SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 100 of 501

CVESummaryPriorityPublished
CVE-2016-8582A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.EXPLOITCRITICAL 9.8EPSS 50.1%28 October 2016
CVE-2016-8581A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.EXPLOITMEDIUM 6.1EPSS 18.7%28 October 2016
CVE-2016-8580PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2.EXPLOIT ×2CRITICAL 9.8EPSS 4.86%28 October 2016
CVE-2016-5764Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution.EXPLOITHIGH 8.8EPSS 6.77%27 October 2016
CVE-2016-5617Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —25 October 2016
CVE-2016-5616Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —25 October 2016
CVE-2016-3473Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors.EXPLOITHIGH 7.7EPSS 12.0%25 October 2016
CVE-2016-6828The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certain SACK state after a failed data copy, which allows local users to cause a denial of service (tcp_xmit_retransmit_queue…EXPLOITMEDIUM 5.5EPSS 1.17%16 October 2016
CVE-2016-7194The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability…EXPLOITHIGH 7.5EPSS 52.6%14 October 2016
CVE-2016-7190The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability…EXPLOITHIGH 7.5EPSS 58.8%14 October 2016
CVE-2016-7189The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Remote Code Execution Vulnerability."EXPLOITHIGH 7.5EPSS 42.4%14 October 2016
CVE-2016-7188The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege…EXPLOITHIGH 7.8EPSS 4.15%14 October 2016
CVE-2016-7185The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a…EXPLOITHIGH 7.8EPSS 3.82%14 October 2016
CVE-2016-7182The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype…EXPLOITCRITICAL 9.8EPSS 26.2%14 October 2016
CVE-2016-3388Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a…EXPLOITMEDIUM 5.3EPSS 25.6%14 October 2016
CVE-2016-3387Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a…EXPLOITHIGH 7.5EPSS 17.8%14 October 2016
CVE-2016-3386The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability…EXPLOITHIGH 7.5EPSS 36.1%14 October 2016
CVE-2016-3376The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a…EXPLOITHIGH 7.8EPSS 12.8%14 October 2016
CVE-2016-3209Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010…EXPLOITMEDIUM 5.5EPSS 38.6%14 October 2016
CVE-2016-0079The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege…EXPLOITMEDIUM 5.0EPSS 4.10%14 October 2016
CVE-2016-0075The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the…EXPLOITMEDIUM 5.5EPSS 4.19%14 October 2016
CVE-2016-0073The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the…EXPLOITMEDIUM 5.0EPSS 4.15%14 October 2016
CVE-2016-0070The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted…EXPLOITMEDIUM 5.5EPSS 11.7%14 October 2016
CVE-2016-4273Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a…EXPLOITHIGH 8.8EPSS 19.9%13 October 2016
CVE-2016-7065The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.EXPLOITHIGH 8.8EPSS 10.4%13 October 2016
CVE-2016-5425The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging…EXPLOITHIGH 7.8EPSS 3.78%13 October 2016
CVE-2016-6689Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30768347.EXPLOITMEDIUM 5.5EPSS 2.86%10 October 2016
CVE-2016-5348The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-the-middle attackers to cause a denial of service (memory consumption, and device hang or reboot) via a…EXPLOITMEDIUM 5.9EPSS 4.68%10 October 2016
CVE-2015-2080The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.EXPLOITHIGH 7.5EPSS 62.9%7 October 2016
CVE-2016-1000125Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for JoomlaEXPLOITCRITICAL 9.8EPSS 1.60%6 October 2016
CVE-2016-1000124Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6EXPLOITCRITICAL 9.8EPSS 1.64%6 October 2016
CVE-2016-1000123Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for JoomlaEXPLOITCRITICAL 9.8EPSS 2.25%6 October 2016
CVE-2016-6435The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.EXPLOITMEDIUM 6.5EPSS 36.3%6 October 2016
CVE-2016-6434Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.EXPLOITHIGH 7.8EPSS 1.02%6 October 2016
CVE-2016-6433The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.EXPLOIT ×2HIGH 8.8EPSS 80.7%6 October 2016
CVE-2016-1240The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java…EXPLOITHIGH 7.8EPSS 9.65%3 October 2016
CVE-2016-2776buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted…EXPLOITHIGH 7.5EPSS 89.0%28 September 2016
CVE-2016-7098Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.EXPLOITHIGH 8.1EPSS 6.55%26 September 2016
CVE-2016-6662Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local…EXPLOITCRITICAL 9.8EPSS 60.1%20 September 2016
CVE-2016-6415Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure VulnerabilityKEVEXPLOITHIGH 7.5EPSS 87.7%19 September 2016
CVE-2016-4275Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a…EXPLOITHIGH 8.8EPSS 19.4%14 September 2016
CVE-2016-3373The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly implement registry access control,…EXPLOITMEDIUM 5.5EPSS 14.9%14 September 2016
CVE-2016-3371The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local…EXPLOITMEDIUM 5.5EPSS 32.9%14 September 2016
CVE-2016-3357Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, SharePoint Server 2013 SP1, Excel Automation…EXPLOITHIGH 7.8EPSS 40.9%14 September 2016
CVE-2016-3325Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."EXPLOITLOW 3.1EPSS 52.1%14 September 2016
CVE-2016-3324Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."EXPLOITHIGH 8.8EPSS 26.2%14 September 2016
CVE-2016-3247Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."EXPLOITHIGH 7.5EPSS 65.4%14 September 2016
CVE-2016-3861LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions between Unicode character encodings with different encoding widths, which allows remote attackers to…EXPLOITHIGH 7.8EPSS 22.8%11 September 2016
CVE-2016-6855Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid…EXPLOITHIGH 7.5EPSS 16.4%7 September 2016
CVE-2016-1464Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug ID CSCva09375.EXPLOITHIGH 7.8EPSS 11.7%3 September 2016

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.