Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,527 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 139 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-17936 | NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution. | CRITICAL 9.8EPSS 15.3% | 27 November 2018 |
| CVE-2018-17934 | NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. | CRITICAL 9.8EPSS 19.7% | 27 November 2018 |
| CVE-2018-16130 | System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload" URL parameter. | HIGH 8.8EPSS 24.0% | 27 November 2018 |
| CVE-2018-13023 | System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "timeout" URL parameter. | HIGH 8.8EPSS 24.0% | 27 November 2018 |
| CVE-2018-13324 | Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host header. | CRITICAL 9.8EPSS 23.2% | 26 November 2018 |
| CVE-2018-19518 | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without… | HIGH 7.5EPSS 95.2% | 25 November 2018 |
| CVE-2018-19458 | In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246. | HIGH 7.5EPSS 32.9% | 22 November 2018 |
| CVE-2018-19423 | Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file. | HIGH 7.2EPSS 18.1% | 21 November 2018 |
| CVE-2018-19422 | /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these. | HIGH 7.2EPSS 64.3% | 21 November 2018 |
| CVE-2018-19410 | Paessler PRTG Network Monitor Local File Inclusion Vulnerability | KEVCRITICAL 9.8EPSS 97.9% | 21 November 2018 |
| CVE-2018-18761 | SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. | CRITICAL 9.8EPSS 16.5% | 16 November 2018 |
| CVE-2018-16395 | An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. | CRITICAL 9.8EPSS 10.7% | 16 November 2018 |
| CVE-2018-8529 | A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects… | CRITICAL 9.8EPSS 13.5% | 15 November 2018 |
| CVE-2018-12543 | In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert is triggered that should otherwise not be reachable and Mosquitto will… | HIGH 7.5EPSS 36.0% | 15 November 2018 |
| CVE-2018-15712 | Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php. | MEDIUM 6.1EPSS 48.6% | 14 November 2018 |
| CVE-2018-15711 | Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. | HIGH 8.8EPSS 36.0% | 14 November 2018 |
| CVE-2018-15710 | Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php. | HIGH 7.8EPSS 44.1% | 14 November 2018 |
| CVE-2018-15709 | Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request. | HIGH 8.8EPSS 21.0% | 14 November 2018 |
| CVE-2018-15708 | Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request. | CRITICAL 9.8EPSS 89.4% | 14 November 2018 |
| CVE-2018-7358 | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations. | HIGH 8.8EPSS 89.6% | 14 November 2018 |
| CVE-2018-7357 | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access. | HIGH 8.8EPSS 87.9% | 14 November 2018 |
| CVE-2018-6065 | Google Chromium V8 Integer Overflow Vulnerability | KEVHIGH 8.8EPSS 60.3% | 14 November 2018 |
| CVE-2018-17463 | Google Chromium V8 Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 84.6% | 14 November 2018 |
| CVE-2018-8588 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 14 November 2018 |
| CVE-2018-8582 | A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. | HIGH 8.8EPSS 18.6% | 14 November 2018 |
| CVE-2018-8581 | Microsoft Exchange Server Privilege Escalation Vulnerability | KEVHIGH 7.4EPSS 27.4% | 14 November 2018 |
| CVE-2018-8577 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus,… | HIGH 7.8EPSS 19.1% | 14 November 2018 |
| CVE-2018-8576 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft… | HIGH 7.8EPSS 19.1% | 14 November 2018 |
| CVE-2018-8575 | A remote code execution vulnerability exists in Microsoft Project software when it fails to properly handle objects in memory, aka "Microsoft Project Remote Code Execution Vulnerability." This affects Microsoft Project, Office 365 ProPlus, Microsoft… | HIGH 7.8EPSS 19.5% | 14 November 2018 |
| CVE-2018-8574 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office,… | HIGH 7.8EPSS 19.1% | 14 November 2018 |
| CVE-2018-8573 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office. | HIGH 7.8EPSS 19.1% | 14 November 2018 |
| CVE-2018-8570 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. | HIGH 7.5EPSS 14.2% | 14 November 2018 |
| CVE-2018-8557 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 14 November 2018 |
| CVE-2018-8556 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 14 November 2018 |
| CVE-2018-8555 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 14 November 2018 |
| CVE-2018-8553 | A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 7.8EPSS 19.1% | 14 November 2018 |
| CVE-2018-8552 | An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory… | HIGH 7.5EPSS 51.0% | 14 November 2018 |
| CVE-2018-8551 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.3% | 14 November 2018 |
| CVE-2018-8544 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server… | HIGH 8.8EPSS 47.6% | 14 November 2018 |
| CVE-2018-8543 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 14 November 2018 |
| CVE-2018-8542 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 14 November 2018 |
| CVE-2018-8541 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.3% | 14 November 2018 |
| CVE-2018-8539 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Microsoft Office. | HIGH 7.8EPSS 19.1% | 14 November 2018 |
| CVE-2018-8524 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft… | HIGH 7.8EPSS 19.1% | 14 November 2018 |
| CVE-2018-8522 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft… | HIGH 7.8EPSS 19.1% | 14 November 2018 |
| CVE-2018-8476 | A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2,… | CRITICAL 9.8EPSS 64.8% | 14 November 2018 |
| CVE-2018-8450 | A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server… | HIGH 8.8EPSS 16.1% | 14 November 2018 |
| CVE-2018-8256 | A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive… | HIGH 8.8EPSS 22.6% | 14 November 2018 |
| CVE-2018-19246 | PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their web server) is used. | HIGH 7.5EPSS 22.0% | 13 November 2018 |
| CVE-2018-19207 | The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018. | CRITICAL 9.8EPSS 88.1% | 12 November 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.