Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,539 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 158 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-4886 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation occurs in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to handling of bitmap… | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4885 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of Enhanced Metafile Format processing engine (within the image conversion module). | MEDIUM 6.5EPSS 11.2% | 27 February 2018 |
| CVE-2018-4884 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion engine when processing Enhanced Metafile Format (EMF) data that embeds an image in the bitmap… | MEDIUM 6.5EPSS 11.2% | 27 February 2018 |
| CVE-2018-4883 | This vulnerability occurs because of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion engine that handles Enhanced Metafile Format (EMF). | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4882 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the string literal parser. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4881 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that reads bitmap image file (BMP) data. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4880 | This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the conversion module that reads U3D data. | MEDIUM 6.5EPSS 10.8% | 27 February 2018 |
| CVE-2018-4879 | The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that processes Enhanced Metafile Format Plus (EMF+) data. | CRITICAL 9.8EPSS 28.6% | 27 February 2018 |
| CVE-2018-4872 | This vulnerability is a security bypass vulnerability that leads to a sandbox escape. | CRITICAL 10.0EPSS 11.5% | 27 February 2018 |
| CVE-2018-7490 | uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal. | HIGH 7.5EPSS 69.4% | 26 February 2018 |
| CVE-2018-7448 | Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure. | HIGH 7.5EPSS 12.8% | 26 February 2018 |
| CVE-2017-18195 | An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. | MEDIUM 5.3EPSS 11.1% | 26 February 2018 |
| CVE-2018-7489 | FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. | CRITICAL 9.8EPSS 19.8% | 26 February 2018 |
| CVE-2018-1305 | This could have exposed resources to users who were not authorised to access them. | MEDIUM 6.5EPSS 14.5% | 23 February 2018 |
| CVE-2014-3206 | Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php. | CRITICAL 9.8EPSS 51.0% | 23 February 2018 |
| CVE-2018-7314 | SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. | CRITICAL 9.8EPSS 57.8% | 22 February 2018 |
| CVE-2018-7300 | Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbitrary files to the device's filesystem. | CRITICAL 9.8EPSS 30.6% | 22 February 2018 |
| CVE-2018-7297 | Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device. | CRITICAL 9.8EPSS 64.3% | 22 February 2018 |
| CVE-2018-7313 | SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter. | CRITICAL 9.8EPSS 19.1% | 22 February 2018 |
| CVE-2018-7287 | An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. | MEDIUM 5.9EPSS 11.5% | 22 February 2018 |
| CVE-2018-7286 | An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP… | MEDIUM 6.5EPSS 38.3% | 22 February 2018 |
| CVE-2018-7284 | A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. | HIGH 7.5EPSS 57.7% | 22 February 2018 |
| CVE-2016-6272 | XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. | HIGH 7.5EPSS 20.9% | 20 February 2018 |
| CVE-2018-7251 | The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred. | CRITICAL 9.8EPSS 71.8% | 19 February 2018 |
| CVE-2017-7376 | Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects. | CRITICAL 9.8EPSS 23.3% | 19 February 2018 |
| CVE-2018-5381 | The parser can enter an infinite loop on invalid capabilities if a Multi-Protocol capability does not have a recognized AFI/SAFI, causing a denial of service. | HIGH 7.5EPSS 30.2% | 19 February 2018 |
| CVE-2018-5380 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input. | MEDIUM 4.3EPSS 14.8% | 19 February 2018 |
| CVE-2018-5379 | A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code. | CRITICAL 9.8EPSS 38.5% | 19 February 2018 |
| CVE-2018-5378 | Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash. | MEDIUM 5.9EPSS 74.2% | 19 February 2018 |
| CVE-2018-6583 | SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request. | CRITICAL 9.8EPSS 19.1% | 17 February 2018 |
| CVE-2018-6396 | SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action. | CRITICAL 9.8EPSS 23.6% | 17 February 2018 |
| CVE-2018-6006 | SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter. | CRITICAL 9.8EPSS 19.1% | 17 February 2018 |
| CVE-2018-3609 | A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be used to bypass authentication on… | HIGH 8.1EPSS 21.4% | 16 February 2018 |
| CVE-2018-7187 | The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a… | HIGH 8.8EPSS 63.0% | 16 February 2018 |
| CVE-2017-14537 | trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php. | MEDIUM 6.5EPSS 39.3% | 16 February 2018 |
| CVE-2017-14535 | trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php. | HIGH 8.8EPSS 50.1% | 16 February 2018 |
| CVE-2018-5767 | A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header. | CRITICAL 9.8EPSS 47.4% | 15 February 2018 |
| CVE-2017-8984 | A remote code execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506P03 was found. | HIGH 8.8EPSS 11.1% | 15 February 2018 |
| CVE-2017-8982 | A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found. | HIGH 7.5EPSS 14.2% | 15 February 2018 |
| CVE-2017-8976 | A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found. | CRITICAL 9.8EPSS 18.2% | 15 February 2018 |
| CVE-2017-8975 | A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found. | CRITICAL 9.8EPSS 18.2% | 15 February 2018 |
| CVE-2017-8961 | A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution. | HIGH 8.8EPSS 19.1% | 15 February 2018 |
| CVE-2017-8958 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 and earlier was found. | HIGH 8.8EPSS 11.1% | 15 February 2018 |
| CVE-2017-8957 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. | CRITICAL 9.8EPSS 18.2% | 15 February 2018 |
| CVE-2017-8956 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | CRITICAL 9.8EPSS 10.2% | 15 February 2018 |
| CVE-2017-8955 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. | HIGH 7.5EPSS 11.8% | 15 February 2018 |
| CVE-2017-8954 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. | CRITICAL 9.8EPSS 18.2% | 15 February 2018 |
| CVE-2017-8947 | A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found. | CRITICAL 9.8EPSS 29.8% | 15 February 2018 |
| CVE-2017-8946 | A Remote Code Execution vulnerability in HPE Aruba AirWave Glass version v1.0.0 and 1.0.1 was found. | HIGH 8.3EPSS 10.7% | 15 February 2018 |
| CVE-2017-5824 | An unauthenticated remote code execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found. | CRITICAL 9.8EPSS 19.3% | 15 February 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.