Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,539 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 156 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-6223 | A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the product to reset configuration parameters. | CRITICAL 9.8EPSS 10.0% | 15 March 2018 |
| CVE-2018-8715 | With a forged HTTP request, it is possible to bypass authentication for the form and digest login types. | HIGH 8.1EPSS 22.8% | 15 March 2018 |
| CVE-2018-8045 | 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view. | HIGH 8.8EPSS 28.2% | 15 March 2018 |
| CVE-2018-7756 | RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remote attackers to execute arbitrary code or access internal commands, as demonstrated by a RUN command… | CRITICAL 9.8EPSS 60.7% | 15 March 2018 |
| CVE-2018-7702 | SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary recipients, or modify arbitrary message bodies and attachments by leveraging missing authentication and… | CRITICAL 9.1EPSS 14.0% | 15 March 2018 |
| CVE-2018-6329 | It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege escalation exploit on the target system and subsequently execute arbitrary… | CRITICAL 9.8EPSS 61.2% | 14 March 2018 |
| CVE-2018-6328 | It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes. | CRITICAL 9.8EPSS 64.4% | 14 March 2018 |
| CVE-2018-1000120 | A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse. | CRITICAL 9.8EPSS 11.6% | 14 March 2018 |
| CVE-2018-0941 | Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how data is imported, aka "Microsoft Exchange Information Disclosure Vulnerability". | MEDIUM 5.5EPSS 12.5% | 14 March 2018 |
| CVE-2018-0937 | ChakraCore and Microsoft Windows 10 1703 and 1709 allow remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 15.4% | 14 March 2018 |
| CVE-2018-0936 | ChakraCore and Microsoft Windows 10 1709 allow remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 15.4% | 14 March 2018 |
| CVE-2018-0935 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the… | HIGH 7.5EPSS 55.6% | 14 March 2018 |
| CVE-2018-0934 | ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 66.2% | 14 March 2018 |
| CVE-2018-0933 | ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 66.3% | 14 March 2018 |
| CVE-2018-0931 | ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 11.4% | 14 March 2018 |
| CVE-2018-0930 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1709 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 11.5% | 14 March 2018 |
| CVE-2018-0925 | ChakraCore allows remote code execution, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 11.4% | 14 March 2018 |
| CVE-2018-0922 | Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Compatibility Pack SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Office Word… | HIGH 7.8EPSS 18.0% | 14 March 2018 |
| CVE-2018-0919 | Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft… | LOW 3.3EPSS 11.7% | 14 March 2018 |
| CVE-2018-0903 | Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run allow a remote code execution vulnerability due to how objects are handled in memory, aka "Microsoft Access Remote Code Execution… | HIGH 7.8EPSS 16.0% | 14 March 2018 |
| CVE-2018-0893 | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 26.6% | 14 March 2018 |
| CVE-2018-0891 | ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows… | MEDIUM 4.3EPSS 14.2% | 14 March 2018 |
| CVE-2018-0889 | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 15.7% | 14 March 2018 |
| CVE-2018-0886 | The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows… | HIGH 7.0EPSS 82.0% | 14 March 2018 |
| CVE-2018-0883 | Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution… | HIGH 7.5EPSS 14.5% | 14 March 2018 |
| CVE-2018-0878 | Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an… | LOW 3.1EPSS 21.1% | 14 March 2018 |
| CVE-2018-0876 | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 15.7% | 14 March 2018 |
| CVE-2018-0874 | ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption… | HIGH 7.5EPSS 15.7% | 14 March 2018 |
| CVE-2018-0873 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption… | HIGH 7.5EPSS 15.4% | 14 March 2018 |
| CVE-2018-0872 | ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption… | HIGH 7.5EPSS 15.7% | 14 March 2018 |
| CVE-2018-5782 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the… | CRITICAL 9.8EPSS 18.7% | 14 March 2018 |
| CVE-2018-1000130 | A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server. | HIGH 8.1EPSS 72.7% | 14 March 2018 |
| CVE-2018-1000129 | An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser. | MEDIUM 6.1EPSS 24.7% | 14 March 2018 |
| CVE-2018-8096 | Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","Value":false' in an api/settings/setting-isauthenticationenabled PUT request. | CRITICAL 9.8EPSS 48.2% | 14 March 2018 |
| CVE-2018-7750 | transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is… | CRITICAL 9.8EPSS 27.1% | 13 March 2018 |
| CVE-2017-1002101 | In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside… | CRITICAL 9.6EPSS 13.3% | 13 March 2018 |
| CVE-2018-1057 | On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and… | HIGH 8.8EPSS 10.0% | 13 March 2018 |
| CVE-2018-1000094 | CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. | HIGH 7.2EPSS 38.8% | 13 March 2018 |
| CVE-2018-1323 | If only a sub-set of the URLs supported by Tomcat were exposed via IIS, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing Tomcat via the… | HIGH 7.5EPSS 46.4% | 12 March 2018 |
| CVE-2017-2619 | Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition. | HIGH 7.5EPSS 11.1% | 12 March 2018 |
| CVE-2018-8065 | An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. | HIGH 7.5EPSS 75.9% | 12 March 2018 |
| CVE-2018-8057 | A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php. | CRITICAL 9.8EPSS 21.8% | 11 March 2018 |
| CVE-2018-8056 | Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a direct request to /export.php. | HIGH 7.5EPSS 12.7% | 11 March 2018 |
| CVE-2018-7582 | WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991. | HIGH 7.5EPSS 36.4% | 9 March 2018 |
| CVE-2018-7890 | A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). | CRITICAL 9.8EPSS 78.8% | 8 March 2018 |
| CVE-2018-7183 | Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array. | CRITICAL 9.8EPSS 10.2% | 8 March 2018 |
| CVE-2018-1216 | A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere… | CRITICAL 9.8EPSS 21.3% | 8 March 2018 |
| CVE-2018-0147 | Cisco Secure Access Control System Java Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 18.2% | 8 March 2018 |
| CVE-2017-15367 | Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server. | CRITICAL 9.8EPSS 23.1% | 7 March 2018 |
| CVE-2018-7745 | An issue was discovered in Western Bridge Cobub Razor 0.7.2. | HIGH 7.5EPSS 12.0% | 7 March 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.