SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,535 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 146 of 348

CVESummaryPriorityPublished
CVE-2016-4391A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.CRITICAL 9.8EPSS 20.4%6 August 2018
CVE-2017-6920Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.CRITICAL 9.8EPSS 20.5%6 August 2018
CVE-2018-14933NUUO NVRmini Devices OS Command Injection Vulnerability KEVCRITICAL 9.8EPSS 94.9%4 August 2018
CVE-2018-14417A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3.CRITICAL 9.8EPSS 89.6%4 August 2018
CVE-2018-14912cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.HIGH 7.5EPSS 92.9%3 August 2018
CVE-2018-14728upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.CRITICAL 9.8EPSS 76.5%3 August 2018
CVE-2018-14773An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2.MEDIUM 6.5EPSS 58.1%3 August 2018
CVE-2018-14574django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.MEDIUM 6.1EPSS 25.5%3 August 2018
CVE-2018-13416In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.CRITICAL 9.8EPSS 20.2%3 August 2018
CVE-2018-8037If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user.MEDIUM 5.9EPSS 11.3%2 August 2018
CVE-2018-1336An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service.HIGH 7.5EPSS 20.6%2 August 2018
CVE-2018-8032Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.MEDIUM 6.1EPSS 10.6%2 August 2018
CVE-2018-14847MikroTik Router OS Directory Traversal VulnerabilityKEVCRITICAL 9.1EPSS 96.1%2 August 2018
CVE-2018-3924An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096.HIGH 7.8EPSS 44.1%1 August 2018
CVE-2018-8034The host name verification when using TLS with the WebSocket client was missing.HIGH 7.5EPSS 21.3%1 August 2018
CVE-2018-10618The device generates a weak password hash that is easily cracked, allowing a remote attacker to obtain the password for the device.CRITICAL 9.8EPSS 10.1%1 August 2018
CVE-2018-14767In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault and crash.CRITICAL 9.8EPSS 29.3%31 July 2018
CVE-2017-15118A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack…CRITICAL 9.8EPSS 11.9%27 July 2018
CVE-2017-15120An unauthenticated remote attacker could cause a denial of service.HIGH 7.5EPSS 51.8%27 July 2018
CVE-2017-12150A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.HIGH 7.4EPSS 13.3%26 July 2018
CVE-2018-14493Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name.MEDIUM 6.1EPSS 40.9%25 July 2018
CVE-2018-1002208SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction.MEDIUM 5.5EPSS 10.2%25 July 2018
CVE-2018-1002206SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction.MEDIUM 5.5EPSS 10.1%25 July 2018
CVE-2018-1002205DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction.MEDIUM 5.5EPSS 10.4%25 July 2018
CVE-2018-1002204adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction.MEDIUM 5.5EPSS 15.4%25 July 2018
CVE-2018-1002203unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction.MEDIUM 5.5EPSS 11.9%25 July 2018
CVE-2018-1002202zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction.MEDIUM 6.5EPSS 13.1%25 July 2018
CVE-2018-1002201zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction.MEDIUM 5.5EPSS 10.3%25 July 2018
CVE-2018-1002200plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction.MEDIUM 5.5EPSS 13.2%25 July 2018
CVE-2016-5649A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication.CRITICAL 9.8EPSS 24.4%24 July 2018
CVE-2018-14335Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.MEDIUM 6.5EPSS 13.4%24 July 2018
CVE-2018-14328Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for /dashboard/addplan, /dashboard/paywithcard/charge, /dashboard/withdrawal, or /privacy&terms,…CRITICAL 9.8EPSS 10.7%23 July 2018
CVE-2018-1999002A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the…HIGH 7.5EPSS 86.6%23 July 2018
CVE-2018-1999001A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins…HIGH 8.8EPSS 18.1%23 July 2018
CVE-2018-5070Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability.CRITICAL 9.8EPSS 25.4%20 July 2018
CVE-2018-5069Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability.CRITICAL 9.8EPSS 25.4%20 July 2018
CVE-2018-5068Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability.HIGH 7.5EPSS 27.8%20 July 2018
CVE-2018-5067Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 11.3%20 July 2018
CVE-2018-5065Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability.HIGH 8.8EPSS 31.5%20 July 2018
CVE-2018-5064Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability.CRITICAL 9.8EPSS 25.4%20 July 2018
CVE-2018-5063Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability.MEDIUM 6.5EPSS 31.0%20 July 2018
CVE-2018-5058Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 11.3%20 July 2018
CVE-2018-5052Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 11.3%20 July 2018
CVE-2018-5045Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 11.3%20 July 2018
CVE-2018-5041Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 11.3%20 July 2018
CVE-2018-5040Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 11.3%20 July 2018
CVE-2018-5038Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 11.3%20 July 2018
CVE-2018-5036Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 11.3%20 July 2018
CVE-2018-5032Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 10.8%20 July 2018
CVE-2018-5028Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 11.3%20 July 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.