Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,535 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 150 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-12613 | An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. | HIGH 8.8EPSS 98.4% | 21 June 2018 |
| CVE-2018-12617 | qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. | HIGH 7.5EPSS 25.1% | 21 June 2018 |
| CVE-2018-0301 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to craft a packet to the management interface on an affected system, causing a buffer overflow. | CRITICAL 9.8EPSS 17.0% | 20 June 2018 |
| CVE-2018-12604 | GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log. | HIGH 7.5EPSS 13.2% | 20 June 2018 |
| CVE-2018-12327 | Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. | CRITICAL 9.8EPSS 28.7% | 20 June 2018 |
| CVE-2018-12293 | The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer… | HIGH 8.8EPSS 10.4% | 19 June 2018 |
| CVE-2018-9022 | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file. | CRITICAL 9.8EPSS 12.8% | 18 June 2018 |
| CVE-2018-1333 | By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. | HIGH 7.5EPSS 17.1% | 18 June 2018 |
| CVE-2015-4664 | An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands. | CRITICAL 9.8EPSS 20.6% | 18 June 2018 |
| CVE-2018-12533 | JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData… | CRITICAL 9.8EPSS 19.0% | 18 June 2018 |
| CVE-2018-11218 | Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows. | CRITICAL 9.8EPSS 59.0% | 17 June 2018 |
| CVE-2018-12453 | Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream. | HIGH 7.5EPSS 23.9% | 16 June 2018 |
| CVE-2018-11690 | The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. | MEDIUM 6.1EPSS 33.5% | 14 June 2018 |
| CVE-2018-8267 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet… | HIGH 7.5EPSS 15.7% | 14 June 2018 |
| CVE-2018-8249 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. | HIGH 7.5EPSS 14.3% | 14 June 2018 |
| CVE-2018-8248 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office. | HIGH 7.8EPSS 21.4% | 14 June 2018 |
| CVE-2018-8246 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. | MEDIUM 5.5EPSS 18.5% | 14 June 2018 |
| CVE-2018-8245 | A remote code execution vulnerability exists when Microsoft Publisher fails to utilize features that lock down the Local Machine zone when instantiating OLE objects, aka "Microsoft Publisher Remote Code Execution Vulnerability." This affects Microsoft… | HIGH 7.8EPSS 16.4% | 14 June 2018 |
| CVE-2018-8243 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. | HIGH 7.5EPSS 11.9% | 14 June 2018 |
| CVE-2018-8239 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | MEDIUM 5.5EPSS 58.1% | 14 June 2018 |
| CVE-2018-8236 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. | HIGH 7.5EPSS 14.3% | 14 June 2018 |
| CVE-2018-8231 | A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles objects in memory, aka "HTTP Protocol Stack Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | HIGH 8.1EPSS 16.0% | 14 June 2018 |
| CVE-2018-8229 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 71.0% | 14 June 2018 |
| CVE-2018-8227 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | HIGH 7.5EPSS 16.2% | 14 June 2018 |
| CVE-2018-8226 | A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability." This affects Windows Server 2016, Windows 10, Windows… | HIGH 7.5EPSS 13.5% | 14 June 2018 |
| CVE-2018-8225 | A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows… | HIGH 8.1EPSS 23.6% | 14 June 2018 |
| CVE-2018-8210 | A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows… | HIGH 7.8EPSS 25.2% | 14 June 2018 |
| CVE-2018-8111 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. | HIGH 7.5EPSS 16.2% | 14 June 2018 |
| CVE-2018-8110 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. | HIGH 7.5EPSS 16.2% | 14 June 2018 |
| CVE-2018-0978 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. | HIGH 7.5EPSS 15.7% | 14 June 2018 |
| CVE-2018-0732 | During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. | HIGH 7.5EPSS 48.8% | 12 June 2018 |
| CVE-2018-6961 | VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability | KEVHIGH 8.1EPSS 86.3% | 11 June 2018 |
| CVE-2018-5159 | An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. | CRITICAL 9.8EPSS 21.0% | 11 June 2018 |
| CVE-2018-5158 | The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. | HIGH 8.8EPSS 10.4% | 11 June 2018 |
| CVE-2018-5146 | This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7. | HIGH 8.8EPSS 11.9% | 11 June 2018 |
| CVE-2018-5094 | A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collection on memory that is now uninitialized. | HIGH 7.5EPSS 15.3% | 11 June 2018 |
| CVE-2018-5093 | A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. | HIGH 7.5EPSS 19.8% | 11 June 2018 |
| CVE-2017-7783 | If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. | HIGH 7.5EPSS 13.5% | 11 June 2018 |
| CVE-2017-5465 | An out-of-bounds read while processing SVG content in "ConvolvePixel". | CRITICAL 9.1EPSS 18.5% | 11 June 2018 |
| CVE-2017-5447 | An out-of-bounds read during the processing of glyph widths during text layout. | CRITICAL 9.1EPSS 17.3% | 11 June 2018 |
| CVE-2017-5415 | An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. | MEDIUM 5.3EPSS 12.6% | 11 June 2018 |
| CVE-2017-5404 | A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. | CRITICAL 9.8EPSS 17.3% | 11 June 2018 |
| CVE-2017-5375 | JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. | CRITICAL 9.8EPSS 33.8% | 11 June 2018 |
| CVE-2016-9899 | Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. | CRITICAL 9.8EPSS 21.1% | 11 June 2018 |
| CVE-2016-9079 | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability | KEVHIGH 7.5EPSS 87.4% | 11 June 2018 |
| CVE-2016-9066 | A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. | HIGH 7.5EPSS 12.3% | 11 June 2018 |
| CVE-2018-4243 | A buffer overflow in getvolattrlist allows attackers to execute arbitrary code in a privileged context via a crafted app. | HIGH 7.8EPSS 18.5% | 8 June 2018 |
| CVE-2018-4237 | It allows attackers to gain privileges via a crafted app that leverages a logic error. | HIGH 7.8EPSS 13.7% | 8 June 2018 |
| CVE-2018-4233 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | HIGH 8.8EPSS 53.3% | 8 June 2018 |
| CVE-2018-4222 | It allows remote attackers to execute arbitrary code via a crafted web site that leverages a getWasmBufferFromValue out-of-bounds read during WebAssembly compilation. | HIGH 8.8EPSS 10.4% | 8 June 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.