Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,535 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 151 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-4192 | It allows remote attackers to execute arbitrary code via a crafted web site that leverages a race condition. | HIGH 7.5EPSS 12.3% | 8 June 2018 |
| CVE-2018-11409 | Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key. | MEDIUM 5.3EPSS 98.3% | 8 June 2018 |
| CVE-2018-10088 | Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725. | CRITICAL 9.8EPSS 39.7% | 8 June 2018 |
| CVE-2018-12054 | Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal. | HIGH 7.5EPSS 39.0% | 8 June 2018 |
| CVE-2018-12053 | Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.php by using directory traversal. | HIGH 7.5EPSS 10.9% | 8 June 2018 |
| CVE-2018-3758 | Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine. | HIGH 8.8EPSS 27.5% | 7 June 2018 |
| CVE-2018-12031 | Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action. | CRITICAL 9.8EPSS 19.8% | 7 June 2018 |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 99.9% | 7 June 2018 |
| CVE-2017-16082 | A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. | CRITICAL 9.8EPSS 10.5% | 7 June 2018 |
| CVE-2018-11586 | XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. | CRITICAL 9.8EPSS 15.0% | 5 June 2018 |
| CVE-2018-11714 | This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. | CRITICAL 9.8EPSS 68.1% | 4 June 2018 |
| CVE-2018-10613 | Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior. | HIGH 7.5EPSS 18.1% | 4 June 2018 |
| CVE-2018-11143 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46). | CRITICAL 9.8EPSS 37.2% | 2 June 2018 |
| CVE-2018-11538 | servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass. | HIGH 8.8EPSS 12.7% | 1 June 2018 |
| CVE-2018-11552 | There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. | MEDIUM 6.1EPSS 28.6% | 1 June 2018 |
| CVE-2018-11652 | CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report. | CRITICAL 9.8EPSS 24.4% | 1 June 2018 |
| CVE-2018-11646 | webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3, mishandle an unset pageURL, leading to an application crash. | HIGH 7.5EPSS 68.6% | 1 June 2018 |
| CVE-2018-11139 | The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. | HIGH 8.8EPSS 42.9% | 31 May 2018 |
| CVE-2018-11138 | Quest KACE System Management Appliance Remote Command Execution Vulnerability | KEVCRITICAL 9.8EPSS 92.1% | 31 May 2018 |
| CVE-2018-11132 | In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be executed. | HIGH 8.8EPSS 18.3% | 31 May 2018 |
| CVE-2018-11220 | Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function. | HIGH 8.8EPSS 16.2% | 31 May 2018 |
| CVE-2018-11235 | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. | HIGH 7.8EPSS 48.8% | 30 May 2018 |
| CVE-2018-10466 | Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection. | CRITICAL 9.8EPSS 17.2% | 29 May 2018 |
| CVE-2018-1235 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. | CRITICAL 9.8EPSS 42.9% | 29 May 2018 |
| CVE-2018-6409 | Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter. | MEDIUM 5.3EPSS 14.6% | 26 May 2018 |
| CVE-2018-10350 | A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw within the handling of parameters provided to… | HIGH 8.8EPSS 14.7% | 25 May 2018 |
| CVE-2018-1133 | A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection. | HIGH 8.8EPSS 31.9% | 25 May 2018 |
| CVE-2018-11412 | In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a… | MEDIUM 5.9EPSS 16.2% | 24 May 2018 |
| CVE-2018-8013 | In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. | CRITICAL 9.8EPSS 19.3% | 24 May 2018 |
| CVE-2018-8898 | A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read,… | CRITICAL 9.8EPSS 12.8% | 23 May 2018 |
| CVE-2018-10357 | A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the FileDrop servlet. | HIGH 8.8EPSS 73.1% | 23 May 2018 |
| CVE-2018-10356 | A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRequestDomains class. | HIGH 8.8EPSS 10.2% | 23 May 2018 |
| CVE-2018-10354 | A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the LauncherServer. | HIGH 8.8EPSS 13.2% | 23 May 2018 |
| CVE-2018-8176 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office. | HIGH 8.8EPSS 24.1% | 23 May 2018 |
| CVE-2018-10095 | Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php. | MEDIUM 6.1EPSS 87.0% | 22 May 2018 |
| CVE-2018-10094 | SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes. | CRITICAL 9.8EPSS 70.7% | 22 May 2018 |
| CVE-2018-3639 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a… | MEDIUM 5.5EPSS 60.6% | 22 May 2018 |
| CVE-2018-11311 | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials. | CRITICAL 9.1EPSS 15.7% | 20 May 2018 |
| CVE-2018-4939 | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 62.1% | 19 May 2018 |
| CVE-2018-4937 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. | HIGH 8.8EPSS 26.2% | 19 May 2018 |
| CVE-2018-4936 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. | MEDIUM 6.5EPSS 28.7% | 19 May 2018 |
| CVE-2018-4935 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. | HIGH 8.8EPSS 26.2% | 19 May 2018 |
| CVE-2018-4934 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. | MEDIUM 6.5EPSS 23.2% | 19 May 2018 |
| CVE-2018-4924 | Adobe Dreamweaver CC versions 18.0 and earlier have an OS Command Injection vulnerability. | CRITICAL 9.8EPSS 14.3% | 19 May 2018 |
| CVE-2018-4918 | Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier have an exploitable out-of-bounds write vulnerability. | CRITICAL 9.8EPSS 12.1% | 19 May 2018 |
| CVE-2018-4917 | Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier have an exploitable heap overflow vulnerability. | CRITICAL 9.8EPSS 17.6% | 19 May 2018 |
| CVE-2018-9250 | interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter. | HIGH 8.8EPSS 31.5% | 18 May 2018 |
| CVE-2018-11130 | The header::add_FORMAT_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted vcf file. | HIGH 7.8EPSS 22.4% | 17 May 2018 |
| CVE-2018-1111 | DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. | HIGH 7.5EPSS 98.0% | 17 May 2018 |
| CVE-2018-9958 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. | HIGH 8.8EPSS 62.9% | 17 May 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.