Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,527 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 143 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-12840 | Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. | HIGH 7.5EPSS 28.8% | 25 September 2018 |
| CVE-2018-14647 | This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. | HIGH 7.5EPSS 10.9% | 25 September 2018 |
| CVE-2018-17281 | There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. | HIGH 7.5EPSS 53.4% | 24 September 2018 |
| CVE-2018-16299 | The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter. | HIGH 7.5EPSS 44.4% | 24 September 2018 |
| CVE-2018-16283 | The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. | CRITICAL 9.8EPSS 63.1% | 24 September 2018 |
| CVE-2018-17173 | LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. | CRITICAL 9.8EPSS 56.2% | 21 September 2018 |
| CVE-2018-16833 | Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI. | MEDIUM 6.1EPSS 65.4% | 21 September 2018 |
| CVE-2018-16793 | Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page. | HIGH 8.6EPSS 11.3% | 21 September 2018 |
| CVE-2018-17283 | Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via… | HIGH 7.5EPSS 66.3% | 21 September 2018 |
| CVE-2018-16752 | LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. | HIGH 8.8EPSS 42.7% | 20 September 2018 |
| CVE-2018-14829 | This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. | CRITICAL 9.8EPSS 16.1% | 20 September 2018 |
| CVE-2018-17254 | The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter. | CRITICAL 9.8EPSS 83.0% | 20 September 2018 |
| CVE-2018-17243 | Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection. | CRITICAL 9.8EPSS 74.4% | 20 September 2018 |
| CVE-2018-17207 | By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution. | CRITICAL 9.8EPSS 60.1% | 19 September 2018 |
| CVE-2018-1149 | cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP requests. | CRITICAL 9.8EPSS 15.1% | 19 September 2018 |
| CVE-2018-16670 | There is PLC status disclosure due to lack of authentication for /html/devstat.html. | MEDIUM 5.3EPSS 24.6% | 18 September 2018 |
| CVE-2018-1000802 | Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service,… | CRITICAL 9.8EPSS 20.1% | 18 September 2018 |
| CVE-2018-17153 | It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. | CRITICAL 9.8EPSS 86.6% | 18 September 2018 |
| CVE-2018-11780 | A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. | CRITICAL 9.8EPSS 10.8% | 17 September 2018 |
| CVE-2018-17128 | A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode. | MEDIUM 5.4EPSS 74.8% | 17 September 2018 |
| CVE-2018-16706 | LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080. | HIGH 7.5EPSS 22.3% | 14 September 2018 |
| CVE-2018-16288 | LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs. | HIGH 8.6EPSS 35.8% | 14 September 2018 |
| CVE-2018-16287 | LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs. | CRITICAL 9.8EPSS 19.6% | 14 September 2018 |
| CVE-2018-16286 | LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits. | CRITICAL 9.8EPSS 21.5% | 14 September 2018 |
| CVE-2018-12086 | Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests. | HIGH 7.5EPSS 11.6% | 14 September 2018 |
| CVE-2018-17057 | Attackers can trigger deserialization of arbitrary data via the phar:// wrapper. | CRITICAL 9.8EPSS 26.2% | 14 September 2018 |
| CVE-2018-8475 | A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008,… | HIGH 8.8EPSS 15.9% | 13 September 2018 |
| CVE-2018-8474 | A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync. | HIGH 7.5EPSS 38.2% | 13 September 2018 |
| CVE-2018-8469 | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. | HIGH 7.4EPSS 15.4% | 13 September 2018 |
| CVE-2018-8468 | An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows… | MEDIUM 4.7EPSS 11.8% | 13 September 2018 |
| CVE-2018-8467 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 69.0% | 13 September 2018 |
| CVE-2018-8466 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 69.0% | 13 September 2018 |
| CVE-2018-8465 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.6% | 13 September 2018 |
| CVE-2018-8464 | An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge PDF Remote Code Execution Vulnerability." This affects Microsoft Edge. | HIGH 7.5EPSS 42.6% | 13 September 2018 |
| CVE-2018-8463 | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. | HIGH 7.4EPSS 15.4% | 13 September 2018 |
| CVE-2018-8461 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. | HIGH 7.5EPSS 12.9% | 13 September 2018 |
| CVE-2018-8459 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.6% | 13 September 2018 |
| CVE-2018-8457 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10. | HIGH 7.5EPSS 13.1% | 13 September 2018 |
| CVE-2018-8456 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.6% | 13 September 2018 |
| CVE-2018-8447 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. | HIGH 7.5EPSS 12.9% | 13 September 2018 |
| CVE-2018-8440 | Microsoft Windows Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 18.4% | 13 September 2018 |
| CVE-2018-8430 | A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted PDF file, aka "Word PDF Remote Code Execution Vulnerability." This affects Microsoft Word, Microsoft Office. | HIGH 7.8EPSS 23.0% | 13 September 2018 |
| CVE-2018-8429 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. | MEDIUM 5.5EPSS 12.3% | 13 September 2018 |
| CVE-2018-8424 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | MEDIUM 6.5EPSS 13.0% | 13 September 2018 |
| CVE-2018-8421 | A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET… | CRITICAL 9.8EPSS 29.1% | 13 September 2018 |
| CVE-2018-8420 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008,… | HIGH 8.8EPSS 48.9% | 13 September 2018 |
| CVE-2018-8393 | A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server… | HIGH 7.8EPSS 22.5% | 13 September 2018 |
| CVE-2018-8392 | A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server… | HIGH 7.8EPSS 22.8% | 13 September 2018 |
| CVE-2018-8391 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. | HIGH 7.5EPSS 11.0% | 13 September 2018 |
| CVE-2018-8367 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.9% | 13 September 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.