Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 106 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2016-0121 | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary… | EXPLOIT ✓HIGH 8.8EPSS 35.2% | 9 March 2016 |
| CVE-2016-0120 | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to cause a denial of… | EXPLOIT ✓MEDIUM 6.5EPSS 36.3% | 9 March 2016 |
| CVE-2016-0111 | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different… | EXPLOIT ✓HIGH 7.5EPSS 40.8% | 9 March 2016 |
| CVE-2016-0108 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | EXPLOIT ✓HIGH 7.5EPSS 39.6% | 9 March 2016 |
| CVE-2016-0100 | Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Library Loading Input Validation Remote Code Execution Vulnerability." | EXPLOIT ✓HIGH 8.4EPSS 57.6% | 9 March 2016 |
| CVE-2016-0099 | Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability | KEVEXPLOIT ×4 ✓HIGH 7.8EPSS 36.9% | 9 March 2016 |
| CVE-2016-0094 | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted… | EXPLOIT ✓HIGH 7.8EPSS 4.15% | 9 March 2016 |
| CVE-2016-0093 | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted… | EXPLOIT ✓HIGH 7.8EPSS 4.15% | 9 March 2016 |
| CVE-2016-2279 | Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOITMEDIUM 6.1EPSS 7.59% | 2 March 2016 |
| CVE-2016-2278 | Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism. | EXPLOITHIGH 7.2EPSS 11.5% | 2 March 2016 |
| CVE-2015-7547 | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary… | EXPLOIT ×2 ✓HIGH 8.1EPSS 89.0% | 18 February 2016 |
| CVE-2016-2389 | Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. | EXPLOITHIGH 7.5EPSS 20.4% | 16 February 2016 |
| CVE-2016-2388 | SAP NetWeaver Information Disclosure Vulnerability | KEVEXPLOIT ×2MEDIUM 5.3EPSS 52.2% | 16 February 2016 |
| CVE-2016-2386 | SAP NetWeaver SQL Injection Vulnerability | KEVEXPLOIT ×2CRITICAL 9.8EPSS 71.5% | 16 February 2016 |
| CVE-2016-0752 | Ruby on Rails Directory Traversal Vulnerability | KEVEXPLOIT ✓HIGH 7.5EPSS 95.5% | 16 February 2016 |
| CVE-2016-1525 | Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a .. | EXPLOIT ×2 ✓HIGH 8.6EPSS 71.4% | 13 February 2016 |
| CVE-2016-1524 | Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file,… | EXPLOITCRITICAL 9.6EPSS 91.6% | 13 February 2016 |
| CVE-2016-1287 | Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7), 9.4 before 9.4(2.4), and 9.5 before 9.5(2.2) on ASA… | EXPLOIT ✓CRITICAL 9.8EPSS 49.3% | 11 February 2016 |
| CVE-2016-0985 | Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers… | EXPLOIT ✓HIGH 8.8EPSS 26.1% | 10 February 2016 |
| CVE-2016-0984 | Adobe Flash Player and AIR Use-After-Free Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 54.5% | 10 February 2016 |
| CVE-2016-0974 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler… | EXPLOIT ✓HIGH 8.8EPSS 30.8% | 10 February 2016 |
| CVE-2016-0971 | Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler… | EXPLOIT ✓HIGH 8.8EPSS 33.5% | 10 February 2016 |
| CVE-2016-0967 | Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers… | EXPLOIT ✓HIGH 8.8EPSS 19.7% | 10 February 2016 |
| CVE-2016-0965 | Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers… | EXPLOIT ✓HIGH 8.8EPSS 19.7% | 10 February 2016 |
| CVE-2016-0964 | Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers… | EXPLOIT ✓HIGH 8.8EPSS 19.7% | 10 February 2016 |
| CVE-2016-0956 | The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 43.7% | 10 February 2016 |
| CVE-2016-0953 | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than… | EXPLOIT ✓CRITICAL 9.8EPSS 17.3% | 10 February 2016 |
| CVE-2016-0952 | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than… | EXPLOIT ✓CRITICAL 9.8EPSS 17.3% | 10 February 2016 |
| CVE-2016-0951 | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than… | EXPLOIT ✓CRITICAL 9.8EPSS 17.3% | 10 February 2016 |
| CVE-2016-0063 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | EXPLOIT ✓HIGH 8.8EPSS 34.9% | 10 February 2016 |
| CVE-2016-0051 | The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted… | EXPLOIT ×3 ✓HIGH 7.8EPSS 24.3% | 10 February 2016 |
| CVE-2016-0049 | Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass… | EXPLOIT ✓MEDIUM 6.2EPSS 14.2% | 10 February 2016 |
| CVE-2016-0041 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 10 and 11 mishandle DLL loading, which allows local users to… | EXPLOIT ✓HIGH 7.8EPSS 75.5% | 10 February 2016 |
| CVE-2016-0040 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 24.5% | 10 February 2016 |
| CVE-2016-0728 | The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and… | EXPLOIT ×2HIGH 7.8EPSS 3.44% | 8 February 2016 |
| CVE-2015-7566 | The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by… | EXPLOITMEDIUM 4.6EPSS 1.49% | 8 February 2016 |
| CVE-2016-0801 | The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control… | EXPLOITCRITICAL 9.8EPSS 15.2% | 7 February 2016 |
| CVE-2016-0862 | General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors. | EXPLOIT ✓MEDIUM 6.5EPSS 8.60% | 5 February 2016 |
| CVE-2016-0861 | General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors. | EXPLOIT ✓HIGH 8.8EPSS 11.8% | 5 February 2016 |
| CVE-2016-1721 | The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors. | EXPLOIT ✓HIGH 7.8EPSS 0.92% | 1 February 2016 |
| CVE-2016-1720 | IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors. | EXPLOIT ✓HIGH 7.8EPSS 0.92% | 1 February 2016 |
| CVE-2016-1719 | The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors. | EXPLOIT ×6 ✓HIGH 7.8EPSS 1.07% | 1 February 2016 |
| CVE-2016-1879 | The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a denial of service (assertion failure or NULL pointer… | EXPLOITHIGH 7.5EPSS 11.2% | 29 January 2016 |
| CVE-2015-8770 | Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute… | EXPLOITHIGH 7.5EPSS 26.2% | 29 January 2016 |
| CVE-2016-0492 | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for… | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 92.1% | 21 January 2016 |
| CVE-2016-0491 | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect integrity and availability via unknown vectors related to Load Testing for Web… | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 79.9% | 21 January 2016 |
| CVE-2015-8617 | Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, leading to… | EXPLOITCRITICAL 9.8EPSS 18.3% | 19 January 2016 |
| CVE-2016-1910 | The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290. | EXPLOITMEDIUM 5.3EPSS 6.42% | 15 January 2016 |
| CVE-2016-1909 | Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for… | EXPLOITCRITICAL 9.8EPSS 67.4% | 15 January 2016 |
| CVE-2016-0854 | Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified… | EXPLOIT ✓CRITICAL 9.8EPSS 74.1% | 15 January 2016 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.