Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,801 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 73 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-13878 | It allows local users to bypass intended memory-read restrictions or cause a denial of service (out-of-bounds read and system crash). | EXPLOIT ✓HIGH 7.1EPSS 1.04% | 25 December 2017 |
| CVE-2017-13876 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 5.11% | 25 December 2017 |
| CVE-2017-13875 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 4.43% | 25 December 2017 |
| CVE-2017-13869 | It allows attackers to bypass intended memory-read restrictions via a crafted app. | EXPLOIT ✓MEDIUM 5.5EPSS 4.74% | 25 December 2017 |
| CVE-2017-13868 | It allows attackers to bypass intended memory-read restrictions via a crafted app. | EXPLOITMEDIUM 5.5EPSS 4.71% | 25 December 2017 |
| CVE-2017-13867 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 5.11% | 25 December 2017 |
| CVE-2017-13865 | It allows attackers to bypass intended memory-read restrictions via a crafted app. | EXPLOIT ✓MEDIUM 5.5EPSS 4.25% | 25 December 2017 |
| CVE-2017-13861 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 14.9% | 25 December 2017 |
| CVE-2017-13855 | It allows attackers to bypass intended memory-read restrictions via a crafted app that triggers type confusion. | EXPLOIT ✓MEDIUM 5.5EPSS 4.78% | 25 December 2017 |
| CVE-2017-13847 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 5.03% | 25 December 2017 |
| CVE-2017-17692 | Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property. | EXPLOITHIGH 7.5EPSS 78.8% | 21 December 2017 |
| CVE-2017-17411 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. | EXPLOIT ×2CRITICAL 9.8EPSS 87.9% | 21 December 2017 |
| CVE-2017-5255 | In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell… | EXPLOIT ✓HIGH 8.8EPSS 74.2% | 20 December 2017 |
| CVE-2012-2576 | SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the… | EXPLOIT ✓CRITICAL 9.8EPSS 59.4% | 20 December 2017 |
| CVE-2017-17752 | Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). | EXPLOITMEDIUM 6.1EPSS 1.38% | 20 December 2017 |
| CVE-2017-17761 | The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. | EXPLOITCRITICAL 9.8EPSS 7.50% | 19 December 2017 |
| CVE-2017-17088 | The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. | EXPLOITHIGH 7.5EPSS 6.98% | 19 December 2017 |
| CVE-2017-15049 | The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler. | EXPLOIT ✓HIGH 8.8EPSS 17.0% | 19 December 2017 |
| CVE-2017-15048 | Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler. | EXPLOIT ✓HIGH 8.8EPSS 10.2% | 19 December 2017 |
| CVE-2017-17759 | Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request (which reaches an older version of a West Wind Web… | EXPLOITCRITICAL 9.8EPSS 11.3% | 19 December 2017 |
| CVE-2017-16949 | Improper input sanitization allows the attacker to override the settings for allowed file extensions and upload file size, related to inc/cores/file-uploader.php and file-uploader/file-uploader-class.php. | EXPLOITCRITICAL 9.8EPSS 19.2% | 19 December 2017 |
| CVE-2017-17721 | CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter. | EXPLOITCRITICAL 9.8EPSS 3.60% | 18 December 2017 |
| CVE-2017-17651 | Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 3.05% | 18 December 2017 |
| CVE-2017-17649 | Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter. | EXPLOITMEDIUM 6.1EPSS 2.51% | 18 December 2017 |
| CVE-2017-17645 | Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php. | EXPLOIT ✓CRITICAL 9.8EPSS 3.05% | 18 December 2017 |
| CVE-2017-17643 | FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/. | EXPLOIT ✓CRITICAL 9.8EPSS 2.98% | 18 December 2017 |
| CVE-2017-17739 | The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files. | EXPLOITCRITICAL 9.8EPSS 11.9% | 18 December 2017 |
| CVE-2017-17738 | The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html. | EXPLOITHIGH 7.5EPSS 5.76% | 18 December 2017 |
| CVE-2017-17737 | The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html. | EXPLOITMEDIUM 6.1EPSS 2.08% | 18 December 2017 |
| CVE-2017-3195 | Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges. | EXPLOITCRITICAL 9.8EPSS 21.4% | 16 December 2017 |
| CVE-2017-16787 | The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read arbitrary files by leveraging failure to restrict URL access. | EXPLOITMEDIUM 6.5EPSS 6.62% | 15 December 2017 |
| CVE-2017-17405 | Ruby before 2.4.3 allows Net::FTP command injection. | EXPLOITHIGH 8.8EPSS 73.8% | 15 December 2017 |
| CVE-2017-5264 | Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack. | EXPLOITHIGH 8.8EPSS 2.75% | 14 December 2017 |
| CVE-2017-17672 | In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's… | EXPLOITCRITICAL 9.8EPSS 15.2% | 14 December 2017 |
| CVE-2017-17648 | Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter. | EXPLOITCRITICAL 9.8EPSS 3.80% | 13 December 2017 |
| CVE-2017-17642 | Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job. | EXPLOITCRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17641 | Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17640 | Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter. | EXPLOITCRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17639 | Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17638 | Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17637 | Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17636 | MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17635 | MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter. | EXPLOITCRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17634 | Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17633 | Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17632 | Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17631 | Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17630 | Yoga Class Script 1.0 has SQL Injection via the /list city parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17629 | Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
| CVE-2017-17628 | Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 2.20% | 13 December 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.