Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,535 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 146 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2016-4391 | A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0. | CRITICAL 9.8EPSS 20.4% | 6 August 2018 |
| CVE-2017-6920 | Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations. | CRITICAL 9.8EPSS 20.5% | 6 August 2018 |
| CVE-2018-14933 | NUUO NVRmini Devices OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 94.9% | 4 August 2018 |
| CVE-2018-14417 | A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. | CRITICAL 9.8EPSS 89.6% | 4 August 2018 |
| CVE-2018-14912 | cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request. | HIGH 7.5EPSS 92.9% | 3 August 2018 |
| CVE-2018-14728 | upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter. | CRITICAL 9.8EPSS 76.5% | 3 August 2018 |
| CVE-2018-14773 | An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. | MEDIUM 6.5EPSS 58.1% | 3 August 2018 |
| CVE-2018-14574 | django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect. | MEDIUM 6.1EPSS 25.5% | 3 August 2018 |
| CVE-2018-13416 | In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. | CRITICAL 9.8EPSS 20.2% | 3 August 2018 |
| CVE-2018-8037 | If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. | MEDIUM 5.9EPSS 11.3% | 2 August 2018 |
| CVE-2018-1336 | An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. | HIGH 7.5EPSS 20.6% | 2 August 2018 |
| CVE-2018-8032 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | MEDIUM 6.1EPSS 10.6% | 2 August 2018 |
| CVE-2018-14847 | MikroTik Router OS Directory Traversal Vulnerability | KEVCRITICAL 9.1EPSS 96.1% | 2 August 2018 |
| CVE-2018-3924 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. | HIGH 7.8EPSS 44.1% | 1 August 2018 |
| CVE-2018-8034 | The host name verification when using TLS with the WebSocket client was missing. | HIGH 7.5EPSS 21.3% | 1 August 2018 |
| CVE-2018-10618 | The device generates a weak password hash that is easily cracked, allowing a remote attacker to obtain the password for the device. | CRITICAL 9.8EPSS 10.1% | 1 August 2018 |
| CVE-2018-14767 | In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault and crash. | CRITICAL 9.8EPSS 29.3% | 31 July 2018 |
| CVE-2017-15118 | A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack… | CRITICAL 9.8EPSS 11.9% | 27 July 2018 |
| CVE-2017-15120 | An unauthenticated remote attacker could cause a denial of service. | HIGH 7.5EPSS 51.8% | 27 July 2018 |
| CVE-2017-12150 | A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text. | HIGH 7.4EPSS 13.3% | 26 July 2018 |
| CVE-2018-14493 | Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name. | MEDIUM 6.1EPSS 40.9% | 25 July 2018 |
| CVE-2018-1002208 | SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. | MEDIUM 5.5EPSS 10.2% | 25 July 2018 |
| CVE-2018-1002206 | SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. | MEDIUM 5.5EPSS 10.1% | 25 July 2018 |
| CVE-2018-1002205 | DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. | MEDIUM 5.5EPSS 10.4% | 25 July 2018 |
| CVE-2018-1002204 | adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. | MEDIUM 5.5EPSS 15.4% | 25 July 2018 |
| CVE-2018-1002203 | unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. | MEDIUM 5.5EPSS 11.9% | 25 July 2018 |
| CVE-2018-1002202 | zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. | MEDIUM 6.5EPSS 13.1% | 25 July 2018 |
| CVE-2018-1002201 | zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. | MEDIUM 5.5EPSS 10.3% | 25 July 2018 |
| CVE-2018-1002200 | plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. | MEDIUM 5.5EPSS 13.2% | 25 July 2018 |
| CVE-2016-5649 | A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. | CRITICAL 9.8EPSS 24.4% | 24 July 2018 |
| CVE-2018-14335 | Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file. | MEDIUM 6.5EPSS 13.4% | 24 July 2018 |
| CVE-2018-14328 | Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for /dashboard/addplan, /dashboard/paywithcard/charge, /dashboard/withdrawal, or /privacy&terms,… | CRITICAL 9.8EPSS 10.7% | 23 July 2018 |
| CVE-2018-1999002 | A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the… | HIGH 7.5EPSS 86.6% | 23 July 2018 |
| CVE-2018-1999001 | A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins… | HIGH 8.8EPSS 18.1% | 23 July 2018 |
| CVE-2018-5070 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. | CRITICAL 9.8EPSS 25.4% | 20 July 2018 |
| CVE-2018-5069 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. | CRITICAL 9.8EPSS 25.4% | 20 July 2018 |
| CVE-2018-5068 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 27.8% | 20 July 2018 |
| CVE-2018-5067 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. | HIGH 8.8EPSS 11.3% | 20 July 2018 |
| CVE-2018-5065 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. | HIGH 8.8EPSS 31.5% | 20 July 2018 |
| CVE-2018-5064 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. | CRITICAL 9.8EPSS 25.4% | 20 July 2018 |
| CVE-2018-5063 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. | MEDIUM 6.5EPSS 31.0% | 20 July 2018 |
| CVE-2018-5058 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. | HIGH 8.8EPSS 11.3% | 20 July 2018 |
| CVE-2018-5052 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. | HIGH 8.8EPSS 11.3% | 20 July 2018 |
| CVE-2018-5045 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. | HIGH 8.8EPSS 11.3% | 20 July 2018 |
| CVE-2018-5041 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. | HIGH 8.8EPSS 11.3% | 20 July 2018 |
| CVE-2018-5040 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. | HIGH 8.8EPSS 11.3% | 20 July 2018 |
| CVE-2018-5038 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. | HIGH 8.8EPSS 11.3% | 20 July 2018 |
| CVE-2018-5036 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. | HIGH 8.8EPSS 11.3% | 20 July 2018 |
| CVE-2018-5032 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. | HIGH 8.8EPSS 10.8% | 20 July 2018 |
| CVE-2018-5028 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. | HIGH 8.8EPSS 11.3% | 20 July 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.