Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,739 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 71 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-14097 | An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decrypt contents of a database with information that could be used to access a vulnerable system. | EXPLOITCRITICAL 9.8EPSS 12.7% | 19 January 2018 |
| CVE-2017-14096 | A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to execute a malicious payload on vulnerable systems. | EXPLOITMEDIUM 6.1EPSS 3.04% | 19 January 2018 |
| CVE-2017-14095 | A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system. | EXPLOITHIGH 8.1EPSS 12.5% | 19 January 2018 |
| CVE-2017-14094 | A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system. | EXPLOITCRITICAL 9.8EPSS 19.4% | 19 January 2018 |
| CVE-2017-11398 | A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable… | EXPLOITHIGH 8.8EPSS 8.20% | 19 January 2018 |
| CVE-2012-6708 | jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. | EXPLOITMEDIUM 6.1EPSS 8.63% | 18 January 2018 |
| CVE-2014-2017 | CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject… | EXPLOITMEDIUM 6.1EPSS 2.40% | 18 January 2018 |
| CVE-2018-2698 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). | EXPLOITHIGH 8.8EPSS 1.66% | 18 January 2018 |
| CVE-2018-2636 | Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security). | EXPLOIT ✓HIGH 8.1EPSS 15.1% | 18 January 2018 |
| CVE-2017-10273 | Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). | EXPLOIT ✓MEDIUM 4.7EPSS 1.45% | 18 January 2018 |
| CVE-2018-5726 | MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by the username, password, and configuration settings. | EXPLOITCRITICAL 9.8EPSS 19.8% | 16 January 2018 |
| CVE-2018-5725 | MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server. | EXPLOITHIGH 7.5EPSS 4.63% | 16 January 2018 |
| CVE-2018-5724 | MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi. | EXPLOITCRITICAL 9.8EPSS 11.5% | 16 January 2018 |
| CVE-2018-5723 | MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account. | EXPLOITCRITICAL 9.8EPSS 9.73% | 16 January 2018 |
| CVE-2018-5715 | phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable). | EXPLOITMEDIUM 6.1EPSS 6.91% | 16 January 2018 |
| CVE-2018-5370 | BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI. | EXPLOITMEDIUM 6.1EPSS 2.19% | 16 January 2018 |
| CVE-2018-5702 | Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests… | EXPLOIT ✓HIGH 8.8EPSS 11.9% | 15 January 2018 |
| CVE-2018-5479 | FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. | EXPLOITMEDIUM 6.1EPSS 2.07% | 15 January 2018 |
| CVE-2018-5688 | ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component. | EXPLOIT ✓MEDIUM 6.1EPSS 3.28% | 14 January 2018 |
| CVE-2017-13216 | In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. | EXPLOIT ✓HIGH 7.8EPSS 0.95% | 12 January 2018 |
| CVE-2017-13209 | In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. | EXPLOIT ✓HIGH 7.8EPSS 0.75% | 12 January 2018 |
| CVE-2018-5315 | The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. | EXPLOITCRITICAL 9.8EPSS 4.87% | 12 January 2018 |
| CVE-2018-5262 | A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account. | EXPLOITCRITICAL 9.8EPSS 39.1% | 12 January 2018 |
| CVE-2017-17970 | Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php; the (2) season_id parameter to themes/flixer/ajax/load_season.php; the (3) movie_id parameter to… | EXPLOITCRITICAL 9.8EPSS 5.41% | 12 January 2018 |
| CVE-2017-16887 | Unauthorized Access to Web Services can result in disclosure of the WLAN key/password. | EXPLOITCRITICAL 9.8EPSS 36.6% | 12 January 2018 |
| CVE-2017-16886 | Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal. | EXPLOITHIGH 8.8EPSS 7.11% | 12 January 2018 |
| CVE-2017-16885 | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. | EXPLOITCRITICAL 9.8EPSS 33.5% | 12 January 2018 |
| CVE-2014-6437 | Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors involving the ROM file. | EXPLOIT ✓CRITICAL 9.8EPSS 15.5% | 12 January 2018 |
| CVE-2014-6436 | Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an… | EXPLOIT ✓CRITICAL 9.8EPSS 42.1% | 12 January 2018 |
| CVE-2014-6435 | cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers to cause a denial of service (WAN connectivity reset) via a direct request. | EXPLOIT ✓HIGH 7.5EPSS 12.6% | 12 January 2018 |
| CVE-2018-5347 | Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled. | EXPLOITCRITICAL 9.8EPSS 54.2% | 12 January 2018 |
| CVE-2012-0699 | Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an add action to familynews.php or… | EXPLOIT ×2 ✓HIGH 8.8EPSS 3.57% | 11 January 2018 |
| CVE-2018-5189 | Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain system privileges by flipping pool buffer size, aka a "double fetch" vulnerability. | EXPLOITHIGH 7.8EPSS 1.20% | 11 January 2018 |
| CVE-2017-18016 | Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy engine (reusing the current website's token, which is not bound to an… | EXPLOITMEDIUM 5.3EPSS 5.48% | 11 January 2018 |
| CVE-2012-6667 | Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action. | EXPLOIT ✓MEDIUM 6.1EPSS 4.16% | 11 January 2018 |
| CVE-2018-5333 | In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference. | EXPLOIT ✓MEDIUM 5.5EPSS 7.21% | 11 January 2018 |
| CVE-2017-15665 | In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. | EXPLOITHIGH 7.5EPSS 9.14% | 10 January 2018 |
| CVE-2017-15664 | In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. | EXPLOITHIGH 7.5EPSS 9.14% | 10 January 2018 |
| CVE-2017-15663 | In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. | EXPLOIT ×2HIGH 7.5EPSS 13.2% | 10 January 2018 |
| CVE-2017-15662 | In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. | EXPLOIT ✓HIGH 7.5EPSS 9.14% | 10 January 2018 |
| CVE-2016-9722 | IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. | EXPLOIT ✓MEDIUM 4.2EPSS 12.0% | 10 January 2018 |
| CVE-2018-5211 | PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist. | EXPLOITCRITICAL 9.8EPSS 1.93% | 9 January 2018 |
| CVE-2018-5263 | The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS. | EXPLOIT ✓MEDIUM 5.4EPSS 1.58% | 8 January 2018 |
| CVE-2017-7997 | Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter to webapp/users/prnow.jsp or show_month parameter to (2) webapp/users/blhistory.jsp or (3)… | EXPLOITCRITICAL 9.8EPSS 19.3% | 8 January 2018 |
| CVE-2014-7222 | Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab with… | EXPLOIT ✓MEDIUM 6.5EPSS 11.0% | 8 January 2018 |
| CVE-2014-7221 | TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab… | EXPLOIT ✓MEDIUM 6.5EPSS 11.0% | 8 January 2018 |
| CVE-2018-5282 | Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML document. | EXPLOITHIGH 7.8EPSS 1.55% | 8 January 2018 |
| CVE-2017-16666 | Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. | EXPLOIT ✓HIGH 8.8EPSS 80.8% | 5 January 2018 |
| CVE-2017-16720 | A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. | EXPLOIT ✓CRITICAL 9.8EPSS 50.3% | 5 January 2018 |
| CVE-2017-16716 | A SQL Injection issue was discovered in WebAccess versions prior to 8.3. | EXPLOITCRITICAL 9.8EPSS 6.01% | 5 January 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.