SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 79 of 501

CVESummaryPriorityPublished
CVE-2017-15359In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters.EXPLOITMEDIUM 6.5EPSS 6.17%18 October 2017
CVE-2017-14956Since there is no anti-CSRF token protecting this functionality, it is vulnerable to Cross-Site Request Forgery attacks.EXPLOITMEDIUM 5.7EPSS 1.86%18 October 2017
CVE-2017-14322The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using the IEM_CookieLogin cookie with a…EXPLOITCRITICAL 9.8EPSS 36.5%18 October 2017
CVE-2015-7715Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to…EXPLOITHIGH 8.8EPSS 3.06%18 October 2017
CVE-2015-7714Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field…EXPLOITHIGH 7.2EPSS 2.19%18 October 2017
CVE-2017-15595An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recursion, stack consumption, and hypervisor crash) or possibly gain privileges via crafted page-table stacking.EXPLOITHIGH 8.8EPSS 1.56%18 October 2017
CVE-2017-15579In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.EXPLOITCRITICAL 9.8EPSS 1.49%18 October 2017
CVE-2017-15578In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.EXPLOITHIGH 8.8EPSS 1.34%18 October 2017
CVE-2014-9118The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.EXPLOITHIGH 8.8EPSS 53.4%17 October 2017
CVE-2014-8357backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter in a getConfig action to…EXPLOITHIGH 8.8EPSS 5.44%17 October 2017
CVE-2017-15221ASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324.EXPLOITHIGH 7.8EPSS 5.46%16 October 2017
CVE-2015-2780Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.EXPLOITCRITICAL 9.8EPSS 15.1%16 October 2017
CVE-2014-9148Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.EXPLOITCRITICAL 9.8EPSS 11.4%16 October 2017
CVE-2014-9147Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.EXPLOITHIGH 7.5EPSS 11.4%16 October 2017
CVE-2017-15374Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules.EXPLOITMEDIUM 6.1EPSS 4.81%16 October 2017
CVE-2017-12629Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class.EXPLOITCRITICAL 9.8EPSS 91.9%14 October 2017
CVE-2017-15276OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server allows uploading content using batches (TAR…EXPLOITHIGH 8.8EPSS 9.49%13 October 2017
CVE-2017-15014OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows authenticated users to download arbitrary content files regardless of the attacker's repository permissions: When an…EXPLOITMEDIUM 4.3EPSS 4.95%13 October 2017
CVE-2017-15013OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server stores information about uploaded files in…EXPLOITHIGH 8.8EPSS 6.64%13 October 2017
CVE-2017-15012OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-command, which allows any authenticated user to hijack an arbitrary file from the Content Server filesystem;…EXPLOITHIGH 8.8EPSS 7.78%13 October 2017
CVE-2017-11823The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Microsoft Windows Security Feature Bypass".EXPLOITMEDIUM 6.7EPSS 2.56%13 October 2017
CVE-2017-11811ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka…EXPLOITHIGH 7.5EPSS 65.5%13 October 2017
CVE-2017-11810Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the…EXPLOITHIGH 7.5EPSS 54.8%13 October 2017
CVE-2017-11809ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka…EXPLOITHIGH 7.5EPSS 68.0%13 October 2017
CVE-2017-11802ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka…EXPLOITHIGH 7.5EPSS 69.2%13 October 2017
CVE-2017-11799ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka…EXPLOITHIGH 7.5EPSS 63.7%13 October 2017
CVE-2017-11793Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the…EXPLOITHIGH 7.5EPSS 49.6%13 October 2017
CVE-2017-11785The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information…EXPLOITMEDIUM 5.5EPSS 3.02%13 October 2017
CVE-2017-15287There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.EXPLOITMEDIUM 6.1EPSS 6.15%12 October 2017
CVE-2017-15284Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile.EXPLOITMEDIUM 5.4EPSS 4.03%12 October 2017
CVE-2017-15083Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —11 October 2017
CVE-2017-15220Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../ substring.EXPLOITCRITICAL 9.8EPSS 7.10%11 October 2017
CVE-2013-6924Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.EXPLOIT ×2CRITICAL 9.8EPSS 15.2%11 October 2017
CVE-2017-15236Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via a crafted request to TCP port 3001, as demonstrated by config* files and extendword.txt.EXPLOITHIGH 7.5EPSS 3.61%11 October 2017
CVE-2017-15235The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact filename.EXPLOITHIGH 7.5EPSS 5.53%11 October 2017
CVE-2017-5637Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests.EXPLOITHIGH 7.5EPSS 73.1%10 October 2017
CVE-2014-0030The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.EXPLOITCRITICAL 9.8EPSS 16.9%10 October 2017
CVE-2015-2147Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.EXPLOITCRITICAL 9.8EPSS 1.59%6 October 2017
CVE-2015-2145Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.EXPLOITMEDIUM 4.8EPSS 1.50%6 October 2017
CVE-2015-2143Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentication of users for requests that cause an unspecified impact via unknown parameters.EXPLOITHIGH 8.8EPSS 1.81%6 October 2017
CVE-2015-2142Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack the authentication of users for requests that cause an unspecified impact via the id parameter to…EXPLOITHIGH 8.0EPSS 1.67%6 October 2017
CVE-2017-15084The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.EXPLOITMEDIUM 6.5EPSS 1.49%6 October 2017
CVE-2017-13068QNAP has already patched this vulnerability.EXPLOITHIGH 7.5EPSS 2.58%6 October 2017
CVE-2017-14089An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues.EXPLOITCRITICAL 9.8EPSS 9.78%6 October 2017
CVE-2017-14087A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.EXPLOITHIGH 7.5EPSS 8.33%6 October 2017
CVE-2017-14086Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable or cause a potential INI corruption, which may cause…EXPLOITHIGH 7.5EPSS 7.91%6 October 2017
CVE-2017-14085Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules.EXPLOITMEDIUM 5.3EPSS 5.65%6 October 2017
CVE-2017-14084A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulnerable installations.EXPLOITHIGH 8.1EPSS 10.1%6 October 2017
CVE-2017-14083A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to download the OfficeScan encryption file.EXPLOITHIGH 7.5EPSS 5.50%6 October 2017
CVE-2017-15035EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).EXPLOITHIGH 7.5EPSS 5.61%5 October 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.