Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,535 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 153 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-0494 | GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line. | MEDIUM 6.5EPSS 16.8% | 6 May 2018 |
| CVE-2018-10562 | Dasan GPON Routers Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 4 May 2018 |
| CVE-2018-10561 | Dasan GPON Routers Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 92.9% | 4 May 2018 |
| CVE-2018-10718 | Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets. | CRITICAL 10.0EPSS 30.2% | 3 May 2018 |
| CVE-2018-0258 | A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. | CRITICAL 9.8EPSS 48.2% | 2 May 2018 |
| CVE-2018-8115 | A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability."… | HIGH 8.6EPSS 34.6% | 2 May 2018 |
| CVE-2016-10036 | Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary… | CRITICAL 9.8EPSS 25.6% | 1 May 2018 |
| CVE-2018-10583 | An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within… | HIGH 7.5EPSS 78.3% | 1 May 2018 |
| CVE-2017-17020 | On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before 1.15.01, command injection in alphapd (binary responsible for running the camera's web server)… | HIGH 8.8EPSS 14.8% | 1 May 2018 |
| CVE-2018-5234 | The Norton Core router prior to v237 may be susceptible to a command injection exploit. | HIGH 8.0EPSS 16.4% | 30 April 2018 |
| CVE-2018-10553 | A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings. | MEDIUM 6.5EPSS 39.0% | 30 April 2018 |
| CVE-2018-10546 | An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. | HIGH 7.5EPSS 10.2% | 29 April 2018 |
| CVE-2018-9845 | Etherpad Lite before 1.6.4 is exploitable for admin access. | CRITICAL 9.8EPSS 12.9% | 29 April 2018 |
| CVE-2018-10517 | In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element. | HIGH 7.2EPSS 11.8% | 27 April 2018 |
| CVE-2018-7669 | The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from the host Operating System using a sitecore/shell/default.aspx?xmlcontrol=LogViewerDetails&file= URI. | HIGH 7.5EPSS 17.2% | 27 April 2018 |
| CVE-2018-1418 | IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. | HIGH 8.8EPSS 51.4% | 26 April 2018 |
| CVE-2018-1335 | From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. | HIGH 8.1EPSS 93.8% | 25 April 2018 |
| CVE-2018-8716 | WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers. | MEDIUM 5.4EPSS 38.7% | 25 April 2018 |
| CVE-2017-2885 | An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. | CRITICAL 9.8EPSS 23.5% | 24 April 2018 |
| CVE-2016-9587 | Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. | HIGH 8.1EPSS 17.4% | 24 April 2018 |
| CVE-2018-8880 | Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which leads to internal network information disclosure. | HIGH 7.5EPSS 13.6% | 23 April 2018 |
| CVE-2018-10285 | Since the app does not use any sort of session ID, an attacker might bypass authentication. | CRITICAL 9.8EPSS 12.8% | 22 April 2018 |
| CVE-2018-9059 | Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code via a malicious login request to forum.ghp. | CRITICAL 9.8EPSS 76.9% | 20 April 2018 |
| CVE-2018-10201 | It is possible to read arbitrary files outside the root directory of the web server. | HIGH 7.5EPSS 44.4% | 20 April 2018 |
| CVE-2018-3843 | An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotations. | HIGH 8.8EPSS 21.9% | 19 April 2018 |
| CVE-2018-1146 | A remote unauthenticated user can enable telnet on the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to set.cgi. | HIGH 7.5EPSS 28.7% | 19 April 2018 |
| CVE-2018-1145 | A remote unauthenticated user can overflow a stack buffer in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to proxy.cgi. | CRITICAL 9.8EPSS 24.5% | 19 April 2018 |
| CVE-2018-1143 | A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to twonky_command.cgi. | CRITICAL 9.8EPSS 54.7% | 19 April 2018 |
| CVE-2018-2879 | Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine). | CRITICAL 9.0EPSS 21.7% | 19 April 2018 |
| CVE-2018-2799 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). | MEDIUM 5.3EPSS 14.9% | 19 April 2018 |
| CVE-2018-2791 | Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). | HIGH 8.2EPSS 38.8% | 19 April 2018 |
| CVE-2018-2628 | Oracle WebLogic Server Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 19 April 2018 |
| CVE-2018-8831 | A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist. | MEDIUM 6.1EPSS 52.7% | 18 April 2018 |
| CVE-2018-8736 | A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root. | HIGH 8.8EPSS 46.3% | 18 April 2018 |
| CVE-2018-8735 | Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection. | HIGH 8.8EPSS 63.6% | 18 April 2018 |
| CVE-2018-8734 | SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter. | CRITICAL 9.8EPSS 52.6% | 18 April 2018 |
| CVE-2018-8733 | Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability. | CRITICAL 9.8EPSS 27.0% | 18 April 2018 |
| CVE-2018-6913 | Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count. | CRITICAL 9.8EPSS 10.9% | 17 April 2018 |
| CVE-2018-5430 | TIBCO JasperReports Server Information Disclosure Vulnerability | KEVHIGH 8.8EPSS 49.6% | 17 April 2018 |
| CVE-2018-10070 | A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on port 21 that begins with many '\0' characters, preventing the affected… | HIGH 7.5EPSS 12.7% | 16 April 2018 |
| CVE-2018-0737 | The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. | MEDIUM 5.9EPSS 11.8% | 16 April 2018 |
| CVE-2014-2069 | Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to FileManager.aspx. | HIGH 7.5EPSS 15.7% | 16 April 2018 |
| CVE-2018-6546 | plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes code at a user-defined (local or SMB) path as SYSTEM when the execute_installer parameter is used in an… | CRITICAL 9.8EPSS 17.5% | 13 April 2018 |
| CVE-2017-0372 | Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities. | CRITICAL 9.8EPSS 11.5% | 13 April 2018 |
| CVE-2018-5511 | On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced. | HIGH 7.2EPSS 14.5% | 13 April 2018 |
| CVE-2018-9843 | The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialized .NET object in an Authorization HTTP header. | CRITICAL 9.8EPSS 17.0% | 12 April 2018 |
| CVE-2018-9842 | CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message. | MEDIUM 5.3EPSS 16.2% | 12 April 2018 |
| CVE-2018-9118 | exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter. | HIGH 7.5EPSS 46.9% | 12 April 2018 |
| CVE-2018-1030 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. | HIGH 8.8EPSS 24.5% | 12 April 2018 |
| CVE-2018-1029 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office,… | HIGH 7.8EPSS 20.9% | 12 April 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.