SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,540 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 160 of 348

CVESummaryPriorityPublished
CVE-2018-2392Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.HIGH 7.5EPSS 41.1%14 February 2018
CVE-2018-6910DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.HIGH 7.5EPSS 18.8%13 February 2018
CVE-2017-15709When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.LOW 3.7EPSS 22.9%13 February 2018
CVE-2018-6911The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).CRITICAL 9.8EPSS 12.8%13 February 2018
CVE-2018-6892An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition.CRITICAL 9.8EPSS 93.4%11 February 2018
CVE-2018-1000049Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API.HIGH 7.5EPSS 76.9%9 February 2018
CVE-2018-1000035A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.HIGH 7.8EPSS 30.0%9 February 2018
CVE-2018-1000027The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy.HIGH 7.5EPSS 12.9%9 February 2018
CVE-2018-3607XXXTreeNode method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.HIGH 8.8EPSS 14.4%9 February 2018
CVE-2018-3606XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.HIGH 8.8EPSS 48.8%9 February 2018
CVE-2018-3605TopXXX, ViolationXXX, and IncidentXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.HIGH 8.8EPSS 19.9%9 February 2018
CVE-2018-3604GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.HIGH 8.8EPSS 67.8%9 February 2018
CVE-2018-6871LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.CRITICAL 9.8EPSS 22.8%9 February 2018
CVE-2018-6789Exim Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 82.1%8 February 2018
CVE-2018-5550Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie or perform other reflected XSS attacks on a currently…MEDIUM 6.1EPSS 36.9%8 February 2018
CVE-2018-1163This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13.CRITICAL 9.8EPSS 16.0%8 February 2018
CVE-2018-1161This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.2.0.13.CRITICAL 9.8EPSS 66.7%8 February 2018
CVE-2017-17420This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.CRITICAL 9.8EPSS 48.2%8 February 2018
CVE-2018-0127A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, which could lead…CRITICAL 9.8EPSS 77.5%8 February 2018
CVE-2018-0125Cisco VPN Routers Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 55.2%8 February 2018
CVE-2018-6794Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c.MEDIUM 5.3EPSS 24.3%7 February 2018
CVE-2018-4878Adobe Flash Player Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 89.5%6 February 2018
CVE-2018-6389In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many…HIGH 7.5EPSS 72.7%6 February 2018
CVE-2017-7525A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the…CRITICAL 9.8EPSS 37.7%6 February 2018
CVE-2018-6605SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.CRITICAL 9.8EPSS 57.7%5 February 2018
CVE-2017-9414Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that conduct cross-site scripting (XSS) attacks or possibly…HIGH 8.8EPSS 15.4%5 February 2018
CVE-2018-6317The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remote attackers to read memory or cause a denial of service.CRITICAL 9.1EPSS 43.7%2 February 2018
CVE-2018-6580Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.CRITICAL 9.8EPSS 36.3%2 February 2018
CVE-2018-5701In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerability due to not validating input values from IOCtl 0x00226003.CRITICAL 9.8EPSS 18.5%31 January 2018
CVE-2014-1632htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.HIGH 8.1EPSS 10.5%31 January 2018
CVE-2018-6460User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter func=$_APPLOG.Rfunc and extract sensitive information about the machine, including whether the user is connected to…HIGH 7.5EPSS 11.0%31 January 2018
CVE-2018-1000001In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.HIGH 7.8EPSS 13.4%31 January 2018
CVE-2018-6407An unauthenticated attacker can crash a device by sending a POST request with a huge body size to /hy-cgi/devices.cgi?cmd=searchlandevice.HIGH 7.5EPSS 32.3%30 January 2018
CVE-2016-659911.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.CRITICAL 9.8EPSS 12.3%30 January 2018
CVE-2016-659811.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010.CRITICAL 9.8EPSS 19.2%30 January 2018
CVE-2018-6377In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkboxMEDIUM 6.1EPSS 56.5%30 January 2018
CVE-2018-6397Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter.HIGH 7.5EPSS 11.9%30 January 2018
CVE-2018-0101A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code.CRITICAL 10.0EPSS 86.8%29 January 2018
CVE-2018-6383Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbitrary PHP code by uploading a…HIGH 8.8EPSS 13.5%29 January 2018
CVE-2017-12626Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS…HIGH 7.5EPSS 10.1%29 January 2018
CVE-2017-1000353Jenkins Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.7%29 January 2018
CVE-2018-6008Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.HIGH 7.5EPSS 36.8%29 January 2018
CVE-2017-17976In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.CRITICAL 9.8EPSS 12.5%26 January 2018
CVE-2017-12379ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device.CRITICAL 9.8EPSS 12.5%26 January 2018
CVE-2017-12377ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device.CRITICAL 9.8EPSS 11.6%26 January 2018
CVE-2018-5997Due to an unrestricted upload feature and a path traversal vulnerability, it is possible to upload a file on a filesystem with root privileges: this will lead to remote code execution as root.CRITICAL 9.8EPSS 23.5%25 January 2018
CVE-2018-5973SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryID or CategoryID parameter.CRITICAL 9.8EPSS 20.1%25 January 2018
CVE-2018-1000006GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in…HIGH 8.8EPSS 84.5%24 January 2018
CVE-2018-5319RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request.HIGH 7.5EPSS 12.4%24 January 2018
CVE-2017-13696A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and…CRITICAL 9.8EPSS 78.3%24 January 2018

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.