SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,535 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 149 of 348

CVESummaryPriorityPublished
CVE-2018-4962Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability.HIGH 7.5EPSS 10.9%9 July 2018
CVE-2018-4961Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability.CRITICAL 9.8EPSS 11.6%9 July 2018
CVE-2018-4960Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability.HIGH 7.5EPSS 10.9%9 July 2018
CVE-2018-4959Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability.CRITICAL 9.8EPSS 11.6%9 July 2018
CVE-2018-4958Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability.CRITICAL 9.8EPSS 11.6%9 July 2018
CVE-2018-4957Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability.HIGH 7.5EPSS 10.9%9 July 2018
CVE-2018-4956Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability.HIGH 7.5EPSS 32.8%9 July 2018
CVE-2018-4955Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability.HIGH 7.5EPSS 10.9%9 July 2018
CVE-2018-4950Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds write vulnerability.CRITICAL 9.8EPSS 10.7%9 July 2018
CVE-2018-4949Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability.HIGH 7.5EPSS 32.8%9 July 2018
CVE-2018-4948Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerability.CRITICAL 9.8EPSS 15.4%9 July 2018
CVE-2018-4947Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerability.CRITICAL 9.8EPSS 15.4%9 July 2018
CVE-2018-13784PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.CRITICAL 9.1EPSS 16.5%9 July 2018
CVE-2018-13109All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the…HIGH 7.5EPSS 35.5%6 July 2018
CVE-2018-8046The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data.MEDIUM 6.1EPSS 67.0%5 July 2018
CVE-2018-12571uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a…CRITICAL 9.8EPSS 29.9%5 July 2018
CVE-2018-12520An attacker with foreknowledge of the operating system and standard library in use by the host running the service and the username of the user whose session they're targeting can abuse the deterministic random number generation in order to hijack the…HIGH 8.1EPSS 10.5%5 July 2018
CVE-2018-8038Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.HIGH 7.5EPSS 10.6%5 July 2018
CVE-2017-0929DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class.HIGH 7.5EPSS 12.5%3 July 2018
CVE-2018-7777The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.HIGH 8.8EPSS 31.8%3 July 2018
CVE-2018-9276Paessler PRTG Network Monitor OS Command Injection VulnerabilityKEVHIGH 7.2EPSS 87.0%2 July 2018
CVE-2018-13050A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.CRITICAL 9.8EPSS 39.8%2 July 2018
CVE-2018-10860perl-archive-zip is vulnerable to a directory traversal in Archive::Zip.HIGH 7.5EPSS 48.7%29 June 2018
CVE-2018-12465An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server.HIGH 7.2EPSS 80.0%29 June 2018
CVE-2018-12464A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database.CRITICAL 9.8EPSS 80.7%29 June 2018
CVE-2018-12998A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before…MEDIUM 6.1EPSS 99.3%29 June 2018
CVE-2018-12589Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working directory.HIGH 7.8EPSS 20.1%28 June 2018
CVE-2018-11510The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter.CRITICAL 9.8EPSS 44.3%28 June 2018
CVE-2018-1306The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload.HIGH 7.5EPSS 43.5%27 June 2018
CVE-2018-12909Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the webserver user has access to) via an index.php?op=fileviewer&file= URI.HIGH 7.5EPSS 16.1%27 June 2018
CVE-2018-12908Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for the /dashboard/deposit URI, as demonstrated by discovering database credentials.CRITICAL 9.8EPSS 10.5%27 June 2018
CVE-2018-12905joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions.MEDIUM 6.1EPSS 42.2%27 June 2018
CVE-2018-12900Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and…HIGH 8.8EPSS 25.2%26 June 2018
CVE-2018-12895WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file.HIGH 8.8EPSS 62.2%26 June 2018
CVE-2018-10594This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server.CRITICAL 9.8EPSS 68.6%26 June 2018
CVE-2018-3760There is an information leak vulnerability in Sprockets.HIGH 7.5EPSS 26.7%26 June 2018
CVE-2018-10662There is an Exposed Insecure Interface.CRITICAL 9.8EPSS 79.5%26 June 2018
CVE-2018-10661There is a bypass of access control.CRITICAL 9.8EPSS 86.5%26 June 2018
CVE-2018-10660There is Shell Command Injection.CRITICAL 9.8EPSS 82.1%26 June 2018
CVE-2018-1000600A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through…HIGH 8.8EPSS 90.9%26 June 2018
CVE-2017-7658If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.CRITICAL 9.8EPSS 19.4%26 June 2018
CVE-2018-1000533klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user.CRITICAL 9.8EPSS 73.0%26 June 2018
CVE-2018-1000528GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML.MEDIUM 6.1EPSS 46.8%26 June 2018
CVE-2018-1000517BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffer overflow.CRITICAL 9.8EPSS 32.9%26 June 2018
CVE-2017-7657The chunk length parsing was vulnerable to an integer overflow.CRITICAL 9.8EPSS 14.9%26 June 2018
CVE-2018-10956IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.HIGH 7.5EPSS 55.0%25 June 2018
CVE-2018-12693Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to cause a denial of service (outage) via a long type parameter to /data/syslog.filter.json.MEDIUM 6.5EPSS 15.8%23 June 2018
CVE-2018-12692TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the wps_setup_pin parameter to /data/wps.setup.json.HIGH 8.8EPSS 28.8%23 June 2018
CVE-2018-12636The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.HIGH 7.2EPSS 29.8%22 June 2018
CVE-2018-12634CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.CRITICAL 9.8EPSS 56.4%22 June 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.