SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 101 of 501

CVESummaryPriorityPublished
CVE-2016-1415Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted file, aka Bug ID CSCuz80455.EXPLOITMEDIUM 5.5EPSS 8.91%3 September 2016
CVE-2016-0772The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network…EXPLOITMEDIUM 6.5EPSS 16.4%2 September 2016
CVE-2016-6483The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 before Patch Level 1, and…EXPLOITHIGH 8.6EPSS 10.6%2 September 2016
CVE-2016-4264The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via a crafted OOXML spreadsheet containing an external entity…EXPLOITHIGH 8.6EPSS 34.2%1 September 2016
CVE-2016-5680Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary code via the sn parameter to the transfer_license command.EXPLOITHIGH 8.8EPSS 14.9%31 August 2016
CVE-2016-5679cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn parameter to the transfer_license command.EXPLOITHIGH 8.8EPSS 11.9%31 August 2016
CVE-2016-5678NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.EXPLOITCRITICAL 9.8EPSS 6.48%31 August 2016
CVE-2016-5677NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via…EXPLOITHIGH 7.5EPSS 9.04%31 August 2016
CVE-2016-5676cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefconfig action.EXPLOITHIGH 7.5EPSS 50.3%31 August 2016
CVE-2016-5675handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the…EXPLOITCRITICAL 9.8EPSS 65.7%31 August 2016
CVE-2016-5674__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.EXPLOITCRITICAL 9.8EPSS 91.5%31 August 2016
CVE-2016-6195SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as…EXPLOITCRITICAL 9.8EPSS 35.7%30 August 2016
CVE-2015-5399Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment.EXPLOITMEDIUM 5.4EPSS 2.81%26 August 2016
CVE-2016-4657Apple iOS Webkit Memory Corruption VulnerabilityKEVEXPLOIT ×2HIGH 8.8EPSS 66.8%25 August 2016
CVE-2016-4656Apple iOS Memory Corruption VulnerabilityKEVEXPLOITHIGH 7.8EPSS 23.6%25 August 2016
CVE-2016-4655Apple iOS Information Disclosure VulnerabilityKEVEXPLOITMEDIUM 5.5EPSS 33.4%25 August 2016
CVE-2016-7089WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifconfig command, aka ESCALATEPLOWMAN.EXPLOITHIGH 7.8EPSS 1.18%24 August 2016
CVE-2016-6909Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.EXPLOITCRITICAL 9.8EPSS 36.2%24 August 2016
CVE-2016-6367Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution VulnerabilityKEVEXPLOITHIGH 7.8EPSS 22.6%18 August 2016
CVE-2016-6366Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow VulnerabilityKEVEXPLOITHIGH 8.8EPSS 87.6%18 August 2016
CVE-2016-5847SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384.EXPLOITMEDIUM 5.8EPSS 0.94%13 August 2016
CVE-2016-5845SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of service (program crash) via an invalid file name in an archive file, aka SAP Security Note 2312905.EXPLOITMEDIUM 5.5EPSS 2.98%13 August 2016
CVE-2016-3316Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability."EXPLOITHIGH 7.8EPSS 33.5%9 August 2016
CVE-2016-3313Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability."EXPLOITHIGH 7.8EPSS 39.6%9 August 2016
CVE-2016-3309Microsoft Windows Kernel Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 20.5%9 August 2016
CVE-2016-3304The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007…EXPLOITHIGH 7.8EPSS 41.8%9 August 2016
CVE-2016-3303The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007…EXPLOITHIGH 7.8EPSS 41.8%9 August 2016
CVE-2016-3301The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer;…EXPLOITHIGH 7.8EPSS 34.9%9 August 2016
CVE-2016-3288Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3290.EXPLOITHIGH 7.5EPSS 45.6%9 August 2016
CVE-2016-3237Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows man-in-the-middle attackers to bypass authentication via…EXPLOITHIGH 7.5EPSS 17.3%9 August 2016
CVE-2016-5330Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x…EXPLOITHIGH 7.8EPSS 18.0%8 August 2016
CVE-2015-6396The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.EXPLOITHIGH 7.8EPSS 1.85%8 August 2016
CVE-2016-6515The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) via a long string.EXPLOITHIGH 7.5EPSS 46.2%7 August 2016
CVE-2016-3078Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted call to (1)…EXPLOITCRITICAL 9.8EPSS 56.1%7 August 2016
CVE-2016-6512epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet, related to the MMSE, WAP, WBXML, and…EXPLOITMEDIUM 5.9EPSS 7.15%6 August 2016
CVE-2016-6505epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet.EXPLOITMEDIUM 5.9EPSS 7.35%6 August 2016
CVE-2016-6504epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via…EXPLOITMEDIUM 5.9EPSS 6.20%6 August 2016
CVE-2016-6503The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler options, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.EXPLOITMEDIUM 5.9EPSS 6.06%6 August 2016
CVE-2016-6187The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor setprocattr hook.EXPLOITHIGH 7.8EPSS 2.40%6 August 2016
CVE-2016-6186Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to…EXPLOITMEDIUM 6.1EPSS 6.65%5 August 2016
CVE-2016-5639Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 14.0%3 August 2016
CVE-2016-1611Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.sh, which allows local users to gain privileges by replacing this file's content with arbitrary shell commands.EXPLOITHIGH 7.8EPSS 1.22%1 August 2016
CVE-2016-1610Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote attackers to bypass intended access restrictions and write to arbitrary files via a ..EXPLOITHIGH 7.5EPSS 8.66%1 August 2016
CVE-2016-1609Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input, as demonstrated by a crafted…EXPLOITMEDIUM 5.4EPSS 4.44%1 August 2016
CVE-2016-1608vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ntpServer parameter.EXPLOITHIGH 8.8EPSS 10.9%1 August 2016
CVE-2016-1607Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Security Update 2 allow remote attackers to hijack the authentication of administrators, as demonstrated by reconfiguring time settings…EXPLOITHIGH 7.2EPSS 2.97%1 August 2016
CVE-2016-4469Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add new repository proxy connectors via the token parameter to…EXPLOITHIGH 8.8EPSS 9.79%28 July 2016
CVE-2016-4625Use-after-free vulnerability in IOSurface in Apple OS X before 10.11.6 allows local users to gain privileges via unspecified vectors.EXPLOIT ×2HIGH 7.8EPSS 1.93%22 July 2016
CVE-2016-1863The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than…EXPLOITHIGH 7.8EPSS 0.96%22 July 2016
CVE-2016-3542Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote administrators to affect confidentiality and integrity via unknown vectors.EXPLOITMEDIUM 6.5EPSS 8.21%21 July 2016

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.