SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,539 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 158 of 348

CVESummaryPriorityPublished
CVE-2018-4886This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation occurs in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to handling of bitmap…MEDIUM 6.5EPSS 10.8%27 February 2018
CVE-2018-4885This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of Enhanced Metafile Format processing engine (within the image conversion module).MEDIUM 6.5EPSS 11.2%27 February 2018
CVE-2018-4884This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion engine when processing Enhanced Metafile Format (EMF) data that embeds an image in the bitmap…MEDIUM 6.5EPSS 11.2%27 February 2018
CVE-2018-4883This vulnerability occurs because of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion engine that handles Enhanced Metafile Format (EMF).MEDIUM 6.5EPSS 10.8%27 February 2018
CVE-2018-4882This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the string literal parser.MEDIUM 6.5EPSS 10.8%27 February 2018
CVE-2018-4881This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that reads bitmap image file (BMP) data.MEDIUM 6.5EPSS 10.8%27 February 2018
CVE-2018-4880This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the conversion module that reads U3D data.MEDIUM 6.5EPSS 10.8%27 February 2018
CVE-2018-4879The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that processes Enhanced Metafile Format Plus (EMF+) data.CRITICAL 9.8EPSS 28.6%27 February 2018
CVE-2018-4872This vulnerability is a security bypass vulnerability that leads to a sandbox escape.CRITICAL 10.0EPSS 11.5%27 February 2018
CVE-2018-7490uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.HIGH 7.5EPSS 69.4%26 February 2018
CVE-2018-7448Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.HIGH 7.5EPSS 12.8%26 February 2018
CVE-2017-18195An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0.MEDIUM 5.3EPSS 11.1%26 February 2018
CVE-2018-7489FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw.CRITICAL 9.8EPSS 19.8%26 February 2018
CVE-2018-1305This could have exposed resources to users who were not authorised to access them.MEDIUM 6.5EPSS 14.5%23 February 2018
CVE-2014-3206Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.CRITICAL 9.8EPSS 51.0%23 February 2018
CVE-2018-7314SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.CRITICAL 9.8EPSS 57.8%22 February 2018
CVE-2018-7300Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbitrary files to the device's filesystem.CRITICAL 9.8EPSS 30.6%22 February 2018
CVE-2018-7297Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device.CRITICAL 9.8EPSS 64.3%22 February 2018
CVE-2018-7313SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.CRITICAL 9.8EPSS 19.1%22 February 2018
CVE-2018-7287An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1.MEDIUM 5.9EPSS 11.5%22 February 2018
CVE-2018-7286An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP…MEDIUM 6.5EPSS 38.3%22 February 2018
CVE-2018-7284A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2.HIGH 7.5EPSS 57.7%22 February 2018
CVE-2016-6272XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp.HIGH 7.5EPSS 20.9%20 February 2018
CVE-2018-7251The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.CRITICAL 9.8EPSS 71.8%19 February 2018
CVE-2017-7376Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.CRITICAL 9.8EPSS 23.3%19 February 2018
CVE-2018-5381The parser can enter an infinite loop on invalid capabilities if a Multi-Protocol capability does not have a recognized AFI/SAFI, causing a denial of service.HIGH 7.5EPSS 30.2%19 February 2018
CVE-2018-5380The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.MEDIUM 4.3EPSS 14.8%19 February 2018
CVE-2018-5379A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.CRITICAL 9.8EPSS 38.5%19 February 2018
CVE-2018-5378Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.MEDIUM 5.9EPSS 74.2%19 February 2018
CVE-2018-6583SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.CRITICAL 9.8EPSS 19.1%17 February 2018
CVE-2018-6396SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action.CRITICAL 9.8EPSS 23.6%17 February 2018
CVE-2018-6006SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter.CRITICAL 9.8EPSS 19.1%17 February 2018
CVE-2018-3609A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be used to bypass authentication on…HIGH 8.1EPSS 21.4%16 February 2018
CVE-2018-7187The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a…HIGH 8.8EPSS 63.0%16 February 2018
CVE-2017-14537trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.MEDIUM 6.5EPSS 39.3%16 February 2018
CVE-2017-14535trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.HIGH 8.8EPSS 50.1%16 February 2018
CVE-2018-5767A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.CRITICAL 9.8EPSS 47.4%15 February 2018
CVE-2017-8984A remote code execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506P03 was found.HIGH 8.8EPSS 11.1%15 February 2018
CVE-2017-8982A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.HIGH 7.5EPSS 14.2%15 February 2018
CVE-2017-8976A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.CRITICAL 9.8EPSS 18.2%15 February 2018
CVE-2017-8975A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.CRITICAL 9.8EPSS 18.2%15 February 2018
CVE-2017-8961A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution.HIGH 8.8EPSS 19.1%15 February 2018
CVE-2017-8958A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 and earlier was found.HIGH 8.8EPSS 11.1%15 February 2018
CVE-2017-8957A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.CRITICAL 9.8EPSS 18.2%15 February 2018
CVE-2017-8956A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.CRITICAL 9.8EPSS 10.2%15 February 2018
CVE-2017-8955A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.HIGH 7.5EPSS 11.8%15 February 2018
CVE-2017-8954A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.CRITICAL 9.8EPSS 18.2%15 February 2018
CVE-2017-8947A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found.CRITICAL 9.8EPSS 29.8%15 February 2018
CVE-2017-8946A Remote Code Execution vulnerability in HPE Aruba AirWave Glass version v1.0.0 and 1.0.1 was found.HIGH 8.3EPSS 10.7%15 February 2018
CVE-2017-5824An unauthenticated remote code execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.CRITICAL 9.8EPSS 19.3%15 February 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.