Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,996 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 109 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2015-5999 | Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password,… | EXPLOITMEDIUM 6.8EPSS 3.21% | 18 November 2015 |
| CVE-2015-4852 | Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability | KEVEXPLOIT ×3 ✓CRITICAL 9.8EPSS 96.0% | 18 November 2015 |
| CVE-2015-7805 | Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file. | EXPLOITHIGH 9.3EPSS 13.3% | 17 November 2015 |
| CVE-2015-5602 | sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt." | EXPLOIT ✓HIGH 7.2EPSS 1.46% | 17 November 2015 |
| CVE-2015-7897 | The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image… | EXPLOIT ✓HIGH 7.5EPSS 7.00% | 16 November 2015 |
| CVE-2015-8046 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before… | EXPLOIT ✓HIGH 10.0EPSS 30.0% | 11 November 2015 |
| CVE-2015-8044 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before… | EXPLOIT ✓HIGH 10.0EPSS 40.7% | 11 November 2015 |
| CVE-2015-8043 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before… | EXPLOIT ✓HIGH 10.0EPSS 29.4% | 11 November 2015 |
| CVE-2015-7652 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before… | EXPLOIT ✓HIGH 9.3EPSS 24.6% | 11 November 2015 |
| CVE-2015-6104 | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to… | EXPLOIT ✓HIGH 9.3EPSS 35.3% | 11 November 2015 |
| CVE-2015-6103 | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to… | EXPLOIT ✓HIGH 9.3EPSS 35.3% | 11 November 2015 |
| CVE-2015-6102 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR… | EXPLOIT ✓LOW 2.1EPSS 4.10% | 11 November 2015 |
| CVE-2015-6101 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a… | EXPLOIT ✓MEDIUM 6.9EPSS 3.11% | 11 November 2015 |
| CVE-2015-6100 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a… | EXPLOIT ✓MEDIUM 6.9EPSS 3.23% | 11 November 2015 |
| CVE-2015-6098 | Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows NDIS… | EXPLOIT ✓HIGH 7.2EPSS 3.98% | 11 November 2015 |
| CVE-2015-6086 | Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." | EXPLOIT ✓MEDIUM 4.3EPSS 25.6% | 11 November 2015 |
| CVE-2015-7254 | Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 27.5% | 7 November 2015 |
| CVE-2015-8038 | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) sharedjobmanager or (2) SOMServiceObjDialog. | EXPLOITMEDIUM 4.3EPSS 2.77% | 2 November 2015 |
| CVE-2015-8037 | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SOMVpnSSLPortalDialog or (2) FGDMngUpdHistory. | EXPLOITMEDIUM 4.3EPSS 2.77% | 2 November 2015 |
| CVE-2015-5534 | Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the authentication of administrators for requests that (1) put the website under maintenance via the maintenance_enable parameter or (2)… | EXPLOITMEDIUM 6.8EPSS 2.33% | 2 November 2015 |
| CVE-2015-7858 | SQL injection vulnerability in Joomla! | EXPLOIT ✓HIGH 7.5EPSS 85.6% | 29 October 2015 |
| CVE-2015-7857 | SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! | EXPLOIT ✓HIGH 7.5EPSS 94.5% | 29 October 2015 |
| CVE-2015-7297 | SQL injection vulnerability in Joomla! | EXPLOIT ✓HIGH 7.5EPSS 100.0% | 29 October 2015 |
| CVE-2015-5285 | CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from parameter to _admin/login. | EXPLOITMEDIUM 5.0EPSS 6.09% | 29 October 2015 |
| CVE-2015-7904 | Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP code via vectors involving an upload of an image file. | EXPLOITMEDIUM 6.5EPSS 2.78% | 28 October 2015 |
| CVE-2015-7903 | SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | EXPLOITMEDIUM 6.5EPSS 1.29% | 28 October 2015 |
| CVE-2015-7902 | Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in unspecified circumstances, which allows remote attackers to obtain sensitive information via a series of requests. | EXPLOITMEDIUM 5.0EPSS 3.50% | 28 October 2015 |
| CVE-2015-7901 | Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors. | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 3.26% | 28 October 2015 |
| CVE-2015-7900 | Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive debugging information by entering a crafted URL to trigger an exception, and then visiting a certain status page. | EXPLOITMEDIUM 4.3EPSS 2.95% | 28 October 2015 |
| CVE-2015-6494 | Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | EXPLOITLOW 3.5EPSS 1.75% | 28 October 2015 |
| CVE-2015-6493 | Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | EXPLOITMEDIUM 6.8EPSS 1.32% | 28 October 2015 |
| CVE-2015-7986 | The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTTP request, aka SAP Security Note 2197428. | EXPLOITHIGH 7.5EPSS 6.24% | 27 October 2015 |
| CVE-2015-7007 | Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript execution via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 53.3% | 23 October 2015 |
| CVE-2015-6996 | IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓MEDIUM 6.8EPSS 6.70% | 23 October 2015 |
| CVE-2015-6995 | The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓MEDIUM 6.8EPSS 6.49% | 23 October 2015 |
| CVE-2015-4878 | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than… | EXPLOITLOW 1.5EPSS 0.93% | 21 October 2015 |
| CVE-2015-4877 | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than… | EXPLOITLOW 1.5EPSS 0.91% | 21 October 2015 |
| CVE-2015-4870 | Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser. | EXPLOITMEDIUM 4.0EPSS 30.1% | 21 October 2015 |
| CVE-2015-7648 | Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-7647. | EXPLOIT ✓HIGH 10.0EPSS 29.5% | 18 October 2015 |
| CVE-2015-7647 | Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-7648. | EXPLOIT ✓HIGH 10.0EPSS 29.5% | 18 October 2015 |
| CVE-2015-7645 | Adobe Flash Player Arbitrary Code Execution Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 65.3% | 15 October 2015 |
| CVE-2015-6763 | Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | EXPLOIT ✓HIGH 7.5EPSS 6.97% | 15 October 2015 |
| CVE-2015-7622 | Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to execute… | EXPLOITHIGH 10.0EPSS 23.4% | 14 October 2015 |
| CVE-2015-2554 | The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Object Reference Elevation of Privilege Vulnerability." | EXPLOIT ✓HIGH 7.2EPSS 3.55% | 14 October 2015 |
| CVE-2015-2553 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles junctions during mountpoint creation, which makes… | EXPLOIT ✓HIGH 7.2EPSS 3.26% | 14 October 2015 |
| CVE-2015-2482 | The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | EXPLOIT ✓HIGH 9.3EPSS 32.3% | 14 October 2015 |
| CVE-2015-2342 | The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol. | EXPLOIT ✓HIGH 10.0EPSS 89.0% | 12 October 2015 |
| CVE-2015-7768 | Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD command. | EXPLOIT ×2 ✓HIGH 7.5EPSS 63.2% | 9 October 2015 |
| CVE-2015-7767 | Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long USER command. | EXPLOIT ×2 ✓HIGH 7.5EPSS 4.73% | 9 October 2015 |
| CVE-2015-7766 | PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT/**/INTO." | EXPLOIT ✓HIGH 9.0EPSS 80.6% | 9 October 2015 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.