Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,535 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 148 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-8300 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka "Microsoft SharePoint Remote Code Execution Vulnerability." This affects Microsoft SharePoint. | HIGH 8.8EPSS 13.6% | 11 July 2018 |
| CVE-2018-8298 | ChakraCore Scripting Engine Type Confusion Vulnerability | KEVHIGH 7.5EPSS 74.5% | 11 July 2018 |
| CVE-2018-8296 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11. | HIGH 7.5EPSS 16.5% | 11 July 2018 |
| CVE-2018-8294 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 20.6% | 11 July 2018 |
| CVE-2018-8291 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. | HIGH 7.5EPSS 69.0% | 11 July 2018 |
| CVE-2018-8290 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 20.4% | 11 July 2018 |
| CVE-2018-8288 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. | HIGH 7.5EPSS 69.0% | 11 July 2018 |
| CVE-2018-8287 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet… | HIGH 7.5EPSS 15.8% | 11 July 2018 |
| CVE-2018-8286 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 20.4% | 11 July 2018 |
| CVE-2018-8284 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft… | HIGH 8.1EPSS 41.5% | 11 July 2018 |
| CVE-2018-8283 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. | HIGH 7.5EPSS 14.7% | 11 July 2018 |
| CVE-2018-8281 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft PowerPoint… | HIGH 7.8EPSS 20.8% | 11 July 2018 |
| CVE-2018-8280 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 20.4% | 11 July 2018 |
| CVE-2018-8279 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 70.7% | 11 July 2018 |
| CVE-2018-8275 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 20.4% | 11 July 2018 |
| CVE-2018-8274 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. | HIGH 7.5EPSS 20.4% | 11 July 2018 |
| CVE-2018-8262 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. | HIGH 7.5EPSS 20.4% | 11 July 2018 |
| CVE-2018-8260 | A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Execution Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 4.7.2. | HIGH 8.8EPSS 15.5% | 11 July 2018 |
| CVE-2018-8242 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet… | HIGH 7.5EPSS 18.6% | 11 July 2018 |
| CVE-2018-8206 | A denial of service vulnerability exists when Windows improperly handles File Transfer Protocol (FTP) connections, aka "Windows FTP Server Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server… | HIGH 7.5EPSS 11.5% | 11 July 2018 |
| CVE-2018-8172 | A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio,… | HIGH 7.8EPSS 32.8% | 11 July 2018 |
| CVE-2018-8171 | A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0,… | HIGH 7.5EPSS 10.5% | 11 July 2018 |
| CVE-2018-8125 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. | HIGH 7.5EPSS 19.8% | 11 July 2018 |
| CVE-2018-0949 | A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 9, Internet Explorer 11,… | MEDIUM 6.5EPSS 11.7% | 11 July 2018 |
| CVE-2018-5002 | Adobe Flash Player Stack-based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 25.1% | 9 July 2018 |
| CVE-2018-5001 | Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. | MEDIUM 6.5EPSS 13.2% | 9 July 2018 |
| CVE-2018-5000 | Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. | MEDIUM 6.5EPSS 13.7% | 9 July 2018 |
| CVE-2018-4993 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. | HIGH 7.5EPSS 86.7% | 9 July 2018 |
| CVE-2018-4990 | Adobe Acrobat and Reader Double Free Vulnerability | KEVHIGH 8.8EPSS 36.2% | 9 July 2018 |
| CVE-2018-4989 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability. | CRITICAL 9.8EPSS 11.6% | 9 July 2018 |
| CVE-2018-4988 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability. | CRITICAL 9.8EPSS 11.6% | 9 July 2018 |
| CVE-2018-4987 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Untrusted pointer dereference vulnerability. | CRITICAL 9.8EPSS 13.3% | 9 July 2018 |
| CVE-2018-4986 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 10.9% | 9 July 2018 |
| CVE-2018-4985 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 36.4% | 9 July 2018 |
| CVE-2018-4984 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerability. | CRITICAL 9.8EPSS 15.4% | 9 July 2018 |
| CVE-2018-4983 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability. | CRITICAL 9.8EPSS 11.6% | 9 July 2018 |
| CVE-2018-4982 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerability. | HIGH 8.8EPSS 24.6% | 9 July 2018 |
| CVE-2018-4981 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 10.9% | 9 July 2018 |
| CVE-2018-4978 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerability. | CRITICAL 9.8EPSS 15.4% | 9 July 2018 |
| CVE-2018-4977 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability. | CRITICAL 9.8EPSS 11.6% | 9 July 2018 |
| CVE-2018-4976 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 10.9% | 9 July 2018 |
| CVE-2018-4975 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 10.9% | 9 July 2018 |
| CVE-2018-4973 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 10.9% | 9 July 2018 |
| CVE-2018-4970 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 10.9% | 9 July 2018 |
| CVE-2018-4969 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 10.9% | 9 July 2018 |
| CVE-2018-4968 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerability. | CRITICAL 9.8EPSS 15.4% | 9 July 2018 |
| CVE-2018-4967 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 10.9% | 9 July 2018 |
| CVE-2018-4966 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerability. | CRITICAL 9.8EPSS 15.4% | 9 July 2018 |
| CVE-2018-4964 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 10.9% | 9 July 2018 |
| CVE-2018-4963 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. | HIGH 7.5EPSS 10.9% | 9 July 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.