Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,539 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 157 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-7739 | antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demonstrated by a username=>&password=%0a string to the /login URI. | CRITICAL 9.8EPSS 53.2% | 7 March 2018 |
| CVE-2018-7182 | The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10. | HIGH 7.5EPSS 28.8% | 6 March 2018 |
| CVE-2018-6530 | D-Link Multiple Routers OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 96.7% | 6 March 2018 |
| CVE-2015-5377 | Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. | CRITICAL 9.8EPSS 14.3% | 6 March 2018 |
| CVE-2017-17428 | Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack. | MEDIUM 5.9EPSS 14.6% | 5 March 2018 |
| CVE-2018-0491 | A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. | HIGH 7.5EPSS 14.8% | 5 March 2018 |
| CVE-2018-1000115 | Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of… | HIGH 7.5EPSS 88.1% | 5 March 2018 |
| CVE-2018-7665 | A malicious file can be uploaded via the name parameter to actions/beats_uploader.php or actions/photo_uploader.php, or the coverPhoto parameter to edit_account.php. | CRITICAL 9.8EPSS 15.9% | 5 March 2018 |
| CVE-2018-7662 | Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php. | MEDIUM 5.3EPSS 47.1% | 4 March 2018 |
| CVE-2018-7583 | Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500. | HIGH 7.5EPSS 38.1% | 4 March 2018 |
| CVE-2018-1058 | A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. | HIGH 8.8EPSS 13.1% | 2 March 2018 |
| CVE-2017-14461 | A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. | HIGH 7.1EPSS 16.7% | 2 March 2018 |
| CVE-2018-7584 | In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. | CRITICAL 9.8EPSS 87.3% | 1 March 2018 |
| CVE-2018-7573 | A remote FTP server can send 400 characters of 'F' in conjunction with the FTP 220 response code to crash the application; after this overflow, one can run arbitrary code on the victim machine. | CRITICAL 9.8EPSS 69.2% | 1 March 2018 |
| CVE-2018-2380 | SAP Customer Relationship Management (CRM) Path Traversal Vulnerability | KEVMEDIUM 6.6EPSS 28.9% | 1 March 2018 |
| CVE-2015-5079 | Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. | HIGH 7.5EPSS 17.0% | 28 February 2018 |
| CVE-2015-4117 | Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php. | HIGH 8.8EPSS 10.6% | 28 February 2018 |
| CVE-2018-1304 | It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. | MEDIUM 5.9EPSS 17.1% | 28 February 2018 |
| CVE-2018-7264 | The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF… | CRITICAL 9.8EPSS 12.3% | 28 February 2018 |
| CVE-2018-7467 | AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI. | HIGH 7.5EPSS 10.2% | 27 February 2018 |
| CVE-2018-6481 | A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9124. | CRITICAL 9.8EPSS 20.7% | 27 February 2018 |
| CVE-2018-4916 | The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that handless TIFF data. | HIGH 8.8EPSS 15.1% | 27 February 2018 |
| CVE-2018-4915 | The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the JavaScript API related to color conversion. | HIGH 8.8EPSS 15.1% | 27 February 2018 |
| CVE-2018-4914 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TIFF processing in the XPS engine. | MEDIUM 6.5EPSS 11.2% | 27 February 2018 |
| CVE-2018-4913 | This vulnerability is an instance of a use after free vulnerability in the XFA engine, related to DOM manipulation. | HIGH 8.8EPSS 13.5% | 27 February 2018 |
| CVE-2018-4912 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that handles JPEG 2000 data. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4910 | This vulnerability is an instance of a heap overflow vulnerability in the JavaScript engine. | HIGH 8.8EPSS 24.5% | 27 February 2018 |
| CVE-2018-4909 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module when processing metadata in JPEG images. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4908 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TTF font processing in the XPS module. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4907 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TIFF processing in the XPS module. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4906 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that handles Enhanced Metafile Format Plus (EMF+) data related to graphic object image… | MEDIUM 6.5EPSS 21.2% | 27 February 2018 |
| CVE-2018-4905 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of TIFF processing within the XPS module. | MEDIUM 6.5EPSS 11.2% | 27 February 2018 |
| CVE-2018-4904 | This vulnerability is an instance of a heap overflow vulnerability. | HIGH 8.8EPSS 42.8% | 27 February 2018 |
| CVE-2018-4903 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TIFF processing within the XPS module. | MEDIUM 6.5EPSS 22.0% | 27 February 2018 |
| CVE-2018-4902 | This vulnerability is an instance of a use after free vulnerability in the rendering engine. | HIGH 8.8EPSS 12.2% | 27 February 2018 |
| CVE-2018-4901 | The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the document identity representation. | HIGH 8.8EPSS 16.2% | 27 February 2018 |
| CVE-2018-4900 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of JavaScript manipulation of an Annotation object. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4899 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the initial XPS page processing. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4898 | The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the XPS engine that adds vector graphics and images to a fixed page. | HIGH 8.8EPSS 15.1% | 27 February 2018 |
| CVE-2018-4897 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that parses TIFF metadata. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4896 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that handles Enhanced Metafile Format Plus (EMF+) data. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4895 | The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion engine when processing Enhanced Metafile Format Plus (EMF+) data. | CRITICAL 9.8EPSS 13.7% | 27 February 2018 |
| CVE-2018-4894 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the XPS font processing. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4893 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of XPS font processing. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4892 | This vulnerability is an instance of a use after free vulnerability in the JBIG2 decoder. | HIGH 8.8EPSS 12.2% | 27 February 2018 |
| CVE-2018-4891 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the XPS module that handles TIFF data. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4890 | This vulnerability is an instance of a heap overflow vulnerability in the image conversion engine, when handling JPEG data embedded within an XPS file. | HIGH 8.8EPSS 24.5% | 27 February 2018 |
| CVE-2018-4889 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the XPS image conversion. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4888 | This vulnerability is an instance of a use after free vulnerability. | HIGH 8.8EPSS 12.2% | 27 February 2018 |
| CVE-2018-4887 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the Unicode mapping module that is invoked when processing Enhanced Metafile Format (EMF) data (during image… | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.