Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,540 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 161 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-5988 | SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php. | CRITICAL 9.8EPSS 19.1% | 24 January 2018 |
| CVE-2018-5985 | SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request. | CRITICAL 9.8EPSS 19.1% | 24 January 2018 |
| CVE-2018-5979 | SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field. | CRITICAL 9.8EPSS 19.1% | 24 January 2018 |
| CVE-2018-5972 | SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI. | CRITICAL 9.8EPSS 19.1% | 24 January 2018 |
| CVE-2017-2741 | A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D. | CRITICAL 9.8EPSS 84.6% | 23 January 2018 |
| CVE-2017-18048 | Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not. | HIGH 8.8EPSS 63.4% | 23 January 2018 |
| CVE-2017-16603 | This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. | HIGH 8.8EPSS 54.0% | 23 January 2018 |
| CVE-2017-16597 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. | CRITICAL 9.8EPSS 57.3% | 23 January 2018 |
| CVE-2018-0862 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word… | HIGH 8.8EPSS 18.6% | 22 January 2018 |
| CVE-2018-0849 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word… | HIGH 8.8EPSS 18.6% | 22 January 2018 |
| CVE-2018-0848 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word… | HIGH 8.8EPSS 20.5% | 22 January 2018 |
| CVE-2018-0845 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word… | HIGH 7.8EPSS 19.7% | 22 January 2018 |
| CVE-2018-6000 | The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and… | CRITICAL 9.8EPSS 85.2% | 22 January 2018 |
| CVE-2018-5999 | An issue was discovered in AsusWRT before 3.0.0.4.384_10007. | CRITICAL 9.8EPSS 87.3% | 22 January 2018 |
| CVE-2018-1042 | Moodle 3.x has Server Side Request Forgery in the filepicker. | MEDIUM 6.5EPSS 16.7% | 22 January 2018 |
| CVE-2017-18047 | Buffer Overflow in the FTP client in LabF nfsAxe 3.7 allows remote FTP servers to execute arbitrary code via a long reply. | CRITICAL 9.8EPSS 19.7% | 22 January 2018 |
| CVE-2016-10709 | pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php. | HIGH 8.8EPSS 33.7% | 22 January 2018 |
| CVE-2018-5955 | User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a user to the server via the username and password fields to the rest/user/ URI. | CRITICAL 9.8EPSS 81.4% | 21 January 2018 |
| CVE-2016-10708 | sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c. | HIGH 7.5EPSS 15.7% | 21 January 2018 |
| CVE-2017-14803 | In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system. | CRITICAL 9.8EPSS 34.6% | 20 January 2018 |
| CVE-2017-14097 | An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decrypt contents of a database with information that could be used to access a vulnerable system. | CRITICAL 9.8EPSS 12.7% | 19 January 2018 |
| CVE-2017-14095 | A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system. | HIGH 8.1EPSS 12.5% | 19 January 2018 |
| CVE-2017-14094 | A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system. | CRITICAL 9.8EPSS 19.4% | 19 January 2018 |
| CVE-2017-18044 | A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. | CRITICAL 9.8EPSS 69.8% | 19 January 2018 |
| CVE-2015-9251 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | MEDIUM 6.1EPSS 29.7% | 18 January 2018 |
| CVE-2016-6814 | When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for… | CRITICAL 9.8EPSS 17.2% | 18 January 2018 |
| CVE-2018-2636 | Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security). | HIGH 8.1EPSS 15.1% | 18 January 2018 |
| CVE-2018-2616 | Vulnerability in the OSS Support Tools component of Oracle Support Tools (subcomponent: Diagnostic Assistant). | HIGH 8.8EPSS 27.1% | 18 January 2018 |
| CVE-2018-5726 | MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by the username, password, and configuration settings. | CRITICAL 9.8EPSS 19.8% | 16 January 2018 |
| CVE-2018-5724 | MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi. | CRITICAL 9.8EPSS 11.5% | 16 January 2018 |
| CVE-2018-5712 | There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file. | MEDIUM 6.1EPSS 79.9% | 16 January 2018 |
| CVE-2018-5711 | gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by… | MEDIUM 5.5EPSS 13.2% | 16 January 2018 |
| CVE-2018-5702 | Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests… | HIGH 8.8EPSS 11.9% | 15 January 2018 |
| CVE-2018-5262 | A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account. | CRITICAL 9.8EPSS 39.1% | 12 January 2018 |
| CVE-2017-16887 | Unauthorized Access to Web Services can result in disclosure of the WLAN key/password. | CRITICAL 9.8EPSS 36.6% | 12 January 2018 |
| CVE-2017-16885 | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. | CRITICAL 9.8EPSS 33.5% | 12 January 2018 |
| CVE-2014-6437 | Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors involving the ROM file. | CRITICAL 9.8EPSS 15.5% | 12 January 2018 |
| CVE-2014-6436 | Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an… | CRITICAL 9.8EPSS 42.1% | 12 January 2018 |
| CVE-2014-6435 | cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers to cause a denial of service (WAN connectivity reset) via a direct request. | HIGH 7.5EPSS 12.6% | 12 January 2018 |
| CVE-2018-5371 | diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET… | HIGH 8.8EPSS 42.0% | 12 January 2018 |
| CVE-2018-5347 | Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled. | CRITICAL 9.8EPSS 54.2% | 12 January 2018 |
| CVE-2017-17485 | FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. | CRITICAL 9.8EPSS 49.7% | 10 January 2018 |
| CVE-2017-15663 | In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. | HIGH 7.5EPSS 13.2% | 10 January 2018 |
| CVE-2016-9722 | IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. | MEDIUM 4.2EPSS 12.0% | 10 January 2018 |
| CVE-2018-0812 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word… | HIGH 7.8EPSS 23.9% | 10 January 2018 |
| CVE-2018-0807 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word… | HIGH 8.8EPSS 24.4% | 10 January 2018 |
| CVE-2018-0806 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word… | HIGH 8.8EPSS 24.7% | 10 January 2018 |
| CVE-2018-0805 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word… | HIGH 8.8EPSS 24.4% | 10 January 2018 |
| CVE-2018-0804 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word… | HIGH 8.8EPSS 24.4% | 10 January 2018 |
| CVE-2018-0802 | Microsoft Office Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 93.3% | 10 January 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.