Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,801 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 72 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-17867 | Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. | EXPLOITHIGH 8.8EPSS 11.1% | 4 January 2018 |
| CVE-2017-14960 | xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection. | EXPLOITHIGH 7.5EPSS 3.74% | 4 January 2018 |
| CVE-2014-7862 | The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action. | EXPLOITCRITICAL 9.8EPSS 81.0% | 4 January 2018 |
| CVE-2018-0780 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting… | EXPLOIT ✓MEDIUM 5.3EPSS 58.6% | 4 January 2018 |
| CVE-2018-0777 | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory… | EXPLOIT ✓HIGH 7.5EPSS 78.4% | 4 January 2018 |
| CVE-2018-0776 | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory… | EXPLOIT ✓HIGH 7.5EPSS 78.4% | 4 January 2018 |
| CVE-2018-0775 | Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | EXPLOIT ✓HIGH 7.5EPSS 67.9% | 4 January 2018 |
| CVE-2018-0774 | Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | EXPLOIT ✓HIGH 7.5EPSS 67.9% | 4 January 2018 |
| CVE-2018-0770 | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory… | EXPLOIT ✓HIGH 7.5EPSS 78.4% | 4 January 2018 |
| CVE-2018-0769 | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory… | EXPLOIT ✓HIGH 7.5EPSS 79.0% | 4 January 2018 |
| CVE-2018-0767 | Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine… | EXPLOIT ✓MEDIUM 5.3EPSS 65.5% | 4 January 2018 |
| CVE-2018-0758 | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory… | EXPLOIT ✓HIGH 7.5EPSS 80.8% | 4 January 2018 |
| CVE-2018-0752 | The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API… | EXPLOIT ✓HIGH 7.8EPSS 2.77% | 4 January 2018 |
| CVE-2018-0751 | The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API… | EXPLOIT ✓HIGH 7.1EPSS 2.76% | 4 January 2018 |
| CVE-2018-0749 | The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709… | EXPLOIT ✓HIGH 7.8EPSS 3.21% | 4 January 2018 |
| CVE-2018-0748 | The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of… | EXPLOIT ✓HIGH 7.8EPSS 2.77% | 4 January 2018 |
| CVE-2018-0746 | The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are… | EXPLOIT ✓MEDIUM 4.7EPSS 4.08% | 4 January 2018 |
| CVE-2018-0745 | Windows 10 version 1709, and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Information Disclosure Vulnerability". | EXPLOIT ✓MEDIUM 4.7EPSS 2.87% | 4 January 2018 |
| CVE-2018-0744 | The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled… | EXPLOIT ✓HIGH 7.0EPSS 15.0% | 4 January 2018 |
| CVE-2018-0743 | Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Subsystem for Linux Elevation of… | EXPLOIT ✓HIGH 7.0EPSS 2.84% | 4 January 2018 |
| CVE-2017-5753 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | EXPLOITMEDIUM 5.6EPSS 93.8% | 4 January 2018 |
| CVE-2017-5715 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | EXPLOITMEDIUM 5.6EPSS 74.0% | 4 January 2018 |
| CVE-2018-0114 | A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. | EXPLOITHIGH 7.5EPSS 42.7% | 4 January 2018 |
| CVE-2017-8046 | Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code. | EXPLOITCRITICAL 9.8EPSS 74.5% | 4 January 2018 |
| CVE-2017-18019 | In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which in turn can be used to read the… | EXPLOITHIGH 7.1EPSS 1.24% | 4 January 2018 |
| CVE-2017-1000486 | Primetek Primefaces Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 94.1% | 3 January 2018 |
| CVE-2017-1000499 | phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. | EXPLOIT ✓HIGH 8.8EPSS 8.46% | 3 January 2018 |
| CVE-2017-1000432 | Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access | EXPLOIT ✓HIGH 8.0EPSS 1.65% | 2 January 2018 |
| CVE-2017-17098 | The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php… | EXPLOITCRITICAL 9.8EPSS 6.64% | 2 January 2018 |
| CVE-2017-17097 | gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier… | EXPLOITCRITICAL 9.8EPSS 6.95% | 2 January 2018 |
| CVE-2018-3811 | SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. | EXPLOIT ✓CRITICAL 9.8EPSS 42.0% | 1 January 2018 |
| CVE-2018-3810 | Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served… | EXPLOIT ✓CRITICAL 9.8EPSS 91.1% | 1 January 2018 |
| CVE-2017-18001 | Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI. | EXPLOITCRITICAL 9.8EPSS 13.8% | 31 December 2017 |
| CVE-2015-3302 | The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism." | EXPLOITHIGH 7.5EPSS 21.8% | 29 December 2017 |
| CVE-2017-17968 | A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP response. | EXPLOITCRITICAL 9.8EPSS 39.6% | 29 December 2017 |
| CVE-2017-15667 | In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. | EXPLOIT ✓HIGH 7.5EPSS 3.82% | 28 December 2017 |
| CVE-2017-17932 | A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on the victim machine/computer via a long string to TCP… | EXPLOIT ×3CRITICAL 9.8EPSS 53.6% | 28 December 2017 |
| CVE-2015-7889 | The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with… | EXPLOIT ✓MEDIUM 5.5EPSS 2.26% | 28 December 2017 |
| CVE-2017-13056 | The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file. | EXPLOITHIGH 7.8EPSS 5.64% | 27 December 2017 |
| CVE-2016-6914 | Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file. | EXPLOITHIGH 7.8EPSS 1.16% | 27 December 2017 |
| CVE-2017-7154 | It allows local users to bypass intended memory-read restrictions or cause a denial of service (system crash). | EXPLOIT ✓MEDIUM 6.6EPSS 1.13% | 27 December 2017 |
| CVE-2017-17876 | Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter. | EXPLOITHIGH 7.5EPSS 9.54% | 27 December 2017 |
| CVE-2017-17875 | The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action. | EXPLOITCRITICAL 9.8EPSS 2.65% | 27 December 2017 |
| CVE-2017-17874 | Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI. | EXPLOITHIGH 8.8EPSS 6.03% | 27 December 2017 |
| CVE-2017-17873 | Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 27 December 2017 |
| CVE-2017-17872 | The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 27 December 2017 |
| CVE-2017-17871 | The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.65% | 27 December 2017 |
| CVE-2017-17870 | The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action. | EXPLOIT ✓CRITICAL 9.8EPSS 3.00% | 27 December 2017 |
| CVE-2017-17849 | A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response. | EXPLOIT ×2CRITICAL 9.8EPSS 19.0% | 27 December 2017 |
| CVE-2017-16995 | The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect sign extension. | EXPLOIT ×3 ✓HIGH 7.8EPSS 30.1% | 27 December 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.