Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,527 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 141 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-15956 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 16.5% | 12 October 2018 |
| CVE-2018-15955 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 19.0% | 12 October 2018 |
| CVE-2018-15954 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 19.0% | 12 October 2018 |
| CVE-2018-15953 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 19.8% | 12 October 2018 |
| CVE-2018-15952 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 15.5% | 12 October 2018 |
| CVE-2018-15938 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 13.5% | 12 October 2018 |
| CVE-2018-15937 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an untrusted pointer dereference vulnerability. | HIGH 7.8EPSS 28.0% | 12 October 2018 |
| CVE-2018-15936 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 13.5% | 12 October 2018 |
| CVE-2018-15935 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 13.5% | 12 October 2018 |
| CVE-2018-15934 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 13.5% | 12 October 2018 |
| CVE-2018-15933 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 13.5% | 12 October 2018 |
| CVE-2018-15932 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 18.9% | 12 October 2018 |
| CVE-2018-15931 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an untrusted pointer dereference vulnerability. | HIGH 7.8EPSS 27.8% | 12 October 2018 |
| CVE-2018-15930 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an untrusted pointer dereference vulnerability. | HIGH 7.8EPSS 27.8% | 12 October 2018 |
| CVE-2018-15929 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 13.5% | 12 October 2018 |
| CVE-2018-15928 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 15.9% | 12 October 2018 |
| CVE-2018-15927 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 16.4% | 12 October 2018 |
| CVE-2018-12875 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 16.4% | 12 October 2018 |
| CVE-2018-12874 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 16.4% | 12 October 2018 |
| CVE-2018-12873 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 16.4% | 12 October 2018 |
| CVE-2018-12872 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 19.7% | 12 October 2018 |
| CVE-2018-12871 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 19.7% | 12 October 2018 |
| CVE-2018-12870 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 19.7% | 12 October 2018 |
| CVE-2018-12869 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 19.7% | 12 October 2018 |
| CVE-2018-12867 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 19.7% | 12 October 2018 |
| CVE-2018-12866 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 16.4% | 12 October 2018 |
| CVE-2018-12865 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 15.9% | 12 October 2018 |
| CVE-2018-12864 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 16.0% | 12 October 2018 |
| CVE-2018-12863 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an use after free vulnerability. | HIGH 7.8EPSS 16.9% | 12 October 2018 |
| CVE-2018-12862 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 13.5% | 12 October 2018 |
| CVE-2018-12861 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 15.9% | 12 October 2018 |
| CVE-2018-12860 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. | HIGH 7.8EPSS 13.5% | 12 October 2018 |
| CVE-2018-12859 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 19.7% | 12 October 2018 |
| CVE-2018-12857 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 16.4% | 12 October 2018 |
| CVE-2018-12851 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. | HIGH 7.8EPSS 10.1% | 12 October 2018 |
| CVE-2018-12847 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. | HIGH 7.8EPSS 10.9% | 12 October 2018 |
| CVE-2018-12839 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. | MEDIUM 5.5EPSS 19.8% | 12 October 2018 |
| CVE-2018-12838 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a stack overflow vulnerability. | MEDIUM 5.5EPSS 11.8% | 12 October 2018 |
| CVE-2018-12837 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. | HIGH 7.8EPSS 10.1% | 12 October 2018 |
| CVE-2018-12836 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. | HIGH 7.8EPSS 10.1% | 12 October 2018 |
| CVE-2018-12833 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. | HIGH 7.8EPSS 10.3% | 12 October 2018 |
| CVE-2018-12832 | Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. | HIGH 7.8EPSS 10.1% | 12 October 2018 |
| CVE-2018-17888 | NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution. | CRITICAL 9.8EPSS 29.6% | 12 October 2018 |
| CVE-2018-9206 | Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 | CRITICAL 9.8EPSS 97.3% | 11 October 2018 |
| CVE-2018-12596 | Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden… | CRITICAL 9.8EPSS 22.4% | 10 October 2018 |
| CVE-2018-8006 | An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. | MEDIUM 6.1EPSS 57.2% | 10 October 2018 |
| CVE-2018-8533 | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability."… | MEDIUM 5.5EPSS 23.4% | 10 October 2018 |
| CVE-2018-8532 | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability."… | MEDIUM 5.5EPSS 23.4% | 10 October 2018 |
| CVE-2018-8531 | A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesses objects in memory, aka "Azure IoT Device Client SDK Memory Corruption Vulnerability." This affects Hub Device Client SDK, Azure IoT… | HIGH 8.8EPSS 15.1% | 10 October 2018 |
| CVE-2018-8527 | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This… | MEDIUM 5.5EPSS 23.4% | 10 October 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.