Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,801 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 76 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-16994 | The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call. | EXPLOIT ×3 ✓MEDIUM 5.5EPSS 2.08% | 27 November 2017 |
| CVE-2017-16962 | The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities via (1) the location or details field of a Google Calendar invitation, (2) a crafted Outlook.com calendar (aka Hotmail Calendar)… | EXPLOITMEDIUM 6.1EPSS 2.19% | 27 November 2017 |
| CVE-2017-16944 | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character… | EXPLOIT ✓HIGH 7.5EPSS 63.3% | 25 November 2017 |
| CVE-2017-16939 | The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with… | EXPLOITHIGH 7.8EPSS 2.15% | 24 November 2017 |
| CVE-2017-16935 | Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restrictions via a direct request to /plugins/core-ui/servercomm/messages.xml, as demonstrated by changing… | EXPLOITCRITICAL 9.8EPSS 7.66% | 24 November 2017 |
| CVE-2017-16934 | The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a… | EXPLOITCRITICAL 9.8EPSS 13.5% | 24 November 2017 |
| CVE-2015-3934 | Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login. | EXPLOITCRITICAL 9.8EPSS 3.07% | 21 November 2017 |
| CVE-2017-16902 | On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot. | EXPLOITHIGH 7.5EPSS 8.00% | 20 November 2017 |
| CVE-2017-16894 | In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. | EXPLOIT ✓HIGH 7.5EPSS 86.9% | 20 November 2017 |
| CVE-2017-1000170 | jqueryFileTree 2.1.5 and older Directory Traversal | EXPLOITHIGH 7.5EPSS 59.1% | 17 November 2017 |
| CVE-2017-16819 | A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows remote attackers to inject arbitrary JavaScript in the nameFirst (aka First Name) field for the employee details page (/employee.html)… | EXPLOITMEDIUM 5.4EPSS 1.90% | 17 November 2017 |
| CVE-2017-16843 | Vonage VDV-23 115 3.2.11-0.9.40 devices have stored XSS via the NewKeyword or NewDomain field to /goform/RgParentalBasic. | EXPLOITMEDIUM 5.4EPSS 1.49% | 16 November 2017 |
| CVE-2017-16777 | If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and exploit the suid sudo helper in order to escalate to root. | EXPLOIT ✓HIGH 7.8EPSS 0.98% | 16 November 2017 |
| CVE-2017-16841 | LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx. | EXPLOITMEDIUM 6.1EPSS 1.44% | 16 November 2017 |
| CVE-2017-16836 | Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter. | EXPLOITMEDIUM 6.1EPSS 1.99% | 16 November 2017 |
| CVE-2017-15806 | The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted… | EXPLOIT ✓HIGH 8.1EPSS 10.7% | 15 November 2017 |
| CVE-2017-15271 | A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. | EXPLOITMEDIUM 5.9EPSS 8.74% | 15 November 2017 |
| CVE-2017-15270 | This can be used by attackers to hide data in the Graphical User Interface (GUI) view and create arbitrary entries to a certain extent. | EXPLOITMEDIUM 5.3EPSS 6.97% | 15 November 2017 |
| CVE-2017-14961 | In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300000c. | EXPLOITHIGH 7.8EPSS 1.53% | 15 November 2017 |
| CVE-2017-7851 | D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header. | EXPLOITHIGH 8.8EPSS 2.45% | 15 November 2017 |
| CVE-2017-11882 | Microsoft Office Memory Corruption Vulnerability | KEVEXPLOITHIGH 7.8EPSS 99.9% | 15 November 2017 |
| CVE-2017-11873 | ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka… | EXPLOIT ✓HIGH 7.5EPSS 69.8% | 15 November 2017 |
| CVE-2017-11870 | ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory… | EXPLOIT ✓HIGH 7.5EPSS 59.6% | 15 November 2017 |
| CVE-2017-11861 | Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine… | EXPLOIT ✓HIGH 7.5EPSS 64.2% | 15 November 2017 |
| CVE-2017-11855 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an… | EXPLOIT ✓HIGH 7.5EPSS 48.6% | 15 November 2017 |
| CVE-2017-11841 | ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in… | EXPLOIT ✓HIGH 7.5EPSS 59.6% | 15 November 2017 |
| CVE-2017-11840 | ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in… | EXPLOIT ✓HIGH 7.5EPSS 59.6% | 15 November 2017 |
| CVE-2017-11839 | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to take control of an affected system, due to how the scripting engine handles objects in memory, aka "Scripting Engine… | EXPLOIT ✓HIGH 7.5EPSS 62.4% | 15 November 2017 |
| CVE-2017-11831 | Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log on to an… | EXPLOIT ✓MEDIUM 4.7EPSS 3.33% | 15 November 2017 |
| CVE-2017-11830 | Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsigned file appear to be signed, due to a security feature bypass, aka "Device Guard Security Feature… | EXPLOIT ✓MEDIUM 5.3EPSS 2.57% | 15 November 2017 |
| CVE-2017-12636 | This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet. | EXPLOIT ×2 ✓HIGH 7.2EPSS 89.7% | 14 November 2017 |
| CVE-2017-12635 | In combination with CVE-2017-12636 (Remote Code Execution), this can be used to give non-admin users access to arbitrary shell commands on the server as the database system user. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 99.8% | 14 November 2017 |
| CVE-2017-16807 | A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially prepared SVG document that has been uploaded as a content file. | EXPLOIT ✓MEDIUM 5.4EPSS 2.42% | 13 November 2017 |
| CVE-2017-16806 | The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory traversal. | EXPLOITHIGH 7.5EPSS 91.5% | 13 November 2017 |
| CVE-2017-13849 | It allows remote attackers to cause a denial of service (application crash) via a crafted text file. | EXPLOIT ✓MEDIUM 5.5EPSS 3.78% | 13 November 2017 |
| CVE-2017-13802 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 5.79% | 13 November 2017 |
| CVE-2017-13798 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 6.25% | 13 November 2017 |
| CVE-2017-13797 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 5.25% | 13 November 2017 |
| CVE-2017-13796 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 5.82% | 13 November 2017 |
| CVE-2017-13795 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 5.79% | 13 November 2017 |
| CVE-2017-13794 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 6.71% | 13 November 2017 |
| CVE-2017-13792 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 5.79% | 13 November 2017 |
| CVE-2017-13791 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 5.82% | 13 November 2017 |
| CVE-2017-13785 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 5.79% | 13 November 2017 |
| CVE-2017-13784 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 5.79% | 13 November 2017 |
| CVE-2017-13783 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 5.82% | 13 November 2017 |
| CVE-2017-16783 | In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter. | EXPLOITCRITICAL 9.8EPSS 7.97% | 10 November 2017 |
| CVE-2017-16781 | The installer in MyBB before 1.8.13 has XSS. | EXPLOIT ✓MEDIUM 5.4EPSS 1.58% | 10 November 2017 |
| CVE-2017-16780 | The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file. | EXPLOIT ✓CRITICAL 9.8EPSS 5.77% | 10 November 2017 |
| CVE-2017-16568 | Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. | EXPLOITMEDIUM 5.4EPSS 1.98% | 10 November 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.