SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 78 of 501

CVESummaryPriorityPublished
CVE-2017-15970PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.EXPLOITCRITICAL 9.8EPSS 2.20%29 October 2017
CVE-2017-15969PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.EXPLOITCRITICAL 9.8EPSS 2.07%29 October 2017
CVE-2017-15968MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.EXPLOITCRITICAL 9.8EPSS 2.07%29 October 2017
CVE-2017-15967Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.EXPLOITCRITICAL 9.8EPSS 2.07%29 October 2017
CVE-2017-15966The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.EXPLOITCRITICAL 9.8EPSS 3.40%29 October 2017
CVE-2017-15965The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.EXPLOITCRITICAL 9.8EPSS 3.40%29 October 2017
CVE-2017-15964Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.EXPLOITCRITICAL 9.8EPSS 2.15%29 October 2017
CVE-2017-15963iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.EXPLOITCRITICAL 9.8EPSS 2.07%29 October 2017
CVE-2017-15962iStock Management System 1.0 allows Arbitrary File Upload via user/profile.EXPLOITCRITICAL 9.8EPSS 4.93%29 October 2017
CVE-2017-15961iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.EXPLOITCRITICAL 9.8EPSS 2.15%29 October 2017
CVE-2017-15960Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.EXPLOITCRITICAL 9.8EPSS 2.15%29 October 2017
CVE-2017-15959Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576.EXPLOITCRITICAL 9.8EPSS 2.07%29 October 2017
CVE-2017-15958D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php.EXPLOITCRITICAL 9.8EPSS 2.15%29 October 2017
CVE-2017-15957my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.EXPLOITHIGH 8.8EPSS 3.95%29 October 2017
CVE-2017-15956ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php.EXPLOITHIGH 7.5EPSS 4.66%29 October 2017
CVE-2014-2023Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2)…EXPLOITCRITICAL 9.8EPSS 4.15%26 October 2017
CVE-2017-15879CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export.EXPLOITHIGH 8.8EPSS 7.22%24 October 2017
CVE-2017-15878A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature.EXPLOITMEDIUM 6.1EPSS 3.42%24 October 2017
CVE-2017-15223Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an infinite loop.EXPLOITMEDIUM 5.3EPSS 4.53%24 October 2017
CVE-2017-15222Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.EXPLOIT ×3CRITICAL 9.8EPSS 60.3%24 October 2017
CVE-2017-15081In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.EXPLOITCRITICAL 9.8EPSS 2.41%24 October 2017
CVE-2017-13772Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to…EXPLOIT ×2HIGH 8.8EPSS 51.4%23 October 2017
CVE-2015-5533SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php.EXPLOITHIGH 7.2EPSS 7.17%23 October 2017
CVE-2015-2878Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name parameter to…EXPLOITHIGH 8.8EPSS 4.17%23 October 2017
CVE-2011-4334edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif extension in the userfile parameter.EXPLOITHIGH 8.8EPSS 5.84%23 October 2017
CVE-2011-4333Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) from parameter to index.php or the (2) page_no parameter to recentchanges.php.EXPLOITMEDIUM 6.1EPSS 2.06%23 October 2017
CVE-2017-15808In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.EXPLOITHIGH 8.8EPSS 1.17%23 October 2017
CVE-2017-15687DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.EXPLOITMEDIUM 6.1EPSS 1.45%23 October 2017
CVE-2017-15580An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.EXPLOITCRITICAL 9.8EPSS 15.6%23 October 2017
CVE-2017-7117It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 10.2%23 October 2017
CVE-2017-7115It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic that leverages a race condition.EXPLOITHIGH 8.1EPSS 7.67%23 October 2017
CVE-2017-7089It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.EXPLOITMEDIUM 6.1EPSS 6.73%23 October 2017
CVE-2017-15735In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.EXPLOITHIGH 8.8EPSS 1.10%22 October 2017
CVE-2017-15734In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.EXPLOITHIGH 8.8EPSS 1.10%22 October 2017
CVE-2017-15730In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.EXPLOITHIGH 8.8EPSS 2.48%22 October 2017
CVE-2017-15727In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.EXPLOITMEDIUM 5.4EPSS 1.80%22 October 2017
CVE-2017-15291Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description field.EXPLOITMEDIUM 6.1EPSS 1.67%20 October 2017
CVE-2017-15649net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that…EXPLOITHIGH 7.8EPSS 0.96%19 October 2017
CVE-2017-15647On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.EXPLOITHIGH 7.5EPSS 26.6%19 October 2017
CVE-2017-15646Webmin before 1.860 has XSS with resultant remote code execution.EXPLOITMEDIUM 6.1EPSS 4.81%19 October 2017
CVE-2017-15645CSRF exists in Webmin 1.850.EXPLOITHIGH 8.8EPSS 3.23%19 October 2017
CVE-2017-15644SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.EXPLOITHIGH 8.6EPSS 8.93%19 October 2017
CVE-2017-15643An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7.EXPLOITHIGH 7.4EPSS 6.39%19 October 2017
CVE-2017-15639tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.EXPLOITMEDIUM 6.5EPSS 6.78%19 October 2017
CVE-2017-10366Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor).EXPLOITCRITICAL 9.8EPSS 43.5%19 October 2017
CVE-2017-10355Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking).EXPLOITMEDIUM 5.3EPSS 16.2%19 October 2017
CVE-2017-10309Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment).EXPLOITHIGH 7.1EPSS 8.79%19 October 2017
CVE-2017-10271Oracle Corporation WebLogic Server Remote Code Execution VulnerabilityKEVEXPLOIT ×3HIGH 7.5EPSS 100.0%19 October 2017
CVE-2017-10033Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools).EXPLOITMEDIUM 4.0EPSS 2.33%19 October 2017
CVE-2017-12579An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.EXPLOITHIGH 7.8EPSS 1.47%19 October 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.