SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,535 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 145 of 348

CVESummaryPriorityPublished
CVE-2018-8380A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 14.4%15 August 2018
CVE-2018-8379A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel.HIGH 7.8EPSS 17.1%15 August 2018
CVE-2018-8376A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft PowerPoint.HIGH 8.8EPSS 18.2%15 August 2018
CVE-2018-8375A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office,…HIGH 7.8EPSS 16.2%15 August 2018
CVE-2018-8373Microsoft Scripting Engine Memory Corruption VulnerabilityKEVHIGH 7.5EPSS 61.9%15 August 2018
CVE-2018-8372A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge.HIGH 7.5EPSS 24.8%15 August 2018
CVE-2018-8371A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet…HIGH 7.5EPSS 14.4%15 August 2018
CVE-2018-8359A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore.HIGH 7.5EPSS 14.5%15 August 2018
CVE-2018-8355A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge.HIGH 7.5EPSS 68.2%15 August 2018
CVE-2018-8353A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet…HIGH 7.5EPSS 67.7%15 August 2018
CVE-2018-8350A remote code execution vulnerability exists when Microsoft Windows PDF Library improperly handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.HIGH 8.8EPSS 18.6%15 August 2018
CVE-2018-8349A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows…HIGH 8.8EPSS 22.7%15 August 2018
CVE-2018-8346A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.HIGH 8.8EPSS 18.8%15 August 2018
CVE-2018-8345A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows…HIGH 7.5EPSS 13.6%15 August 2018
CVE-2018-8344A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,…HIGH 8.8EPSS 21.8%15 August 2018
CVE-2018-8316A remote code execution vulnerability exists when Internet Explorer improperly validates hyperlinks before loading executable libraries, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer 11, Internet Explorer 10.HIGH 7.5EPSS 13.6%15 August 2018
CVE-2018-8302A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.CRITICAL 9.8EPSS 25.5%15 August 2018
CVE-2018-8273A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.CRITICAL 9.8EPSS 29.2%15 August 2018
CVE-2018-8266A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.HIGH 7.5EPSS 27.1%15 August 2018
CVE-2018-15156OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/faxq.php after modifying the "hylafax_server" global variable in…HIGH 8.8EPSS 10.2%15 August 2018
CVE-2018-15155OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/fax_dispatch.php after modifying the "hylafax_enscript" global…HIGH 8.8EPSS 10.2%15 August 2018
CVE-2018-15154OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/billing/sl_eob_search.php after modifying the "print_command" global…HIGH 8.8EPSS 10.2%15 August 2018
CVE-2018-15153OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/main/daemon_frame.php after modifying the "hylafax_server" global variable…HIGH 8.8EPSS 61.6%15 August 2018
CVE-2018-15152Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4)…CRITICAL 9.1EPSS 25.9%15 August 2018
CVE-2018-15138Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.HIGH 7.5EPSS 12.9%15 August 2018
CVE-2016-4975Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir.MEDIUM 6.1EPSS 19.8%14 August 2018
CVE-2018-15142Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to execute arbitrary PHP code by writing a file with a PHP extension via the "docid" and "content"…HIGH 8.8EPSS 18.2%13 August 2018
CVE-2018-15141Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to delete arbitrary files via the "docid" parameter when the mode is set to delete.MEDIUM 6.5EPSS 14.5%13 August 2018
CVE-2018-15140Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to read arbitrary files via the "docid" parameter when the mode is set to get.MEDIUM 6.5EPSS 16.7%13 August 2018
CVE-2018-15139Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and…HIGH 8.8EPSS 19.3%13 August 2018
CVE-2018-13417In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.CRITICAL 9.8EPSS 20.7%13 August 2018
CVE-2018-13415In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.CRITICAL 9.8EPSS 31.8%13 August 2018
CVE-2018-11770From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit.MEDIUM 4.2EPSS 65.8%13 August 2018
CVE-2018-5925A security vulnerability has been identified with certain HP Inkjet printers.HIGH 7.8EPSS 10.9%13 August 2018
CVE-2018-5924A security vulnerability has been identified with certain HP Inkjet printers.CRITICAL 9.8EPSS 12.2%13 August 2018
CVE-2018-10630For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it.CRITICAL 9.8EPSS 10.9%10 August 2018
CVE-2018-14028This allows for PHP files to be uploaded.HIGH 7.2EPSS 15.2%10 August 2018
CVE-2018-11492ASUS HG100 devices allow denial of service via an IPv4 packet flood.HIGH 7.5EPSS 11.4%10 August 2018
CVE-2018-10931It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC.CRITICAL 9.8EPSS 68.1%9 August 2018
CVE-2018-15133Laravel Deserialization of Untrusted Data VulnerabilityKEVHIGH 8.1EPSS 76.8%9 August 2018
CVE-2018-15137CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well.CRITICAL 9.8EPSS 18.2%8 August 2018
CVE-2018-7092A potential security vulnerability has been identified in HPE Intelligent Management Center Platform (IMC Plat) 7.3 E0506P09.HIGH 7.5EPSS 52.7%6 August 2018
CVE-2018-7074A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT 7.3 E0506P07.CRITICAL 9.8EPSS 16.7%6 August 2018
CVE-2018-5390Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.HIGH 7.5EPSS 73.7%6 August 2018
CVE-2018-14716A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.HIGH 7.5EPSS 33.0%6 August 2018
CVE-2017-8990A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Service Manager (WSM) Software earlier than version WSM 7.3 (E0506).CRITICAL 9.8EPSS 16.7%6 August 2018
CVE-2016-8527Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS).MEDIUM 6.1EPSS 13.2%6 August 2018
CVE-2016-4404A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2.CRITICAL 9.8EPSS 14.8%6 August 2018
CVE-2016-4403A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2.CRITICAL 9.8EPSS 13.6%6 August 2018
CVE-2016-4402A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2.CRITICAL 9.8EPSS 16.4%6 August 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.