SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,535 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 144 of 348

CVESummaryPriorityPublished
CVE-2018-8354A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 14.6%13 September 2018
CVE-2018-8332A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2,…HIGH 8.8EPSS 19.1%13 September 2018
CVE-2018-8331A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office.HIGH 7.8EPSS 19.5%13 September 2018
CVE-2018-8269A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Service Vulnerability." This affects Microsoft.Data.OData.HIGH 7.5EPSS 26.8%13 September 2018
CVE-2018-7921Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability.MEDIUM 6.5EPSS 13.2%12 September 2018
CVE-2017-1084This results in the possibility a poorly written process could be cause a stack overflow.HIGH 7.5EPSS 15.3%12 September 2018
CVE-2018-16836Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a…CRITICAL 9.8EPSS 61.4%11 September 2018
CVE-2018-16763FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.CRITICAL 9.8EPSS 82.9%9 September 2018
CVE-2018-16059Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.MEDIUM 5.3EPSS 29.8%7 September 2018
CVE-2018-1756IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection.HIGH 7.5EPSS 10.6%7 September 2018
CVE-2018-5391The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly.HIGH 7.5EPSS 32.4%6 September 2018
CVE-2018-16144The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection due to improper sanitization of the rancid_password parameter.CRITICAL 9.8EPSS 32.7%5 September 2018
CVE-2015-9266The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques.CRITICAL 9.8EPSS 74.0%5 September 2018
CVE-2018-14618curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code.CRITICAL 9.8EPSS 11.1%5 September 2018
CVE-2018-16509Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.HIGH 7.8EPSS 92.5%5 September 2018
CVE-2018-16323If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.MEDIUM 6.5EPSS 49.3%1 September 2018
CVE-2018-15745Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.HIGH 7.5EPSS 97.7%30 August 2018
CVE-2018-16159The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.CRITICAL 9.8EPSS 49.9%30 August 2018
CVE-2018-15691Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.CRITICAL 9.8EPSS 16.8%30 August 2018
CVE-2018-16158Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH…CRITICAL 9.8EPSS 34.9%30 August 2018
CVE-2018-16133Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.MEDIUM 5.3EPSS 39.3%29 August 2018
CVE-2018-12710Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.HIGH 8.0EPSS 76.5%29 August 2018
CVE-2018-15727Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.CRITICAL 9.8EPSS 64.3%29 August 2018
CVE-2018-12827Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability.HIGH 7.5EPSS 32.0%29 August 2018
CVE-2018-12824Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability.MEDIUM 5.9EPSS 10.9%29 August 2018
CVE-2018-15839D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.CRITICAL 9.8EPSS 45.3%28 August 2018
CVE-2015-9263It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.CRITICAL 9.8EPSS 13.3%27 August 2018
CVE-2018-15877The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip parameter of a wp-admin/admin.php?page=plainview_activity_monitor&tab=activity_tools request.HIGH 8.8EPSS 77.0%26 August 2018
CVE-2018-3786A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument.CRITICAL 9.8EPSS 12.3%24 August 2018
CVE-2018-15535/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to…HIGH 7.5EPSS 45.2%24 August 2018
CVE-2018-15120libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.MEDIUM 6.5EPSS 11.5%24 August 2018
CVE-2018-15685GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code…HIGH 8.1EPSS 10.4%23 August 2018
CVE-2018-1140A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server.MEDIUM 6.5EPSS 10.8%22 August 2018
CVE-2018-11776Apache Struts Remote Code Execution VulnerabilityKEVHIGH 8.1EPSS 100.0%22 August 2018
CVE-2018-15534Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a direct request for /statistics/gscsetup.xml on TCP port 12003.CRITICAL 9.8EPSS 32.4%21 August 2018
CVE-2018-1000226Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can…CRITICAL 9.8EPSS 12.6%20 August 2018
CVE-2018-15473OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and…MEDIUM 5.3EPSS 98.6%17 August 2018
CVE-2018-14058Pimcore before 5.3.0 allows SQL Injection via the REST web service API.MEDIUM 6.5EPSS 28.9%17 August 2018
CVE-2018-11511The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.CRITICAL 9.8EPSS 11.3%16 August 2018
CVE-2018-11509This may allow an attacker to login and upload a webshell.CRITICAL 9.8EPSS 12.6%16 August 2018
CVE-2018-14007Citrix XenServer 7.1 and newer allows Directory Traversal.CRITICAL 9.8EPSS 56.1%15 August 2018
CVE-2018-8414Microsoft Windows Shell Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 74.0%15 August 2018
CVE-2018-8403A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka "Microsoft Browser Memory Corruption Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10.HIGH 7.5EPSS 12.6%15 August 2018
CVE-2018-8397A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.HIGH 8.8EPSS 67.9%15 August 2018
CVE-2018-8390A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 14.4%15 August 2018
CVE-2018-8389A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet…HIGH 7.5EPSS 28.6%15 August 2018
CVE-2018-8385A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, ChakraCore, Internet Explorer 11,…HIGH 7.5EPSS 14.2%15 August 2018
CVE-2018-8384A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore.HIGH 7.5EPSS 62.1%15 August 2018
CVE-2018-8382An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.MEDIUM 5.5EPSS 12.3%15 August 2018
CVE-2018-8381A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 14.4%15 August 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.