Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,540 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 159 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-5823 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | CRITICAL 9.8EPSS 18.2% | 15 February 2018 |
| CVE-2017-5822 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | HIGH 7.5EPSS 11.9% | 15 February 2018 |
| CVE-2017-5821 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | CRITICAL 9.8EPSS 16.5% | 15 February 2018 |
| CVE-2017-5820 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | CRITICAL 9.8EPSS 18.2% | 15 February 2018 |
| CVE-2017-5819 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | CRITICAL 9.8EPSS 18.2% | 15 February 2018 |
| CVE-2017-5818 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | HIGH 7.5EPSS 11.8% | 15 February 2018 |
| CVE-2017-5817 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | CRITICAL 9.8EPSS 82.6% | 15 February 2018 |
| CVE-2017-5816 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | CRITICAL 9.8EPSS 86.2% | 15 February 2018 |
| CVE-2017-5815 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | CRITICAL 9.8EPSS 33.7% | 15 February 2018 |
| CVE-2017-5811 | A remote code execution vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found. | HIGH 7.5EPSS 17.0% | 15 February 2018 |
| CVE-2017-5808 | A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found. | HIGH 7.5EPSS 16.1% | 15 February 2018 |
| CVE-2017-5807 | A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found. | CRITICAL 9.8EPSS 21.9% | 15 February 2018 |
| CVE-2017-5806 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. | CRITICAL 9.8EPSS 22.2% | 15 February 2018 |
| CVE-2017-5805 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. | CRITICAL 9.8EPSS 22.2% | 15 February 2018 |
| CVE-2017-5804 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. | CRITICAL 9.8EPSS 22.2% | 15 February 2018 |
| CVE-2017-5799 | A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. | HIGH 8.8EPSS 15.2% | 15 February 2018 |
| CVE-2017-5792 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found. | CRITICAL 9.8EPSS 34.3% | 15 February 2018 |
| CVE-2017-5790 | A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found. | CRITICAL 9.8EPSS 18.0% | 15 February 2018 |
| CVE-2017-12561 | A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT version Plat 7.3 E0504P4 and earlier was found. | CRITICAL 9.8EPSS 30.6% | 15 February 2018 |
| CVE-2017-12558 | A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. | CRITICAL 9.8EPSS 37.9% | 15 February 2018 |
| CVE-2017-12557 | A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. | CRITICAL 9.8EPSS 79.8% | 15 February 2018 |
| CVE-2017-12556 | A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. | CRITICAL 9.8EPSS 37.9% | 15 February 2018 |
| CVE-2017-12542 | A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found. | CRITICAL 10.0EPSS 99.3% | 15 February 2018 |
| CVE-2017-12500 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. | HIGH 8.8EPSS 14.7% | 15 February 2018 |
| CVE-2016-8530 | A remote denial of service vulnerability in HPE iMC PLAT version v7.2 E0403P06 and earlier was found. | HIGH 7.5EPSS 48.0% | 15 February 2018 |
| CVE-2016-8523 | A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found. | HIGH 8.8EPSS 16.7% | 15 February 2018 |
| CVE-2016-8519 | A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found. | CRITICAL 9.8EPSS 27.6% | 15 February 2018 |
| CVE-2016-8511 | A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10.00.02, v10.10, v10.11, v10.11.01, v10.20 was found. | CRITICAL 9.8EPSS 15.3% | 15 February 2018 |
| CVE-2018-1041 | A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. | HIGH 7.5EPSS 15.5% | 15 February 2018 |
| CVE-2017-12718 | A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. | HIGH 8.1EPSS 12.8% | 15 February 2018 |
| CVE-2018-0866 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the… | HIGH 7.5EPSS 43.6% | 15 February 2018 |
| CVE-2018-0861 | Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 14.8% | 15 February 2018 |
| CVE-2018-0860 | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 65.3% | 15 February 2018 |
| CVE-2018-0859 | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 17.7% | 15 February 2018 |
| CVE-2018-0858 | ChakraCore allows remote code execution, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 14.8% | 15 February 2018 |
| CVE-2018-0857 | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 15.4% | 15 February 2018 |
| CVE-2018-0856 | Microsoft Edge and ChakraCore in Microsoft Windows 10 1703 and 1709 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 15.4% | 15 February 2018 |
| CVE-2018-0853 | Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow an information disclosure vulnerability, due to how Office initializes the affected variable, aka "Microsoft… | LOW 3.3EPSS 11.8% | 15 February 2018 |
| CVE-2018-0852 | Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1 and RT SP1, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Outlook handles objects in… | HIGH 8.8EPSS 19.4% | 15 February 2018 |
| CVE-2018-0851 | Microsoft Office 2007 SP2, Microsoft Office Word Viewer, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Office… | HIGH 8.8EPSS 19.1% | 15 February 2018 |
| CVE-2018-0841 | Microsoft Office 2016 Click-to-Run allows a remote code execution vulnerability due to how objects are handled in memory, aka "Office Remote Code Execution Vulnerability" | HIGH 8.8EPSS 20.1% | 15 February 2018 |
| CVE-2018-0840 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows… | HIGH 7.5EPSS 53.1% | 15 February 2018 |
| CVE-2018-0838 | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 65.3% | 15 February 2018 |
| CVE-2018-0837 | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 65.3% | 15 February 2018 |
| CVE-2018-0836 | Microsoft Edge and ChakraCore in Microsoft Windows 10 1703 and 1709 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 15.4% | 15 February 2018 |
| CVE-2018-0835 | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 65.3% | 15 February 2018 |
| CVE-2018-0834 | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 54.9% | 15 February 2018 |
| CVE-2018-0833 | The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service vulnerability due to how specially crafted requests are handled, aka "SMBv2/SMBv3 Null Dereference Denial… | MEDIUM 5.3EPSS 39.9% | 15 February 2018 |
| CVE-2018-0825 | StructuredQuery in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution… | HIGH 7.5EPSS 16.5% | 15 February 2018 |
| CVE-2018-2393 | Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable. | HIGH 7.5EPSS 15.5% | 14 February 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.