SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,527 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 138 of 348

CVESummaryPriorityPublished
CVE-2018-8624A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 13.2%12 December 2018
CVE-2018-8619A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer…HIGH 7.5EPSS 44.8%12 December 2018
CVE-2018-8618A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 10.9%12 December 2018
CVE-2018-8617A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 62.5%12 December 2018
CVE-2018-8597A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office,…HIGH 7.8EPSS 16.1%12 December 2018
CVE-2018-8587A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft…HIGH 7.8EPSS 28.8%12 December 2018
CVE-2018-8583A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 10.9%12 December 2018
CVE-2018-8540A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft…CRITICAL 9.8EPSS 21.6%12 December 2018
CVE-2018-10143The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/application.CRITICAL 9.8EPSS 24.8%12 December 2018
CVE-2018-20062ThinkPHP "noneCms" Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.5%11 December 2018
CVE-2018-17480Google Chromium V8 Out-of-Bounds Write VulnerabilityKEVHIGH 8.8EPSS 35.6%11 December 2018
CVE-2018-1000861Jenkins Stapler Web Framework Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 98.3%10 December 2018
CVE-2018-18311Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.CRITICAL 9.8EPSS 11.7%7 December 2018
CVE-2018-7364All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability.CRITICAL 9.8EPSS 10.3%7 December 2018
CVE-2018-19660An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311.HIGH 8.8EPSS 28.8%6 December 2018
CVE-2018-19908This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import.HIGH 8.8EPSS 17.3%6 December 2018
CVE-2018-19753Tarantella Enterprise before 3.11 allows Directory Traversal.HIGH 7.5EPSS 16.6%5 December 2018
CVE-2018-18312Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.CRITICAL 9.8EPSS 12.1%5 December 2018
CVE-2018-19877login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.MEDIUM 6.1EPSS 18.6%5 December 2018
CVE-2018-1002105In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to…CRITICAL 9.8EPSS 87.0%5 December 2018
CVE-2018-19864NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device.CRITICAL 9.8EPSS 24.8%5 December 2018
CVE-2018-17157In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request.CRITICAL 9.8EPSS 24.2%4 December 2018
CVE-2018-4021An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request.HIGH 7.2EPSS 72.2%3 December 2018
CVE-2018-4020An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request.HIGH 7.2EPSS 48.7%3 December 2018
CVE-2018-4019An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request.HIGH 7.2EPSS 48.7%3 December 2018
CVE-2018-14707Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to arbitrary locations.HIGH 7.5EPSS 27.8%3 December 2018
CVE-2018-14706System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the payload in a POST request.CRITICAL 9.8EPSS 17.1%3 December 2018
CVE-2018-14701System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter.CRITICAL 9.8EPSS 20.0%3 December 2018
CVE-2018-14699System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter.CRITICAL 9.8EPSS 29.4%3 December 2018
CVE-2018-7116HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote denial of service via dbman Opcode 10003 'Filename'.HIGH 7.5EPSS 10.3%3 December 2018
CVE-2018-7115HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in dbman.exe opcode 10001 on Windows.MEDIUM 5.3EPSS 13.4%3 December 2018
CVE-2018-7114HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to remote buffer overflow in dbman leading to code execution.CRITICAL 9.8EPSS 32.8%3 December 2018
CVE-2018-16855An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory read while computing the hash of the query for a packet cache lookup, possibly leading to a crash.HIGH 7.5EPSS 59.5%3 December 2018
CVE-2018-19788A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.HIGH 8.8EPSS 11.5%3 December 2018
CVE-2018-3949An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN.HIGH 7.5EPSS 53.3%1 December 2018
CVE-2018-15716NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection.HIGH 8.8EPSS 18.5%30 November 2018
CVE-2018-3948An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server.HIGH 7.5EPSS 23.1%30 November 2018
CVE-2018-15767The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file.HIGH 8.8EPSS 12.3%30 November 2018
CVE-2018-15981Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability.CRITICAL 9.8EPSS 11.7%29 November 2018
CVE-2018-15979Adobe Acrobat and Reader versions 2019.008.20080 and earlier, 2017.011.30105 and earlier, and 2015.006.30456 and earlier have a ntlm sso hash theft vulnerability.HIGH 7.5EPSS 10.3%29 November 2018
CVE-2018-19627In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash.HIGH 7.5EPSS 17.7%29 November 2018
CVE-2018-12122Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive…HIGH 7.5EPSS 41.3%28 November 2018
CVE-2018-12121Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of the…HIGH 7.5EPSS 10.2%28 November 2018
CVE-2018-13361User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter.MEDIUM 5.3EPSS 16.9%27 November 2018
CVE-2018-13359Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.HIGH 8.8EPSS 19.9%27 November 2018
CVE-2018-13358System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.HIGH 8.8EPSS 24.9%27 November 2018
CVE-2018-13354System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.CRITICAL 9.8EPSS 22.9%27 November 2018
CVE-2018-13350SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.CRITICAL 9.8EPSS 16.7%27 November 2018
CVE-2018-13338System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation.CRITICAL 9.8EPSS 10.2%27 November 2018
CVE-2018-18982NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.HIGH 8.8EPSS 60.8%27 November 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.