Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 77 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-16567 | Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. | EXPLOITMEDIUM 5.4EPSS 2.24% | 10 November 2017 |
| CVE-2017-16562 | The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to… | EXPLOITCRITICAL 9.8EPSS 27.4% | 10 November 2017 |
| CVE-2017-16249 | The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. | EXPLOITHIGH 7.5EPSS 59.4% | 10 November 2017 |
| CVE-2017-12969 | Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open… | EXPLOITHIGH 8.8EPSS 10.1% | 10 November 2017 |
| CVE-2017-11309 | Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response. | EXPLOITCRITICAL 9.6EPSS 9.40% | 10 November 2017 |
| CVE-2015-3933 | Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php. | EXPLOITCRITICAL 9.8EPSS 3.76% | 8 November 2017 |
| CVE-2017-16642 | In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the… | EXPLOIT ✓HIGH 7.5EPSS 26.4% | 7 November 2017 |
| CVE-2017-6331 | Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses the real time protection for the application that is run on servers and clients. | EXPLOIT ✓HIGH 7.1EPSS 1.69% | 6 November 2017 |
| CVE-2017-14016 | A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. | EXPLOIT ✓MEDIUM 6.3EPSS 16.0% | 6 November 2017 |
| CVE-2017-16001 | In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges. | EXPLOIT ✓HIGH 7.8EPSS 0.93% | 6 November 2017 |
| CVE-2017-16570 | KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. | EXPLOITHIGH 8.8EPSS 2.21% | 6 November 2017 |
| CVE-2017-16524 | Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrary PHP code via a filename with a .php extension, which… | EXPLOITHIGH 8.8EPSS 30.3% | 6 November 2017 |
| CVE-2017-16543 | Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter. | EXPLOITCRITICAL 9.8EPSS 5.56% | 5 November 2017 |
| CVE-2017-16542 | Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request. | EXPLOITHIGH 8.8EPSS 5.49% | 5 November 2017 |
| CVE-2017-16513 | Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations field, aka WSCLT-1729. | EXPLOIT ✓HIGH 7.8EPSS 2.22% | 3 November 2017 |
| CVE-2017-16237 | In Vir.IT eXplorer Anti-Virus before 8.5.42, the driver file (VIAGLT64.SYS) contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8273007C. | EXPLOITHIGH 7.8EPSS 1.47% | 3 November 2017 |
| CVE-2017-12243 | A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to obtain root shell privileges on… | EXPLOITHIGH 7.8EPSS 77.1% | 2 November 2017 |
| CVE-2017-15918 | This makes privilege escalation trivial and also exposes the user and system keychains to local attacks. | EXPLOITHIGH 7.8EPSS 1.15% | 1 November 2017 |
| CVE-2017-16353 | GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. | EXPLOITMEDIUM 6.5EPSS 13.7% | 1 November 2017 |
| CVE-2017-16352 | GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() function of the magick/describe.c file. | EXPLOITHIGH 8.8EPSS 14.5% | 1 November 2017 |
| CVE-2017-16244 | Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. | EXPLOITHIGH 8.8EPSS 1.98% | 1 November 2017 |
| CVE-2017-15884 | In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges. | EXPLOIT ✓HIGH 7.0EPSS 0.90% | 31 October 2017 |
| CVE-2017-15950 | Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. | EXPLOITHIGH 7.8EPSS 5.51% | 31 October 2017 |
| CVE-2017-15993 | Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15992 | Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15991 | Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability… | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15990 | Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. | EXPLOITCRITICAL 9.8EPSS 7.68% | 31 October 2017 |
| CVE-2017-15989 | Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15988 | Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15987 | Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter. | EXPLOITCRITICAL 9.8EPSS 1.98% | 31 October 2017 |
| CVE-2017-15986 | CPA Lead Reward Script allows SQL Injection via the username parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15985 | Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15984 | Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15983 | MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15982 | Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | EXPLOITCRITICAL 9.8EPSS 2.59% | 31 October 2017 |
| CVE-2017-15981 | Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | EXPLOITCRITICAL 9.8EPSS 2.59% | 31 October 2017 |
| CVE-2017-15980 | US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15979 | Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15978 | AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15977 | Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter. | EXPLOITCRITICAL 9.8EPSS 2.65% | 31 October 2017 |
| CVE-2017-15921 | In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioctl 0x80002010. | EXPLOITHIGH 7.5EPSS 7.58% | 30 October 2017 |
| CVE-2017-15920 | In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioctl 0x80002054. | EXPLOITHIGH 7.5EPSS 7.58% | 30 October 2017 |
| CVE-2017-7411 | The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a preference value that can be arbitrarily manipulated by malicious users through the REST API interface, and this can be exploited to inject… | EXPLOIT ✓HIGH 8.8EPSS 66.6% | 30 October 2017 |
| CVE-2012-5357 | Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data. | EXPLOIT ✓CRITICAL 9.8EPSS 67.8% | 30 October 2017 |
| CVE-2017-15976 | ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604. | EXPLOITCRITICAL 9.8EPSS 3.05% | 29 October 2017 |
| CVE-2017-15975 | Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461. | EXPLOITCRITICAL 9.8EPSS 3.05% | 29 October 2017 |
| CVE-2017-15974 | tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php. | EXPLOITCRITICAL 9.8EPSS 3.70% | 29 October 2017 |
| CVE-2017-15973 | Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php. | EXPLOITCRITICAL 9.8EPSS 2.86% | 29 October 2017 |
| CVE-2017-15972 | SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971. | EXPLOITCRITICAL 9.8EPSS 2.86% | 29 October 2017 |
| CVE-2017-15971 | Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972. | EXPLOITCRITICAL 9.8EPSS 2.03% | 29 October 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.