Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,527 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 140 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-19206 | steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment. | MEDIUM 6.1EPSS 55.9% | 12 November 2018 |
| CVE-2018-19127 | A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. | CRITICAL 9.8EPSS 20.8% | 9 November 2018 |
| CVE-2018-19126 | PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload. | CRITICAL 9.8EPSS 22.5% | 9 November 2018 |
| CVE-2018-19125 | PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory. | HIGH 7.5EPSS 10.8% | 9 November 2018 |
| CVE-2018-15439 | A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. | CRITICAL 9.8EPSS 49.7% | 8 November 2018 |
| CVE-2018-15381 | A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. | CRITICAL 9.8EPSS 87.3% | 8 November 2018 |
| CVE-2018-8021 | Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. | CRITICAL 9.8EPSS 52.8% | 7 November 2018 |
| CVE-2018-16844 | nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. | HIGH 7.5EPSS 12.4% | 7 November 2018 |
| CVE-2018-16843 | nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. | HIGH 7.5EPSS 47.1% | 7 November 2018 |
| CVE-2018-19052 | There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character. | HIGH 7.5EPSS 13.7% | 7 November 2018 |
| CVE-2018-14667 | Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability | KEVCRITICAL 9.8EPSS 74.2% | 6 November 2018 |
| CVE-2018-18980 | An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. | HIGH 7.5EPSS 25.0% | 6 November 2018 |
| CVE-2018-18957 | It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c. | CRITICAL 9.8EPSS 11.6% | 5 November 2018 |
| CVE-2018-18820 | A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. | HIGH 8.1EPSS 48.9% | 5 November 2018 |
| CVE-2018-18949 | Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings. | CRITICAL 9.8EPSS 24.5% | 5 November 2018 |
| CVE-2018-18925 | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. | CRITICAL 9.8EPSS 31.1% | 4 November 2018 |
| CVE-2018-18777 | Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. | MEDIUM 4.3EPSS 22.8% | 1 November 2018 |
| CVE-2018-15706 | WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API. | MEDIUM 6.5EPSS 32.4% | 31 October 2018 |
| CVE-2018-15705 | WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. | MEDIUM 6.5EPSS 12.2% | 31 October 2018 |
| CVE-2018-11759 | If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application… | HIGH 7.5EPSS 90.6% | 31 October 2018 |
| CVE-2018-18850 | In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment processes could upload a maliciously crafted YAML configuration, potentially allowing for remote execution of arbitrary code, running… | HIGH 8.8EPSS 12.5% | 31 October 2018 |
| CVE-2018-0734 | The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. | MEDIUM 5.9EPSS 12.2% | 30 October 2018 |
| CVE-2018-18778 | ACME mini_httpd before 1.30 lets remote users read arbitrary files. | MEDIUM 6.5EPSS 70.8% | 29 October 2018 |
| CVE-2018-14665 | X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges. | MEDIUM 6.6EPSS 27.0% | 25 October 2018 |
| CVE-2018-15442 | A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. | HIGH 7.8EPSS 16.0% | 24 October 2018 |
| CVE-2018-18475 | Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload. | CRITICAL 9.8EPSS 20.4% | 23 October 2018 |
| CVE-2018-17445 | A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | CRITICAL 9.8EPSS 11.1% | 23 October 2018 |
| CVE-2017-18349 | parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of… | CRITICAL 9.8EPSS 39.0% | 23 October 2018 |
| CVE-2018-8569 | A remote code execution vulnerability exists in the Yammer desktop application due to the loading of arbitrary content, aka "Yammer Desktop Application Remote Code Execution Vulnerability." This affects Yammer Desktop App. | HIGH 7.8EPSS 13.3% | 23 October 2018 |
| CVE-2018-15704 | Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. | HIGH 8.8EPSS 21.5% | 22 October 2018 |
| CVE-2018-18557 | LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring… | HIGH 8.8EPSS 15.0% | 22 October 2018 |
| CVE-2018-18428 | TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI. | HIGH 7.5EPSS 11.5% | 19 October 2018 |
| CVE-2018-18284 | Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator. | HIGH 8.6EPSS 16.3% | 19 October 2018 |
| CVE-2015-4632 | Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path… | HIGH 7.5EPSS 51.8% | 18 October 2018 |
| CVE-2018-12386 | A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. | HIGH 8.1EPSS 13.4% | 18 October 2018 |
| CVE-2018-12814 | Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. | CRITICAL 9.8EPSS 11.2% | 17 October 2018 |
| CVE-2018-12813 | Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. | CRITICAL 9.8EPSS 11.2% | 17 October 2018 |
| CVE-2018-10824 | An attacker having a directory traversal (or LFI) can easily get full router access. | CRITICAL 9.8EPSS 12.5% | 17 October 2018 |
| CVE-2018-10823 | An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. | HIGH 8.8EPSS 77.7% | 17 October 2018 |
| CVE-2018-10822 | Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices… | HIGH 7.5EPSS 39.3% | 17 October 2018 |
| CVE-2018-7076 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) prior to iMC PLAT 7.3 E0605P04. | CRITICAL 9.8EPSS 12.3% | 17 October 2018 |
| CVE-2018-10933 | A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. | CRITICAL 9.1EPSS 91.8% | 17 October 2018 |
| CVE-2018-3953 | Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAM. | HIGH 7.2EPSS 13.5% | 17 October 2018 |
| CVE-2018-3252 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). | CRITICAL 9.8EPSS 28.0% | 17 October 2018 |
| CVE-2018-3245 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). | CRITICAL 9.8EPSS 94.3% | 17 October 2018 |
| CVE-2018-3191 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). | CRITICAL 9.8EPSS 63.2% | 17 October 2018 |
| CVE-2018-3167 | Vulnerability in the Application Management Pack for Oracle E-Business Suite component of Oracle E-Business Suite (subcomponent: User Monitoring). | MEDIUM 5.3EPSS 17.1% | 17 October 2018 |
| CVE-2018-17532 | Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. | CRITICAL 9.8EPSS 70.7% | 15 October 2018 |
| CVE-2018-18323 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI. | HIGH 7.5EPSS 70.7% | 15 October 2018 |
| CVE-2018-18322 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter. | CRITICAL 9.8EPSS 15.1% | 15 October 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.