 |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 99.9% | 7 June 2018 |
| CVE-2018-11138 | Quest KACE System Management Appliance Remote Command Execution Vulnerability | KEVCRITICAL 9.8EPSS 92.1% | 31 May 2018 |
| CVE-2018-4939 | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 62.1% | 19 May 2018 |
| CVE-2018-8174 | Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability | KEVHIGH 7.5EPSS 88.3% | 9 May 2018 |
| CVE-2018-8120 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.0EPSS 73.4% | 9 May 2018 |
| CVE-2018-0824 | Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.8EPSS 73.2% | 9 May 2018 |
| CVE-2018-10562 | Dasan GPON Routers Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 4 May 2018 |
| CVE-2018-10561 | Dasan GPON Routers Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 92.9% | 4 May 2018 |
| CVE-2018-2628 | Oracle WebLogic Server Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 19 April 2018 |
| CVE-2018-5430 | TIBCO JasperReports Server Information Disclosure Vulnerability | KEVHIGH 8.8EPSS 49.6% | 17 April 2018 |
| CVE-2018-1273 | VMware Tanzu Spring Data Commons Property Binder Vulnerability | KEVCRITICAL 9.8EPSS 97.0% | 11 April 2018 |
| CVE-2018-7600 | Drupal Core Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 29 March 2018 |
| CVE-2018-0180 | Cisco IOS Software Denial-of-Service Vulnerability | KEVMEDIUM 5.9EPSS 4.93% | 28 March 2018 |
| CVE-2018-0179 | Cisco IOS Software Denial-of-Service Vulnerability | KEVMEDIUM 5.9EPSS 4.93% | 28 March 2018 |
| CVE-2018-0175 | Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability | KEVHIGH 8.0EPSS 3.48% | 28 March 2018 |
| CVE-2018-0174 | Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability | KEVHIGH 8.6EPSS 7.61% | 28 March 2018 |
| CVE-2018-0173 | Cisco IOS and IOS XE Software Improper Input Validation Vulnerability | KEVHIGH 8.6EPSS 7.61% | 28 March 2018 |
| CVE-2018-0172 | Cisco IOS and IOS XE Software Improper Input Validation Vulnerability | KEVHIGH 8.6EPSS 7.82% | 28 March 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.