SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,539 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 155 of 348

CVESummaryPriorityPublished
CVE-2017-14463An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before.CRITICAL 9.8EPSS 38.9%5 April 2018
CVE-2017-14462An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before.CRITICAL 9.8EPSS 35.2%5 April 2018
CVE-2016-8380The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.HIGH 7.3EPSS 10.9%5 April 2018
CVE-2016-8371The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.HIGH 7.3EPSS 10.9%5 April 2018
CVE-2018-9126The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.CRITICAL 9.8EPSS 48.9%4 April 2018
CVE-2018-8719For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.MEDIUM 5.3EPSS 15.6%4 April 2018
CVE-2018-0986A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This…HIGH 8.8EPSS 63.3%4 April 2018
CVE-2018-9248FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.CRITICAL 9.8EPSS 14.5%4 April 2018
CVE-2018-9205Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.HIGH 7.5EPSS 55.1%4 April 2018
CVE-2016-10718Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.HIGH 7.5EPSS 12.2%4 April 2018
CVE-2018-6914Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a…HIGH 7.5EPSS 10.2%3 April 2018
CVE-2018-4162It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.HIGH 8.8EPSS 37.8%3 April 2018
CVE-2018-4121It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.HIGH 8.8EPSS 13.1%3 April 2018
CVE-2018-9230In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remote attackers to bypass intended access restrictions or…CRITICAL 9.8EPSS 13.2%2 April 2018
CVE-2018-6849In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.MEDIUM 4.3EPSS 28.7%1 April 2018
CVE-2018-9161Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading user/scripts/login_par.js.CRITICAL 9.8EPSS 56.7%31 March 2018
CVE-2018-9160SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.CRITICAL 9.8EPSS 75.6%31 March 2018
CVE-2018-7171Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a ..HIGH 7.5EPSS 27.9%30 March 2018
CVE-2018-7600Drupal Core Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%29 March 2018
CVE-2018-0171Cisco IOS and IOS XE Software Smart Install Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.5%28 March 2018
CVE-2018-0151Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 14.2%28 March 2018
CVE-2018-8823modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.CRITICAL 9.8EPSS 50.4%28 March 2018
CVE-2018-0739Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion.MEDIUM 6.5EPSS 18.6%27 March 2018
CVE-2018-7700DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.HIGH 8.8EPSS 74.1%27 March 2018
CVE-2018-6882Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 25.3%27 March 2018
CVE-2018-9032An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version : 1.02-2.06) devices potentially allows attackers to bypass SharePort Web Access Portal by directly…CRITICAL 9.8EPSS 27.7%27 March 2018
CVE-2018-7658NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exactly 11 bytes.HIGH 7.5EPSS 38.5%26 March 2018
CVE-2018-1189Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Antivirus Page within the OneFS web administration interface.MEDIUM 4.8EPSS 27.7%26 March 2018
CVE-2018-1312In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.CRITICAL 9.8EPSS 15.8%26 March 2018
CVE-2018-1303A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory.HIGH 7.5EPSS 69.8%26 March 2018
CVE-2018-1302The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.MEDIUM 5.9EPSS 12.9%26 March 2018
CVE-2018-1301A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header.MEDIUM 5.9EPSS 15.0%26 March 2018
CVE-2017-15715In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename.HIGH 8.1EPSS 85.5%26 March 2018
CVE-2017-15710If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example, 'en-US' is truncated to 'en').HIGH 7.5EPSS 17.1%26 March 2018
CVE-2018-8947rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.HIGH 7.5EPSS 11.0%25 March 2018
CVE-2018-7719Acrolinx Server before 5.2.5 on Windows allows Directory Traversal.HIGH 7.5EPSS 46.9%25 March 2018
CVE-2017-17736Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.CRITICAL 9.8EPSS 68.5%23 March 2018
CVE-2018-1207Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code.CRITICAL 9.8EPSS 90.1%23 March 2018
CVE-2018-8828A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2.CRITICAL 9.8EPSS 30.4%20 March 2018
CVE-2018-1322An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.MEDIUM 4.9EPSS 19.9%20 March 2018
CVE-2018-1321An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations,…HIGH 7.2EPSS 17.5%20 March 2018
CVE-2018-8088org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data.CRITICAL 9.8EPSS 14.7%20 March 2018
CVE-2017-17215Huawei HG532 with some customized versions has a remote code execution vulnerability.HIGH 8.8EPSS 78.3%20 March 2018
CVE-2018-7445MikroTik RouterOS Stack-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 60.8%19 March 2018
CVE-2014-2674Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attackers to read arbitrary files via a ..HIGH 7.5EPSS 15.2%19 March 2018
CVE-2018-1218In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer overflow condition when handling certain messages.HIGH 7.5EPSS 13.4%19 March 2018
CVE-2018-7422A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php, aka absolute…HIGH 7.5EPSS 62.3%19 March 2018
CVE-2018-8770Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, controllers/posterrorTest.php, controllers/posteventTest.php,…MEDIUM 5.3EPSS 59.2%18 March 2018
CVE-2018-6229A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.CRITICAL 9.8EPSS 10.2%15 March 2018
CVE-2018-6228A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.CRITICAL 9.8EPSS 10.2%15 March 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.