SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,527 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 142 of 348

CVESummaryPriorityPublished
CVE-2018-8513A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 14.2%10 October 2018
CVE-2018-8511A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 14.2%10 October 2018
CVE-2018-8510A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 14.2%10 October 2018
CVE-2018-8509A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge.HIGH 7.5EPSS 12.8%10 October 2018
CVE-2018-8505A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 14.2%10 October 2018
CVE-2018-8504A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Office 365…HIGH 8.8EPSS 19.7%10 October 2018
CVE-2018-8503A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 14.2%10 October 2018
CVE-2018-8502A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office,…HIGH 8.8EPSS 20.5%10 October 2018
CVE-2018-8501A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in Protected View, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Office 365 ProPlus,…HIGH 8.8EPSS 19.7%10 October 2018
CVE-2018-8500A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore.CRITICAL 9.8EPSS 18.5%10 October 2018
CVE-2018-8495A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.HIGH 7.5EPSS 50.7%10 October 2018
CVE-2018-8494A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008,…HIGH 8.8EPSS 22.1%10 October 2018
CVE-2018-8491A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11.HIGH 7.5EPSS 12.8%10 October 2018
CVE-2018-8473A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 14.2%10 October 2018
CVE-2018-8472An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka "Windows GDI Information Disclosure…MEDIUM 5.5EPSS 18.9%10 October 2018
CVE-2018-8460A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11.HIGH 7.5EPSS 20.7%10 October 2018
CVE-2018-8453Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 70.0%10 October 2018
CVE-2018-8432A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Microsoft Office Word…HIGH 7.8EPSS 19.5%10 October 2018
CVE-2018-8423A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows…HIGH 7.8EPSS 32.2%10 October 2018
CVE-2018-8413A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows Theme API Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019,…HIGH 7.8EPSS 46.3%10 October 2018
CVE-2018-8292An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1,…HIGH 7.5EPSS 14.8%10 October 2018
CVE-2018-8265A remote code execution vulnerability exists in the way Microsoft Exchange software parses specially crafted email messages, aka "Microsoft Exchange Remote Code Execution Vulnerability." This affects Microsoft Exchange Server.HIGH 7.8EPSS 19.3%10 October 2018
CVE-2018-14649This allows unauthenticated attackers to access this debug shell and escalate privileges.CRITICAL 9.8EPSS 11.7%9 October 2018
CVE-2018-18069process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php.MEDIUM 6.1EPSS 13.2%8 October 2018
CVE-2018-18065_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.MEDIUM 6.5EPSS 17.2%8 October 2018
CVE-2018-17442An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.HIGH 8.8EPSS 14.2%8 October 2018
CVE-2018-17440They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin).CRITICAL 9.8EPSS 38.5%8 October 2018
CVE-2012-6710ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.CRITICAL 9.8EPSS 25.0%7 October 2018
CVE-2018-17456Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a…CRITICAL 9.8EPSS 97.4%6 October 2018
CVE-2018-15379A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file.CRITICAL 9.8EPSS 86.2%5 October 2018
CVE-2018-0476A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.MEDIUM 5.9EPSS 13.7%5 October 2018
CVE-2018-0472A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the device to reload.HIGH 8.6EPSS 16.2%5 October 2018
CVE-2018-11784When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause…MEDIUM 4.3EPSS 94.5%4 October 2018
CVE-2018-17553An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authenticated attackers to achieve remote code execution via a POST request with engine=picnik and…HIGH 8.8EPSS 79.0%3 October 2018
CVE-2018-17552SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.CRITICAL 9.8EPSS 84.1%3 October 2018
CVE-2018-17408Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute arbitrary code via a crafted CSV file that is accessed through the Import CSV File menu.HIGH 7.8EPSS 19.0%3 October 2018
CVE-2018-5393The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices.CRITICAL 9.8EPSS 12.9%28 September 2018
CVE-2018-16055An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user input from the $_POST parameters "ifdescr" and "ipv" to a shell without escaping the contents of…HIGH 8.8EPSS 11.2%26 September 2018
CVE-2018-15531JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.CRITICAL 9.8EPSS 27.9%26 September 2018
CVE-2018-16364A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.HIGH 8.1EPSS 17.9%26 September 2018
CVE-2018-14634Linux Kernel Integer Overflow VulnerabilityKEVHIGH 7.8EPSS 14.7%25 September 2018
CVE-2018-11763In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect.MEDIUM 5.9EPSS 50.8%25 September 2018
CVE-2018-15965Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability.CRITICAL 9.8EPSS 25.9%25 September 2018
CVE-2018-15961Adobe ColdFusion Unrestricted File Upload VulnerabilityKEVCRITICAL 9.8EPSS 100.0%25 September 2018
CVE-2018-15959Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability.CRITICAL 9.8EPSS 25.9%25 September 2018
CVE-2018-15958Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability.CRITICAL 9.8EPSS 25.9%25 September 2018
CVE-2018-15957Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability.CRITICAL 9.8EPSS 28.2%25 September 2018
CVE-2018-12850Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability.HIGH 7.5EPSS 33.6%25 September 2018
CVE-2018-12849Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability.HIGH 7.5EPSS 33.6%25 September 2018
CVE-2018-12848Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds write vulnerability.CRITICAL 9.8EPSS 34.7%25 September 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.