SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,516 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 137 of 348

CVESummaryPriorityPublished
CVE-2019-0571An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows…HIGH 7.8EPSS 15.8%8 January 2019
CVE-2019-0568A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 69.5%8 January 2019
CVE-2019-0567A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 80.1%8 January 2019
CVE-2019-0566An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.HIGH 8.8EPSS 18.6%8 January 2019
CVE-2019-0547A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers.CRITICAL 9.8EPSS 71.4%8 January 2019
CVE-2019-0546A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C++ constructs, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio.HIGH 7.8EPSS 16.2%8 January 2019
CVE-2019-0541Microsoft MSHTML Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 53.2%8 January 2019
CVE-2019-0539A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 82.9%8 January 2019
CVE-2019-0538A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,…HIGH 7.8EPSS 20.5%8 January 2019
CVE-2018-19862Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request.CRITICAL 9.8EPSS 12.6%3 January 2019
CVE-2018-19861Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request.CRITICAL 9.8EPSS 12.6%3 January 2019
CVE-2018-18264Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.HIGH 7.5EPSS 70.4%3 January 2019
CVE-2018-19362FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.CRITICAL 9.8EPSS 10.6%2 January 2019
CVE-2018-19361FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.CRITICAL 9.8EPSS 10.6%2 January 2019
CVE-2018-19360FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.CRITICAL 9.8EPSS 10.6%2 January 2019
CVE-2018-14721FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.CRITICAL 10.0EPSS 10.5%2 January 2019
CVE-2018-14718FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.CRITICAL 9.8EPSS 12.7%2 January 2019
CVE-2018-20608imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.HIGH 7.5EPSS 12.1%30 December 2018
CVE-2018-1000888PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class.HIGH 8.8EPSS 19.1%28 December 2018
CVE-2018-19616An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000.HIGH 8.1EPSS 30.3%26 December 2018
CVE-2018-11742NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.CRITICAL 9.8EPSS 14.3%26 December 2018
CVE-2018-11741NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs.CRITICAL 9.8EPSS 17.9%26 December 2018
CVE-2018-20463There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string.HIGH 7.5EPSS 13.2%25 December 2018
CVE-2018-20247In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack overflow.HIGH 7.8EPSS 54.5%24 December 2018
CVE-2018-7836An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.CRITICAL 9.8EPSS 32.0%24 December 2018
CVE-2018-20346SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by…HIGH 8.1EPSS 10.3%21 December 2018
CVE-2018-20338Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.CRITICAL 9.8EPSS 11.5%21 December 2018
CVE-2018-17246Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.CRITICAL 9.8EPSS 82.3%20 December 2018
CVE-2018-1160Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c.CRITICAL 9.8EPSS 86.5%20 December 2018
CVE-2018-1000811bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution.HIGH 8.8EPSS 47.6%20 December 2018
CVE-2018-8653Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityKEVHIGH 7.5EPSS 29.6%20 December 2018
CVE-2018-6307LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution.HIGH 8.1EPSS 26.5%19 December 2018
CVE-2018-15127LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code executionCRITICAL 9.8EPSS 15.1%19 December 2018
CVE-2018-15126LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code executionCRITICAL 9.8EPSS 11.8%19 December 2018
CVE-2018-18556A privilege escalation issue was discovered in VyOS 1.1.8.CRITICAL 9.9EPSS 15.4%17 December 2018
CVE-2018-20173Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.CRITICAL 9.8EPSS 24.5%17 December 2018
CVE-2018-20148In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call.CRITICAL 9.8EPSS 26.8%14 December 2018
CVE-2018-18006Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google cloud printers, encrypted passwords…CRITICAL 9.8EPSS 21.5%14 December 2018
CVE-2018-16873In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly.HIGH 8.1EPSS 66.3%14 December 2018
CVE-2018-19439XSS exists in the Administration Console in Oracle Secure Global Desktop 4.4 20080807152602 (but was fixed in later versions including 5.4). helpwindow.jsp has reflected XSS via all parameters, as demonstrated by the…MEDIUM 6.1EPSS 20.5%13 December 2018
CVE-2018-1821IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.CRITICAL 9.1EPSS 15.8%13 December 2018
CVE-2018-8033In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint.HIGH 7.5EPSS 25.7%13 December 2018
CVE-2018-8639Microsoft Windows Win32k Improper Resource Shutdown or Release VulnerabilityKEVHIGH 7.8EPSS 22.2%12 December 2018
CVE-2018-8636A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office,…HIGH 7.8EPSS 16.1%12 December 2018
CVE-2018-8634A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to properly handle objects in the memory, aka "Microsoft Text-To-Speech Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10,…HIGH 8.8EPSS 15.4%12 December 2018
CVE-2018-8631A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.HIGH 7.5EPSS 68.5%12 December 2018
CVE-2018-8629A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 22.6%12 December 2018
CVE-2018-8628A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365…HIGH 7.8EPSS 15.9%12 December 2018
CVE-2018-8626A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows…CRITICAL 9.8EPSS 21.2%12 December 2018
CVE-2018-8625A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.HIGH 7.5EPSS 43.8%12 December 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.