Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 78 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-15970 | PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter. | EXPLOITCRITICAL 9.8EPSS 2.20% | 29 October 2017 |
| CVE-2017-15969 | PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category. | EXPLOITCRITICAL 9.8EPSS 2.07% | 29 October 2017 |
| CVE-2017-15968 | MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter. | EXPLOITCRITICAL 9.8EPSS 2.07% | 29 October 2017 |
| CVE-2017-15967 | Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template. | EXPLOITCRITICAL 9.8EPSS 2.07% | 29 October 2017 |
| CVE-2017-15966 | The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php. | EXPLOITCRITICAL 9.8EPSS 3.40% | 29 October 2017 |
| CVE-2017-15965 | The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action. | EXPLOITCRITICAL 9.8EPSS 3.40% | 29 October 2017 |
| CVE-2017-15964 | Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI. | EXPLOITCRITICAL 9.8EPSS 2.15% | 29 October 2017 |
| CVE-2017-15963 | iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter. | EXPLOITCRITICAL 9.8EPSS 2.07% | 29 October 2017 |
| CVE-2017-15962 | iStock Management System 1.0 allows Arbitrary File Upload via user/profile. | EXPLOITCRITICAL 9.8EPSS 4.93% | 29 October 2017 |
| CVE-2017-15961 | iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php. | EXPLOITCRITICAL 9.8EPSS 2.15% | 29 October 2017 |
| CVE-2017-15960 | Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php. | EXPLOITCRITICAL 9.8EPSS 2.15% | 29 October 2017 |
| CVE-2017-15959 | Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576. | EXPLOITCRITICAL 9.8EPSS 2.07% | 29 October 2017 |
| CVE-2017-15958 | D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php. | EXPLOITCRITICAL 9.8EPSS 2.15% | 29 October 2017 |
| CVE-2017-15957 | my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file. | EXPLOITHIGH 8.8EPSS 3.95% | 29 October 2017 |
| CVE-2017-15956 | ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php. | EXPLOITHIGH 7.5EPSS 4.66% | 29 October 2017 |
| CVE-2014-2023 | Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2)… | EXPLOITCRITICAL 9.8EPSS 4.15% | 26 October 2017 |
| CVE-2017-15879 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export. | EXPLOITHIGH 8.8EPSS 7.22% | 24 October 2017 |
| CVE-2017-15878 | A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature. | EXPLOITMEDIUM 6.1EPSS 3.42% | 24 October 2017 |
| CVE-2017-15223 | Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an infinite loop. | EXPLOITMEDIUM 5.3EPSS 4.53% | 24 October 2017 |
| CVE-2017-15222 | Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code. | EXPLOIT ×3 ✓CRITICAL 9.8EPSS 60.3% | 24 October 2017 |
| CVE-2017-15081 | In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php. | EXPLOITCRITICAL 9.8EPSS 2.41% | 24 October 2017 |
| CVE-2017-13772 | Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to… | EXPLOIT ×2HIGH 8.8EPSS 51.4% | 23 October 2017 |
| CVE-2015-5533 | SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. | EXPLOITHIGH 7.2EPSS 7.17% | 23 October 2017 |
| CVE-2015-2878 | Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name parameter to… | EXPLOITHIGH 8.8EPSS 4.17% | 23 October 2017 |
| CVE-2011-4334 | edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif extension in the userfile parameter. | EXPLOIT ✓HIGH 8.8EPSS 5.84% | 23 October 2017 |
| CVE-2011-4333 | Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) from parameter to index.php or the (2) page_no parameter to recentchanges.php. | EXPLOIT ✓MEDIUM 6.1EPSS 2.06% | 23 October 2017 |
| CVE-2017-15808 | In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php. | EXPLOITHIGH 8.8EPSS 1.17% | 23 October 2017 |
| CVE-2017-15687 | DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI. | EXPLOITMEDIUM 6.1EPSS 1.45% | 23 October 2017 |
| CVE-2017-15580 | An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content. | EXPLOITCRITICAL 9.8EPSS 15.6% | 23 October 2017 |
| CVE-2017-7117 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 10.2% | 23 October 2017 |
| CVE-2017-7115 | It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic that leverages a race condition. | EXPLOIT ✓HIGH 8.1EPSS 7.67% | 23 October 2017 |
| CVE-2017-7089 | It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing. | EXPLOITMEDIUM 6.1EPSS 6.73% | 23 October 2017 |
| CVE-2017-15735 | In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary. | EXPLOITHIGH 8.8EPSS 1.10% | 22 October 2017 |
| CVE-2017-15734 | In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php. | EXPLOITHIGH 8.8EPSS 1.10% | 22 October 2017 |
| CVE-2017-15730 | In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php. | EXPLOITHIGH 8.8EPSS 2.48% | 22 October 2017 |
| CVE-2017-15727 | In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment. | EXPLOITMEDIUM 5.4EPSS 1.80% | 22 October 2017 |
| CVE-2017-15291 | Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description field. | EXPLOITMEDIUM 6.1EPSS 1.67% | 20 October 2017 |
| CVE-2017-15649 | net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that… | EXPLOITHIGH 7.8EPSS 0.96% | 19 October 2017 |
| CVE-2017-15647 | On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value. | EXPLOITHIGH 7.5EPSS 26.6% | 19 October 2017 |
| CVE-2017-15646 | Webmin before 1.860 has XSS with resultant remote code execution. | EXPLOITMEDIUM 6.1EPSS 4.81% | 19 October 2017 |
| CVE-2017-15645 | CSRF exists in Webmin 1.850. | EXPLOITHIGH 8.8EPSS 3.23% | 19 October 2017 |
| CVE-2017-15644 | SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000. | EXPLOITHIGH 8.6EPSS 8.93% | 19 October 2017 |
| CVE-2017-15643 | An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. | EXPLOITHIGH 7.4EPSS 6.39% | 19 October 2017 |
| CVE-2017-15639 | tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature. | EXPLOITMEDIUM 6.5EPSS 6.78% | 19 October 2017 |
| CVE-2017-10366 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). | EXPLOITCRITICAL 9.8EPSS 43.5% | 19 October 2017 |
| CVE-2017-10355 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). | EXPLOITMEDIUM 5.3EPSS 16.2% | 19 October 2017 |
| CVE-2017-10309 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). | EXPLOIT ✓HIGH 7.1EPSS 8.79% | 19 October 2017 |
| CVE-2017-10271 | Oracle Corporation WebLogic Server Remote Code Execution Vulnerability | KEVEXPLOIT ×3 ✓HIGH 7.5EPSS 100.0% | 19 October 2017 |
| CVE-2017-10033 | Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). | EXPLOITMEDIUM 4.0EPSS 2.33% | 19 October 2017 |
| CVE-2017-12579 | An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell. | EXPLOIT ✓HIGH 7.8EPSS 1.47% | 19 October 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.