Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,527 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 138 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-8624 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 13.2% | 12 December 2018 |
| CVE-2018-8619 | A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer… | HIGH 7.5EPSS 44.8% | 12 December 2018 |
| CVE-2018-8618 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 10.9% | 12 December 2018 |
| CVE-2018-8617 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 62.5% | 12 December 2018 |
| CVE-2018-8597 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office,… | HIGH 7.8EPSS 16.1% | 12 December 2018 |
| CVE-2018-8587 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft… | HIGH 7.8EPSS 28.8% | 12 December 2018 |
| CVE-2018-8583 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 10.9% | 12 December 2018 |
| CVE-2018-8540 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft… | CRITICAL 9.8EPSS 21.6% | 12 December 2018 |
| CVE-2018-10143 | The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/application. | CRITICAL 9.8EPSS 24.8% | 12 December 2018 |
| CVE-2018-20062 | ThinkPHP "noneCms" Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.5% | 11 December 2018 |
| CVE-2018-17480 | Google Chromium V8 Out-of-Bounds Write Vulnerability | KEVHIGH 8.8EPSS 35.6% | 11 December 2018 |
| CVE-2018-1000861 | Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 10 December 2018 |
| CVE-2018-18311 | Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | CRITICAL 9.8EPSS 11.7% | 7 December 2018 |
| CVE-2018-7364 | All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. | CRITICAL 9.8EPSS 10.3% | 7 December 2018 |
| CVE-2018-19660 | An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. | HIGH 8.8EPSS 28.8% | 6 December 2018 |
| CVE-2018-19908 | This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import. | HIGH 8.8EPSS 17.3% | 6 December 2018 |
| CVE-2018-19753 | Tarantella Enterprise before 3.11 allows Directory Traversal. | HIGH 7.5EPSS 16.6% | 5 December 2018 |
| CVE-2018-18312 | Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | CRITICAL 9.8EPSS 12.1% | 5 December 2018 |
| CVE-2018-19877 | login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field. | MEDIUM 6.1EPSS 18.6% | 5 December 2018 |
| CVE-2018-1002105 | In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to… | CRITICAL 9.8EPSS 87.0% | 5 December 2018 |
| CVE-2018-19864 | NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device. | CRITICAL 9.8EPSS 24.8% | 5 December 2018 |
| CVE-2018-17157 | In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request. | CRITICAL 9.8EPSS 24.2% | 4 December 2018 |
| CVE-2018-4021 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. | HIGH 7.2EPSS 72.2% | 3 December 2018 |
| CVE-2018-4020 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. | HIGH 7.2EPSS 48.7% | 3 December 2018 |
| CVE-2018-4019 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. | HIGH 7.2EPSS 48.7% | 3 December 2018 |
| CVE-2018-14707 | Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to arbitrary locations. | HIGH 7.5EPSS 27.8% | 3 December 2018 |
| CVE-2018-14706 | System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the payload in a POST request. | CRITICAL 9.8EPSS 17.1% | 3 December 2018 |
| CVE-2018-14701 | System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter. | CRITICAL 9.8EPSS 20.0% | 3 December 2018 |
| CVE-2018-14699 | System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter. | CRITICAL 9.8EPSS 29.4% | 3 December 2018 |
| CVE-2018-7116 | HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote denial of service via dbman Opcode 10003 'Filename'. | HIGH 7.5EPSS 10.3% | 3 December 2018 |
| CVE-2018-7115 | HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in dbman.exe opcode 10001 on Windows. | MEDIUM 5.3EPSS 13.4% | 3 December 2018 |
| CVE-2018-7114 | HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to remote buffer overflow in dbman leading to code execution. | CRITICAL 9.8EPSS 32.8% | 3 December 2018 |
| CVE-2018-16855 | An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory read while computing the hash of the query for a packet cache lookup, possibly leading to a crash. | HIGH 7.5EPSS 59.5% | 3 December 2018 |
| CVE-2018-19788 | A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command. | HIGH 8.8EPSS 11.5% | 3 December 2018 |
| CVE-2018-3949 | An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. | HIGH 7.5EPSS 53.3% | 1 December 2018 |
| CVE-2018-15716 | NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. | HIGH 8.8EPSS 18.5% | 30 November 2018 |
| CVE-2018-3948 | An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server. | HIGH 7.5EPSS 23.1% | 30 November 2018 |
| CVE-2018-15767 | The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file. | HIGH 8.8EPSS 12.3% | 30 November 2018 |
| CVE-2018-15981 | Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. | CRITICAL 9.8EPSS 11.7% | 29 November 2018 |
| CVE-2018-15979 | Adobe Acrobat and Reader versions 2019.008.20080 and earlier, 2017.011.30105 and earlier, and 2015.006.30456 and earlier have a ntlm sso hash theft vulnerability. | HIGH 7.5EPSS 10.3% | 29 November 2018 |
| CVE-2018-19627 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. | HIGH 7.5EPSS 17.7% | 29 November 2018 |
| CVE-2018-12122 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive… | HIGH 7.5EPSS 41.3% | 28 November 2018 |
| CVE-2018-12121 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of the… | HIGH 7.5EPSS 10.2% | 28 November 2018 |
| CVE-2018-13361 | User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter. | MEDIUM 5.3EPSS 16.9% | 27 November 2018 |
| CVE-2018-13359 | Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter. | HIGH 8.8EPSS 19.9% | 27 November 2018 |
| CVE-2018-13358 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter. | HIGH 8.8EPSS 24.9% | 27 November 2018 |
| CVE-2018-13354 | System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter. | CRITICAL 9.8EPSS 22.9% | 27 November 2018 |
| CVE-2018-13350 | SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter. | CRITICAL 9.8EPSS 16.7% | 27 November 2018 |
| CVE-2018-13338 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation. | CRITICAL 9.8EPSS 10.2% | 27 November 2018 |
| CVE-2018-18982 | NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution. | HIGH 8.8EPSS 60.8% | 27 November 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.