Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 102 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2016-4372 | HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted… | EXPLOITCRITICAL 9.8EPSS 15.4% | 15 July 2016 |
| CVE-2016-4232 | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to obtain sensitive information from process memory via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 36.5% | 13 July 2016 |
| CVE-2016-4231 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different… | EXPLOIT ✓HIGH 8.8EPSS 32.9% | 13 July 2016 |
| CVE-2016-4230 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different… | EXPLOIT ✓HIGH 8.8EPSS 32.2% | 13 July 2016 |
| CVE-2016-4229 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different… | EXPLOIT ✓HIGH 8.8EPSS 32.5% | 13 July 2016 |
| CVE-2016-4228 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different… | EXPLOIT ✓HIGH 8.8EPSS 33.1% | 13 July 2016 |
| CVE-2016-4227 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different… | EXPLOIT ✓HIGH 8.8EPSS 32.9% | 13 July 2016 |
| CVE-2016-4226 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different… | EXPLOIT ✓HIGH 8.8EPSS 33.1% | 13 July 2016 |
| CVE-2016-4208 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of… | EXPLOIT ✓CRITICAL 9.8EPSS 15.8% | 13 July 2016 |
| CVE-2016-4207 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of… | EXPLOIT ✓CRITICAL 9.8EPSS 15.8% | 13 July 2016 |
| CVE-2016-4206 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of… | EXPLOIT ✓CRITICAL 9.8EPSS 15.8% | 13 July 2016 |
| CVE-2016-4205 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of… | EXPLOIT ✓CRITICAL 9.8EPSS 15.8% | 13 July 2016 |
| CVE-2016-4204 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of… | EXPLOIT ✓CRITICAL 9.8EPSS 15.8% | 13 July 2016 |
| CVE-2016-4203 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of… | EXPLOIT ✓CRITICAL 9.8EPSS 24.1% | 13 July 2016 |
| CVE-2016-4201 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of… | EXPLOIT ✓CRITICAL 9.8EPSS 18.5% | 13 July 2016 |
| CVE-2016-4179 | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a… | EXPLOIT ✓HIGH 8.8EPSS 20.5% | 13 July 2016 |
| CVE-2016-4177 | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors,… | EXPLOIT ✓HIGH 8.8EPSS 17.6% | 13 July 2016 |
| CVE-2016-4176 | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors,… | EXPLOIT ✓HIGH 8.8EPSS 17.6% | 13 July 2016 |
| CVE-2016-4175 | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a… | EXPLOIT ✓HIGH 8.8EPSS 20.5% | 13 July 2016 |
| CVE-2016-6174 | applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute… | EXPLOITHIGH 8.1EPSS 10.7% | 12 July 2016 |
| CVE-2016-4997 | The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container… | EXPLOIT ×2 ✓HIGH 7.8EPSS 5.68% | 3 July 2016 |
| CVE-2016-1337 | Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of the boot process, related to a "Boot Information Disclosure" issue, aka Bug ID CSCux17178. | EXPLOITHIGH 8.1EPSS 3.74% | 3 July 2016 |
| CVE-2016-1336 | goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter, related to a "Gateway HTTP Corruption Denial of Service" issue, aka Bug ID CSCuy28100. | EXPLOITHIGH 7.5EPSS 7.94% | 3 July 2016 |
| CVE-2016-1328 | goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless parameter, related to a "Gateway Client List Denial of Service" issue, aka Bug ID CSCux24948. | EXPLOITHIGH 7.5EPSS 7.94% | 3 July 2016 |
| CVE-2016-3989 | The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allows… | EXPLOITHIGH 8.1EPSS 3.77% | 3 July 2016 |
| CVE-2016-3962 | Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with… | EXPLOITHIGH 7.3EPSS 6.79% | 3 July 2016 |
| CVE-2016-5734 | phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted… | EXPLOITCRITICAL 9.8EPSS 76.6% | 3 July 2016 |
| CVE-2016-5228 | Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9.4.x before 9.4 HF 12815 allows remote attackers to execute arbitrary code via a long MacroName argument. | EXPLOIT ✓CRITICAL 9.8EPSS 11.0% | 3 July 2016 |
| CVE-2016-1606 | Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code via (1) the NetworkName property value to ObjectXSNAConfig.ObjectXSNAConfig in iconfig.dll, (2) the… | EXPLOITCRITICAL 9.8EPSS 35.4% | 3 July 2016 |
| CVE-2016-0400 | CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a… | EXPLOITMEDIUM 6.1EPSS 2.51% | 2 July 2016 |
| CVE-2016-5304 | Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | EXPLOIT ✓MEDIUM 6.8EPSS 4.43% | 30 June 2016 |
| CVE-2016-3653 | Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to hijack the authentication of arbitrary users. | EXPLOIT ✓HIGH 8.0EPSS 1.28% | 30 June 2016 |
| CVE-2016-3652 | Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | EXPLOIT ✓MEDIUM 5.4EPSS 3.31% | 30 June 2016 |
| CVE-2016-3646 | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection… | EXPLOIT ✓HIGH 8.4EPSS 22.2% | 30 June 2016 |
| CVE-2016-3645 | Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before… | EXPLOIT ✓CRITICAL 9.8EPSS 18.1% | 30 June 2016 |
| CVE-2016-3644 | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection… | EXPLOIT ✓HIGH 8.4EPSS 21.7% | 30 June 2016 |
| CVE-2016-2210 | Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6… | EXPLOIT ✓HIGH 7.3EPSS 21.4% | 30 June 2016 |
| CVE-2016-2209 | Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6… | EXPLOIT ✓HIGH 7.3EPSS 24.6% | 30 June 2016 |
| CVE-2016-2207 | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection… | EXPLOIT ✓HIGH 8.4EPSS 22.6% | 30 June 2016 |
| CVE-2016-4971 | GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource. | EXPLOIT ×2 ✓HIGH 8.8EPSS 46.1% | 30 June 2016 |
| CVE-2016-4309 | Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter. | EXPLOITHIGH 7.5EPSS 9.42% | 30 June 2016 |
| CVE-2016-5840 | hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header. | EXPLOITHIGH 7.2EPSS 5.65% | 30 June 2016 |
| CVE-2016-1583 | The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames,… | EXPLOIT ✓HIGH 7.8EPSS 1.39% | 27 June 2016 |
| CVE-2016-1861 | The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1846. | EXPLOIT ✓HIGH 7.8EPSS 6.22% | 19 June 2016 |
| CVE-2016-3643 | SolarWinds Virtualization Manager Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 3.67% | 17 June 2016 |
| CVE-2016-4138 | Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs… | EXPLOIT ✓CRITICAL 9.8EPSS 25.4% | 16 June 2016 |
| CVE-2016-4137 | Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs… | EXPLOIT ✓HIGH 8.8EPSS 16.4% | 16 June 2016 |
| CVE-2016-4136 | Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs… | EXPLOIT ✓HIGH 8.8EPSS 16.4% | 16 June 2016 |
| CVE-2016-4135 | Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs… | EXPLOIT ✓HIGH 8.8EPSS 16.5% | 16 June 2016 |
| CVE-2016-3235 | Microsoft Office OLE DLL Side Loading Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 43.3% | 16 June 2016 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.