SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,535 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 147 of 348

CVESummaryPriorityPublished
CVE-2018-5015Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 11.3%20 July 2018
CVE-2018-5007Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability.HIGH 8.8EPSS 18.0%20 July 2018
CVE-2018-5006Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability.HIGH 7.5EPSS 53.8%20 July 2018
CVE-2018-12815Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability.CRITICAL 9.8EPSS 11.0%20 July 2018
CVE-2018-12804Adobe Connect versions 9.7.5 and earlier have an Authentication Bypass vulnerability.CRITICAL 9.8EPSS 11.5%20 July 2018
CVE-2018-12798Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.CRITICAL 9.8EPSS 13.5%20 July 2018
CVE-2018-12794Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Type Confusion vulnerability.HIGH 8.8EPSS 15.9%20 July 2018
CVE-2018-12788Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability.HIGH 8.8EPSS 11.3%20 July 2018
CVE-2018-12782Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Double Free vulnerability.CRITICAL 9.8EPSS 11.2%20 July 2018
CVE-2018-12768Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability.HIGH 7.5EPSS 27.8%20 July 2018
CVE-2018-12767Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability.HIGH 7.5EPSS 27.8%20 July 2018
CVE-2018-12766Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability.HIGH 7.5EPSS 27.8%20 July 2018
CVE-2018-12765Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability.HIGH 7.5EPSS 27.8%20 July 2018
CVE-2018-12764Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability.MEDIUM 6.5EPSS 31.0%20 July 2018
CVE-2018-12755Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability.CRITICAL 9.8EPSS 25.3%20 July 2018
CVE-2018-12754Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability.CRITICAL 9.8EPSS 25.3%20 July 2018
CVE-2018-7602Drupal Core Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.2%19 July 2018
CVE-2018-14392The New Threads plugin before 1.2 for MyBB has XSS.MEDIUM 6.1EPSS 48.6%19 July 2018
CVE-2018-14364GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.CRITICAL 9.8EPSS 50.1%18 July 2018
CVE-2018-8011By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault.HIGH 7.5EPSS 56.0%18 July 2018
CVE-2018-2992Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).HIGH 7.1EPSS 35.5%18 July 2018
CVE-2018-2894Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services).CRITICAL 9.8EPSS 50.2%18 July 2018
CVE-2018-2893Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).CRITICAL 9.8EPSS 71.2%18 July 2018
CVE-2018-1612IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information.MEDIUM 5.8EPSS 57.0%17 July 2018
CVE-2018-13862Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attackers to reset the authentication via the "/xml/system/setAttribute.xml" URL, using the GET request "?id=0&attr=protectAccess&newValue=0"…CRITICAL 9.8EPSS 50.6%17 July 2018
CVE-2018-13859MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, allow unauthorized remote attackers to reset the authentication via the "/xml/system/setAttribute.xml" URL, using the GET request…CRITICAL 9.8EPSS 17.9%17 July 2018
CVE-2018-0710Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.HIGH 8.8EPSS 14.2%17 July 2018
CVE-2018-0709Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.HIGH 8.8EPSS 13.6%17 July 2018
CVE-2018-0708Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.HIGH 8.8EPSS 26.3%17 July 2018
CVE-2018-0707Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.HIGH 7.2EPSS 59.2%17 July 2018
CVE-2018-0706Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access sensitive information.HIGH 8.8EPSS 48.7%17 July 2018
CVE-2018-12584The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a denial of service (buffer overflow) or possibly execute arbitrary code when TLS communication is enabled.CRITICAL 9.8EPSS 24.6%16 July 2018
CVE-2018-13981The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default component that permits arbitrary upload of PHP files, because the formmailer widget blocks .php files but…CRITICAL 9.8EPSS 17.3%16 July 2018
CVE-2018-11716There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022,…CRITICAL 9.8EPSS 14.3%16 July 2018
CVE-2018-14064The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.CRITICAL 9.8EPSS 37.6%15 July 2018
CVE-2016-9498ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects.CRITICAL 9.8EPSS 21.2%13 July 2018
CVE-2016-6566An unauthenticated remote attacker may be able to modify the POST request and insert a SQL query which may then be executed by the backend server. eTRAKiT 3.2.1.17 was tested, but other versions may also be vulnerable.CRITICAL 9.8EPSS 11.6%13 July 2018
CVE-2016-6563Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers.CRITICAL 9.8EPSS 79.7%13 July 2018
CVE-2018-1000207MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content.HIGH 7.2EPSS 64.1%13 July 2018
CVE-2018-12980The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.HIGH 8.8EPSS 29.8%12 July 2018
CVE-2018-14009Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.CRITICAL 9.8EPSS 38.0%12 July 2018
CVE-2018-12463An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML…CRITICAL 9.8EPSS 13.8%12 July 2018
CVE-2018-11529VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files.HIGH 8.0EPSS 37.0%11 July 2018
CVE-2017-16709Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute arbitrary code via unspecified vectors.HIGH 7.2EPSS 72.0%11 July 2018
CVE-2018-8007Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs under, by bypassing…HIGH 7.2EPSS 11.6%11 July 2018
CVE-2018-8327A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.CRITICAL 9.8EPSS 22.5%11 July 2018
CVE-2018-8312A remote code execution vulnerability exists when Microsoft Access fails to properly handle objects in memory, aka "Microsoft Access Remote Code Execution Vulnerability." This affects Microsoft Access, Microsoft Office.HIGH 7.8EPSS 20.8%11 July 2018
CVE-2018-8311A remote code execution vulnerability exists when Skype for Business and Microsoft Lync clients fail to properly sanitize specially crafted content, aka "Remote Code Execution Vulnerability in Skype For Business and Lync." This affects Skype, Microsoft…HIGH 8.8EPSS 16.4%11 July 2018
CVE-2018-8304A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,…MEDIUM 5.9EPSS 12.6%11 July 2018
CVE-2018-8301A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge.HIGH 7.5EPSS 13.9%11 July 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.