SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,914 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 83 of 501

CVESummaryPriorityPublished
CVE-2017-12953The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted gig file.EXPLOITMEDIUM 6.5EPSS 4.16%28 August 2017
CVE-2017-12952The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.EXPLOITMEDIUM 6.5EPSS 4.18%28 August 2017
CVE-2017-12951The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted gig file.EXPLOITMEDIUM 6.5EPSS 3.07%28 August 2017
CVE-2017-12950The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.EXPLOITMEDIUM 6.5EPSS 5.05%28 August 2017
CVE-2014-9558Multiple SQL injection vulnerabilities in SmartCMS v.2.EXPLOITCRITICAL 9.8EPSS 3.70%28 August 2017
CVE-2014-9312Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.EXPLOITHIGH 8.8EPSS 45.4%28 August 2017
CVE-2014-5301Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.EXPLOITHIGH 8.8EPSS 78.4%28 August 2017
CVE-2017-9650An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code.EXPLOITHIGH 7.8EPSS 2.37%25 August 2017
CVE-2017-9644An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.EXPLOITHIGH 7.0EPSS 1.41%25 August 2017
CVE-2017-9640A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC…EXPLOITMEDIUM 6.3EPSS 8.45%25 August 2017
CVE-2015-4181Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 11.6%25 August 2017
CVE-2015-1325Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS…EXPLOITHIGH 7.0EPSS 0.90%25 August 2017
CVE-2015-8352Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a ..EXPLOITCRITICAL 9.8EPSS 15.6%24 August 2017
CVE-2015-7896LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file.EXPLOITMEDIUM 6.5EPSS 6.96%24 August 2017
CVE-2015-7259ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login to a target account via any of its username and…EXPLOITHIGH 8.8EPSS 9.46%24 August 2017
CVE-2015-7258ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.EXPLOITHIGH 8.8EPSS 12.9%24 August 2017
CVE-2015-7257ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from…EXPLOITHIGH 7.5EPSS 6.71%24 August 2017
CVE-2017-11357Telerik UI for ASP.NET AJAX Insecure Direct Object Reference VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 77.7%23 August 2017
CVE-2017-11317Telerik UI for ASP.NET AJAX Unrestricted File Upload VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 84.2%23 August 2017
CVE-2017-12971Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.EXPLOITMEDIUM 6.1EPSS 2.63%23 August 2017
CVE-2017-12970Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for requests that (1) add or (2) delete user accounts via a request to phpsftpd/users.php.EXPLOITHIGH 8.8EPSS 2.22%23 August 2017
CVE-2017-12965Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.EXPLOITCRITICAL 9.8EPSS 15.7%23 August 2017
CVE-2017-11610The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.EXPLOITHIGH 8.8EPSS 87.4%23 August 2017
CVE-2017-12787A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug…EXPLOITCRITICAL 9.8EPSS 24.6%22 August 2017
CVE-2017-12786Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when…EXPLOITCRITICAL 9.8EPSS 25.3%22 August 2017
CVE-2017-12785The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, is prone to a buffer overflow in the "show log cli" command.EXPLOITCRITICAL 9.8EPSS 16.0%22 August 2017
CVE-2015-2857Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.EXPLOITCRITICAL 9.8EPSS 84.2%22 August 2017
CVE-2017-12984PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.EXPLOITMEDIUM 6.1EPSS 2.24%21 August 2017
CVE-2017-10661Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel…EXPLOITHIGH 7.0EPSS 13.4%19 August 2017
CVE-2015-4071The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}.EXPLOITMEDIUM 5.3EPSS 9.55%18 August 2017
CVE-2015-7945The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2 allows remote attackers to obtain the…EXPLOITHIGH 7.5EPSS 9.36%18 August 2017
CVE-2015-7944The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2, when used in SSL mode, allows remote…EXPLOITHIGH 7.5EPSS 14.2%18 August 2017
CVE-2017-9767Multiple cross-site scripting (XSS) vulnerabilities in Quali CloudShell before 8 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Name or (2) Description parameter to RM/Reservation/ReserveNew; the (3) Description…EXPLOITMEDIUM 5.4EPSS 2.98%18 August 2017
CVE-2017-12943D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, as demonstrated by discovering the admin password.EXPLOITCRITICAL 9.8EPSS 39.2%18 August 2017
CVE-2017-11664The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.EXPLOITMEDIUM 6.5EPSS 8.43%17 August 2017
CVE-2017-11663The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.EXPLOITMEDIUM 6.5EPSS 5.51%17 August 2017
CVE-2017-11662The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.EXPLOITHIGH 7.5EPSS 9.70%17 August 2017
CVE-2017-11661The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.EXPLOITHIGH 7.5EPSS 10.8%17 August 2017
CVE-2017-8665The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege Vulnerability."EXPLOITHIGH 7.8EPSS 4.35%15 August 2017
CVE-2017-6328The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are…EXPLOITHIGH 8.8EPSS 2.14%11 August 2017
CVE-2017-6327Symantec Messaging Gateway Remote Code Execution VulnerabilityKEVEXPLOITHIGH 8.8EPSS 35.9%11 August 2017
CVE-2017-3106Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files.EXPLOITHIGH 8.8EPSS 22.3%11 August 2017
CVE-2015-7894The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers to cause a denial of service (segmentation fault and process crash) and execute arbitrary code via a crafted JPG.EXPLOITHIGH 8.8EPSS 8.85%9 August 2017
CVE-2015-2291Intel Ethernet Diagnostics Driver for Windows Denial-of-Service VulnerabilityKEVEXPLOITHIGH 7.8EPSS 9.01%9 August 2017
CVE-2014-5144Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted markdown.EXPLOITMEDIUM 5.4EPSS 1.99%9 August 2017
CVE-2017-8671Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling…EXPLOITHIGH 7.5EPSS 69.3%8 August 2017
CVE-2017-8670Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in…EXPLOITHIGH 7.5EPSS 68.7%8 August 2017
CVE-2017-8657Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling…EXPLOITHIGH 7.5EPSS 54.6%8 August 2017
CVE-2017-8656Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in…EXPLOITHIGH 7.5EPSS 69.3%8 August 2017
CVE-2017-8652Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability".EXPLOITMEDIUM 6.5EPSS 22.9%8 August 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.