Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,535 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 145 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-8380 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 14.4% | 15 August 2018 |
| CVE-2018-8379 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel. | HIGH 7.8EPSS 17.1% | 15 August 2018 |
| CVE-2018-8376 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft PowerPoint. | HIGH 8.8EPSS 18.2% | 15 August 2018 |
| CVE-2018-8375 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office,… | HIGH 7.8EPSS 16.2% | 15 August 2018 |
| CVE-2018-8373 | Microsoft Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 61.9% | 15 August 2018 |
| CVE-2018-8372 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. | HIGH 7.5EPSS 24.8% | 15 August 2018 |
| CVE-2018-8371 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet… | HIGH 7.5EPSS 14.4% | 15 August 2018 |
| CVE-2018-8359 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. | HIGH 7.5EPSS 14.5% | 15 August 2018 |
| CVE-2018-8355 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. | HIGH 7.5EPSS 68.2% | 15 August 2018 |
| CVE-2018-8353 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet… | HIGH 7.5EPSS 67.7% | 15 August 2018 |
| CVE-2018-8350 | A remote code execution vulnerability exists when Microsoft Windows PDF Library improperly handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10. | HIGH 8.8EPSS 18.6% | 15 August 2018 |
| CVE-2018-8349 | A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows… | HIGH 8.8EPSS 22.7% | 15 August 2018 |
| CVE-2018-8346 | A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. | HIGH 8.8EPSS 18.8% | 15 August 2018 |
| CVE-2018-8345 | A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows… | HIGH 7.5EPSS 13.6% | 15 August 2018 |
| CVE-2018-8344 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 8.8EPSS 21.8% | 15 August 2018 |
| CVE-2018-8316 | A remote code execution vulnerability exists when Internet Explorer improperly validates hyperlinks before loading executable libraries, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer 11, Internet Explorer 10. | HIGH 7.5EPSS 13.6% | 15 August 2018 |
| CVE-2018-8302 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. | CRITICAL 9.8EPSS 25.5% | 15 August 2018 |
| CVE-2018-8273 | A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server. | CRITICAL 9.8EPSS 29.2% | 15 August 2018 |
| CVE-2018-8266 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 27.1% | 15 August 2018 |
| CVE-2018-15156 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/faxq.php after modifying the "hylafax_server" global variable in… | HIGH 8.8EPSS 10.2% | 15 August 2018 |
| CVE-2018-15155 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/fax_dispatch.php after modifying the "hylafax_enscript" global… | HIGH 8.8EPSS 10.2% | 15 August 2018 |
| CVE-2018-15154 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/billing/sl_eob_search.php after modifying the "print_command" global… | HIGH 8.8EPSS 10.2% | 15 August 2018 |
| CVE-2018-15153 | OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/main/daemon_frame.php after modifying the "hylafax_server" global variable… | HIGH 8.8EPSS 61.6% | 15 August 2018 |
| CVE-2018-15152 | Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4)… | CRITICAL 9.1EPSS 25.9% | 15 August 2018 |
| CVE-2018-15138 | Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs. | HIGH 7.5EPSS 12.9% | 15 August 2018 |
| CVE-2016-4975 | Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. | MEDIUM 6.1EPSS 19.8% | 14 August 2018 |
| CVE-2018-15142 | Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to execute arbitrary PHP code by writing a file with a PHP extension via the "docid" and "content"… | HIGH 8.8EPSS 18.2% | 13 August 2018 |
| CVE-2018-15141 | Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to delete arbitrary files via the "docid" parameter when the mode is set to delete. | MEDIUM 6.5EPSS 14.5% | 13 August 2018 |
| CVE-2018-15140 | Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to read arbitrary files via the "docid" parameter when the mode is set to get. | MEDIUM 6.5EPSS 16.7% | 13 August 2018 |
| CVE-2018-15139 | Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and… | HIGH 8.8EPSS 19.3% | 13 August 2018 |
| CVE-2018-13417 | In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. | CRITICAL 9.8EPSS 20.7% | 13 August 2018 |
| CVE-2018-13415 | In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. | CRITICAL 9.8EPSS 31.8% | 13 August 2018 |
| CVE-2018-11770 | From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. | MEDIUM 4.2EPSS 65.8% | 13 August 2018 |
| CVE-2018-5925 | A security vulnerability has been identified with certain HP Inkjet printers. | HIGH 7.8EPSS 10.9% | 13 August 2018 |
| CVE-2018-5924 | A security vulnerability has been identified with certain HP Inkjet printers. | CRITICAL 9.8EPSS 12.2% | 13 August 2018 |
| CVE-2018-10630 | For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. | CRITICAL 9.8EPSS 10.9% | 10 August 2018 |
| CVE-2018-14028 | This allows for PHP files to be uploaded. | HIGH 7.2EPSS 15.2% | 10 August 2018 |
| CVE-2018-11492 | ASUS HG100 devices allow denial of service via an IPv4 packet flood. | HIGH 7.5EPSS 11.4% | 10 August 2018 |
| CVE-2018-10931 | It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. | CRITICAL 9.8EPSS 68.1% | 9 August 2018 |
| CVE-2018-15133 | Laravel Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.1EPSS 76.8% | 9 August 2018 |
| CVE-2018-15137 | CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. | CRITICAL 9.8EPSS 18.2% | 8 August 2018 |
| CVE-2018-7092 | A potential security vulnerability has been identified in HPE Intelligent Management Center Platform (IMC Plat) 7.3 E0506P09. | HIGH 7.5EPSS 52.7% | 6 August 2018 |
| CVE-2018-7074 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT 7.3 E0506P07. | CRITICAL 9.8EPSS 16.7% | 6 August 2018 |
| CVE-2018-5390 | Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. | HIGH 7.5EPSS 73.7% | 6 August 2018 |
| CVE-2018-14716 | A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code. | HIGH 7.5EPSS 33.0% | 6 August 2018 |
| CVE-2017-8990 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Service Manager (WSM) Software earlier than version WSM 7.3 (E0506). | CRITICAL 9.8EPSS 16.7% | 6 August 2018 |
| CVE-2016-8527 | Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). | MEDIUM 6.1EPSS 13.2% | 6 August 2018 |
| CVE-2016-4404 | A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. | CRITICAL 9.8EPSS 14.8% | 6 August 2018 |
| CVE-2016-4403 | A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. | CRITICAL 9.8EPSS 13.6% | 6 August 2018 |
| CVE-2016-4402 | A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. | CRITICAL 9.8EPSS 16.4% | 6 August 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.