SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,801 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 75 of 501

CVESummaryPriorityPublished
CVE-2017-17577FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17576FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17575FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17574FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17573FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17572FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17571FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17570FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17538MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.EXPLOITHIGH 7.5EPSS 7.79%13 December 2017
CVE-2017-11918ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine…EXPLOITHIGH 7.5EPSS 62.6%12 December 2017
CVE-2017-11914ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory…EXPLOITHIGH 7.5EPSS 62.6%12 December 2017
CVE-2017-11911ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption…EXPLOITHIGH 7.5EPSS 65.5%12 December 2017
CVE-2017-11909ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption…EXPLOITHIGH 7.5EPSS 65.5%12 December 2017
CVE-2017-11907Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as…EXPLOITHIGH 7.5EPSS 64.7%12 December 2017
CVE-2017-11906Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to…EXPLOITMEDIUM 5.3EPSS 25.1%12 December 2017
CVE-2017-11903Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as…EXPLOITHIGH 7.5EPSS 46.8%12 December 2017
CVE-2017-11893ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine…EXPLOITHIGH 7.5EPSS 68.5%12 December 2017
CVE-2017-11890Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the…EXPLOITHIGH 7.5EPSS 50.1%12 December 2017
CVE-2017-11885Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow a remote code execution vulnerability due to…EXPLOITMEDIUM 6.6EPSS 45.5%12 December 2017
CVE-2017-5717Type Confusion in Content Protection HECI Service in Intel Graphics Driver allows unprivileged user to elevate privileges via local access.EXPLOITHIGH 7.8EPSS 1.44%12 December 2017
CVE-2017-17562Embedthis GoAhead Remote Code Execution VulnerabilityKEVEXPLOIT ×2HIGH 8.1EPSS 96.3%12 December 2017
CVE-2017-17560This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.EXPLOITCRITICAL 9.8EPSS 73.4%12 December 2017
CVE-2014-8358Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014) use a weak ACL for the "Mobile Partner" directory, which allows remote…EXPLOITHIGH 7.8EPSS 5.02%11 December 2017
CVE-2017-17111Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.EXPLOITCRITICAL 9.8EPSS 8.80%11 December 2017
CVE-2017-17110Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.EXPLOITCRITICAL 9.8EPSS 8.58%11 December 2017
CVE-2017-15944Palo Alto Networks PAN-OS Remote Code Execution VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 98.3%11 December 2017
CVE-2017-11319Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges by leveraging insufficient validation methods and missing cross server side checking mechanisms.EXPLOITHIGH 8.8EPSS 5.56%11 December 2017
CVE-2017-16921In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell…EXPLOITHIGH 8.8EPSS 19.9%8 December 2017
CVE-2017-17055Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.EXPLOITCRITICAL 9.0EPSS 8.71%7 December 2017
CVE-2017-16884Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to failed authentication requests alerts.EXPLOITMEDIUM 6.1EPSS 4.33%7 December 2017
CVE-2017-13156An elevation of privilege vulnerability in the Android system (art).EXPLOITHIGH 7.8EPSS 20.5%6 December 2017
CVE-2017-14355A potential security vulnerability has been identified in HPE Connected Backup versions 8.6 and 8.8.6.EXPLOITHIGH 7.8EPSS 1.64%5 December 2017
CVE-2016-1252The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 allows man-in-the-middle attackers…EXPLOITMEDIUM 5.9EPSS 7.27%5 December 2017
CVE-2017-8824The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.EXPLOITHIGH 7.8EPSS 1.34%5 December 2017
CVE-2017-16930The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler.EXPLOITCRITICAL 9.8EPSS 34.3%5 December 2017
CVE-2017-16929The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by issuing a specially crafted request, allowing a remote attacker to read/write arbitrary files.EXPLOITHIGH 8.1EPSS 12.9%5 December 2017
CVE-2017-15889Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.EXPLOITHIGH 8.8EPSS 73.7%4 December 2017
CVE-2017-17095tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.EXPLOITHIGH 8.8EPSS 10.6%2 December 2017
CVE-2017-17090An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older.EXPLOITHIGH 7.5EPSS 81.5%2 December 2017
CVE-2017-16953connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.EXPLOITHIGH 7.5EPSS 11.3%1 December 2017
CVE-2017-16895The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges via a crafted data packet.EXPLOITHIGH 7.8EPSS 1.02%1 December 2017
CVE-2017-15357The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.EXPLOITHIGH 7.4EPSS 1.16%1 December 2017
CVE-2017-17085In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash.EXPLOITHIGH 7.5EPSS 16.8%1 December 2017
CVE-2017-11282Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser.EXPLOITCRITICAL 9.8EPSS 34.8%1 December 2017
CVE-2017-11281Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function.EXPLOIT ×2CRITICAL 9.8EPSS 33.9%1 December 2017
CVE-2017-1000405Nevertheless, it does allow us to overwrite read-only huge pages.EXPLOIT ×2HIGH 7.0EPSS 2.84%30 November 2017
CVE-2017-13872It allows attackers to obtain administrator access without a password via certain interactions involving entry of the root user name.EXPLOIT ×2HIGH 8.1EPSS 36.8%29 November 2017
CVE-2017-17058The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory.EXPLOITHIGH 7.5EPSS 23.7%29 November 2017
CVE-2017-16952KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.EXPLOITMEDIUM 5.5EPSS 3.23%28 November 2017
CVE-2017-16951Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, or AIF file.EXPLOITMEDIUM 5.5EPSS 3.23%28 November 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.