Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,527 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 142 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-8513 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 10 October 2018 |
| CVE-2018-8511 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 10 October 2018 |
| CVE-2018-8510 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 10 October 2018 |
| CVE-2018-8509 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. | HIGH 7.5EPSS 12.8% | 10 October 2018 |
| CVE-2018-8505 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 10 October 2018 |
| CVE-2018-8504 | A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Office 365… | HIGH 8.8EPSS 19.7% | 10 October 2018 |
| CVE-2018-8503 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 10 October 2018 |
| CVE-2018-8502 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office,… | HIGH 8.8EPSS 20.5% | 10 October 2018 |
| CVE-2018-8501 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in Protected View, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Office 365 ProPlus,… | HIGH 8.8EPSS 19.7% | 10 October 2018 |
| CVE-2018-8500 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. | CRITICAL 9.8EPSS 18.5% | 10 October 2018 |
| CVE-2018-8495 | A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | HIGH 7.5EPSS 50.7% | 10 October 2018 |
| CVE-2018-8494 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008,… | HIGH 8.8EPSS 22.1% | 10 October 2018 |
| CVE-2018-8491 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. | HIGH 7.5EPSS 12.8% | 10 October 2018 |
| CVE-2018-8473 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.2% | 10 October 2018 |
| CVE-2018-8472 | An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka "Windows GDI Information Disclosure… | MEDIUM 5.5EPSS 18.9% | 10 October 2018 |
| CVE-2018-8460 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. | HIGH 7.5EPSS 20.7% | 10 October 2018 |
| CVE-2018-8453 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 70.0% | 10 October 2018 |
| CVE-2018-8432 | A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Microsoft Office Word… | HIGH 7.8EPSS 19.5% | 10 October 2018 |
| CVE-2018-8423 | A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows… | HIGH 7.8EPSS 32.2% | 10 October 2018 |
| CVE-2018-8413 | A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows Theme API Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019,… | HIGH 7.8EPSS 46.3% | 10 October 2018 |
| CVE-2018-8292 | An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1,… | HIGH 7.5EPSS 14.8% | 10 October 2018 |
| CVE-2018-8265 | A remote code execution vulnerability exists in the way Microsoft Exchange software parses specially crafted email messages, aka "Microsoft Exchange Remote Code Execution Vulnerability." This affects Microsoft Exchange Server. | HIGH 7.8EPSS 19.3% | 10 October 2018 |
| CVE-2018-14649 | This allows unauthenticated attackers to access this debug shell and escalate privileges. | CRITICAL 9.8EPSS 11.7% | 9 October 2018 |
| CVE-2018-18069 | process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php. | MEDIUM 6.1EPSS 13.2% | 8 October 2018 |
| CVE-2018-18065 | _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | MEDIUM 6.5EPSS 17.2% | 8 October 2018 |
| CVE-2018-17442 | An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code. | HIGH 8.8EPSS 14.2% | 8 October 2018 |
| CVE-2018-17440 | They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). | CRITICAL 9.8EPSS 38.5% | 8 October 2018 |
| CVE-2012-6710 | ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php. | CRITICAL 9.8EPSS 25.0% | 7 October 2018 |
| CVE-2018-17456 | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a… | CRITICAL 9.8EPSS 97.4% | 6 October 2018 |
| CVE-2018-15379 | A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. | CRITICAL 9.8EPSS 86.2% | 5 October 2018 |
| CVE-2018-0476 | A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. | MEDIUM 5.9EPSS 13.7% | 5 October 2018 |
| CVE-2018-0472 | A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the device to reload. | HIGH 8.6EPSS 16.2% | 5 October 2018 |
| CVE-2018-11784 | When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause… | MEDIUM 4.3EPSS 94.5% | 4 October 2018 |
| CVE-2018-17553 | An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authenticated attackers to achieve remote code execution via a POST request with engine=picnik and… | HIGH 8.8EPSS 79.0% | 3 October 2018 |
| CVE-2018-17552 | SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie. | CRITICAL 9.8EPSS 84.1% | 3 October 2018 |
| CVE-2018-17408 | Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute arbitrary code via a crafted CSV file that is accessed through the Import CSV File menu. | HIGH 7.8EPSS 19.0% | 3 October 2018 |
| CVE-2018-5393 | The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. | CRITICAL 9.8EPSS 12.9% | 28 September 2018 |
| CVE-2018-16055 | An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user input from the $_POST parameters "ifdescr" and "ipv" to a shell without escaping the contents of… | HIGH 8.8EPSS 11.2% | 26 September 2018 |
| CVE-2018-15531 | JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java. | CRITICAL 9.8EPSS 27.9% | 26 September 2018 |
| CVE-2018-16364 | A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share. | HIGH 8.1EPSS 17.9% | 26 September 2018 |
| CVE-2018-14634 | Linux Kernel Integer Overflow Vulnerability | KEVHIGH 7.8EPSS 14.7% | 25 September 2018 |
| CVE-2018-11763 | In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. | MEDIUM 5.9EPSS 50.8% | 25 September 2018 |
| CVE-2018-15965 | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. | CRITICAL 9.8EPSS 25.9% | 25 September 2018 |
| CVE-2018-15961 | Adobe ColdFusion Unrestricted File Upload Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 25 September 2018 |
| CVE-2018-15959 | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. | CRITICAL 9.8EPSS 25.9% | 25 September 2018 |
| CVE-2018-15958 | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. | CRITICAL 9.8EPSS 25.9% | 25 September 2018 |
| CVE-2018-15957 | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. | CRITICAL 9.8EPSS 28.2% | 25 September 2018 |
| CVE-2018-12850 | Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. | HIGH 7.5EPSS 33.6% | 25 September 2018 |
| CVE-2018-12849 | Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. | HIGH 7.5EPSS 33.6% | 25 September 2018 |
| CVE-2018-12848 | Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds write vulnerability. | CRITICAL 9.8EPSS 34.7% | 25 September 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.