SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 80 of 501

CVESummaryPriorityPublished
CVE-2017-1000253Linux Kernel PIE Stack Buffer Corruption Vulnerability KEVEXPLOITHIGH 7.8EPSS 10.7%5 October 2017
CVE-2017-1000119October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.EXPLOITHIGH 7.2EPSS 61.3%5 October 2017
CVE-2017-1000117A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed.EXPLOITHIGH 8.8EPSS 77.8%5 October 2017
CVE-2017-1000112Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch.EXPLOIT ×3HIGH 7.0EPSS 20.8%5 October 2017
CVE-2017-14491Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.EXPLOITCRITICAL 9.8EPSS 84.9%4 October 2017
CVE-2017-12617Apache Tomcat Remote Code Execution VulnerabilityKEVEXPLOIT ×2HIGH 8.1EPSS 100.0%4 October 2017
CVE-2017-6090Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the…EXPLOIT ×2HIGH 8.8EPSS 96.2%3 October 2017
CVE-2017-6089SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/deletebookmarks.php; or the (3) id…EXPLOITCRITICAL 9.8EPSS 2.95%3 October 2017
CVE-2017-14848WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.EXPLOITHIGH 8.8EPSS 3.03%3 October 2017
CVE-2017-14758OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId.EXPLOITHIGH 8.8EPSS 2.67%3 October 2017
CVE-2017-14757OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId.EXPLOITHIGH 8.8EPSS 1.90%3 October 2017
CVE-2017-14496Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.EXPLOITHIGH 7.5EPSS 66.3%3 October 2017
CVE-2017-14495Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.EXPLOITHIGH 7.5EPSS 84.3%3 October 2017
CVE-2017-14494dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.EXPLOITMEDIUM 5.9EPSS 67.5%3 October 2017
CVE-2017-14493Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.EXPLOITCRITICAL 9.8EPSS 83.6%3 October 2017
CVE-2017-14492Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.EXPLOITCRITICAL 9.8EPSS 93.3%3 October 2017
CVE-2017-11322The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) metacharacter in the argument to chroothole_client.EXPLOITHIGH 8.2EPSS 5.08%3 October 2017
CVE-2017-11321The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metacharacters in the less command.EXPLOITHIGH 7.2EPSS 8.34%3 October 2017
CVE-2015-7358The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over…EXPLOITHIGH 7.8EPSS 1.21%3 October 2017
CVE-2017-14955Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.EXPLOITMEDIUM 5.9EPSS 12.1%2 October 2017
CVE-2017-14939decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calculation, which allows remote attackers to cause a denial of service (heap-based buffer over-read and…EXPLOITMEDIUM 5.5EPSS 5.94%30 September 2017
CVE-2017-14738FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).EXPLOITCRITICAL 9.8EPSS 2.62%30 September 2017
CVE-2017-14702ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserialization.EXPLOITCRITICAL 9.8EPSS 8.30%30 September 2017
CVE-2017-14620SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cross Site Scripting.EXPLOITMEDIUM 6.1EPSS 2.47%30 September 2017
CVE-2017-14507Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2)…EXPLOITCRITICAL 9.8EPSS 5.29%29 September 2017
CVE-2017-14847Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.EXPLOITHIGH 8.8EPSS 2.69%28 September 2017
CVE-2017-14846Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.EXPLOITHIGH 8.8EPSS 2.69%28 September 2017
CVE-2017-14845Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.EXPLOITHIGH 8.8EPSS 2.69%28 September 2017
CVE-2017-14844Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.EXPLOITHIGH 8.8EPSS 2.69%28 September 2017
CVE-2017-14843Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.EXPLOITHIGH 8.8EPSS 2.69%28 September 2017
CVE-2017-14842Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.EXPLOITHIGH 8.8EPSS 2.69%28 September 2017
CVE-2017-14841Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.EXPLOITMEDIUM 6.5EPSS 2.28%28 September 2017
CVE-2017-14840TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.EXPLOITHIGH 8.8EPSS 3.52%28 September 2017
CVE-2017-14839TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.EXPLOITHIGH 8.8EPSS 3.52%28 September 2017
CVE-2017-14838TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.EXPLOITHIGH 8.8EPSS 3.52%28 September 2017
CVE-2017-11120On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an internal buffer overflow in the Wi-Fi firmware, aka B-V2017061204.EXPLOITCRITICAL 9.8EPSS 9.13%28 September 2017
CVE-2015-8249The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.EXPLOITCRITICAL 9.8EPSS 73.6%28 September 2017
CVE-2015-3643usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call…EXPLOITHIGH 7.8EPSS 1.53%28 September 2017
CVE-2015-1336The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.EXPLOITHIGH 7.8EPSS 1.05%28 September 2017
CVE-2017-14704Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then…EXPLOITHIGH 8.8EPSS 8.48%26 September 2017
CVE-2017-13129Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators by leveraging lack of anti-CSRF tokens.EXPLOITHIGH 8.0EPSS 1.08%26 September 2017
CVE-2017-14703SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.EXPLOITCRITICAL 9.8EPSS 2.06%26 September 2017
CVE-2014-0997WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android 4.1.2 as used in the Motorola RAZR HD, and potentially other unspecified Android releases before 5.0.1…EXPLOITHIGH 7.5EPSS 6.40%26 September 2017
CVE-2015-7293Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.EXPLOITHIGH 8.8EPSS 3.04%25 September 2017
CVE-2015-4669The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.EXPLOITHIGH 7.8EPSS 1.05%25 September 2017
CVE-2015-4668Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.EXPLOITMEDIUM 6.1EPSS 6.72%25 September 2017
CVE-2015-4667Multiple hardcoded credentials in Xsuite 2.x.EXPLOITCRITICAL 9.8EPSS 11.1%25 September 2017
CVE-2017-14627Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside…EXPLOIT ×2HIGH 7.8EPSS 19.9%23 September 2017
CVE-2017-14717In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.EXPLOITMEDIUM 5.4EPSS 1.40%22 September 2017
CVE-2017-14712In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.EXPLOITMEDIUM 5.4EPSS 1.40%22 September 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.