SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 91 of 501

CVESummaryPriorityPublished
CVE-2015-7568SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.EXPLOITCRITICAL 9.8EPSS 4.06%24 April 2017
CVE-2015-7247D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration backup, which allows remote attackers to obtain…EXPLOITCRITICAL 9.8EPSS 10.2%24 April 2017
CVE-2015-7246D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative access.EXPLOITCRITICAL 9.8EPSS 14.3%24 April 2017
CVE-2015-7245Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a ..EXPLOITHIGH 7.5EPSS 45.5%24 April 2017
CVE-2017-7852D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack.EXPLOITHIGH 8.8EPSS 4.29%24 April 2017
CVE-2015-0107IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7…EXPLOITMEDIUM 6.5EPSS 5.96%24 April 2017
CVE-2015-0104IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7…EXPLOITHIGH 8.8EPSS 6.85%24 April 2017
CVE-2016-5399The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.EXPLOITHIGH 7.8EPSS 9.84%21 April 2017
CVE-2016-1561ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.EXPLOITHIGH 7.5EPSS 74.3%21 April 2017
CVE-2016-1560ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH…EXPLOITCRITICAL 9.8EPSS 72.3%21 April 2017
CVE-2017-8051Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.EXPLOITCRITICAL 9.8EPSS 16.5%21 April 2017
CVE-2016-1555NETGEAR Multiple WAP Devices Command Injection VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 98.3%21 April 2017
CVE-2015-8285The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.EXPLOITHIGH 7.5EPSS 5.47%20 April 2017
CVE-2017-7938Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long argument.EXPLOITMEDIUM 6.6EPSS 4.99%20 April 2017
CVE-2017-7692SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mishandled in a popen call.EXPLOITHIGH 8.8EPSS 32.2%20 April 2017
CVE-2015-8256Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.EXPLOITMEDIUM 6.1EPSS 50.8%17 April 2017
CVE-2017-7615MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.EXPLOIT ×2HIGH 8.8EPSS 90.9%16 April 2017
CVE-2017-7874Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —15 April 2017
CVE-2017-7690Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary with a Trojan horse program.EXPLOITHIGH 7.8EPSS 0.99%14 April 2017
CVE-2017-6554pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACT_NEWFILESENT action.EXPLOITHIGH 7.2EPSS 15.6%14 April 2017
CVE-2016-5312Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a ..EXPLOITMEDIUM 6.5EPSS 53.7%14 April 2017
CVE-2016-5310The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6…EXPLOITMEDIUM 5.5EPSS 5.31%14 April 2017
CVE-2016-5309The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6…EXPLOITMEDIUM 5.5EPSS 6.88%14 April 2017
CVE-2016-1713Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a…EXPLOIT ×2HIGH 7.3EPSS 16.6%14 April 2017
CVE-2016-0727The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 16.04 LTS allows local users with…EXPLOITHIGH 7.8EPSS 1.25%14 April 2017
CVE-2015-6568Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for…EXPLOIT ×2HIGH 8.8EPSS 10.5%14 April 2017
CVE-2015-6567Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly.EXPLOIT ×2HIGH 8.8EPSS 10.8%14 April 2017
CVE-2017-7643Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid program.EXPLOITHIGH 7.8EPSS 0.97%14 April 2017
CVE-2017-7457XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.EXPLOITMEDIUM 5.0EPSS 1.79%14 April 2017
CVE-2017-7456Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.EXPLOITHIGH 7.5EPSS 29.3%14 April 2017
CVE-2017-7455Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.EXPLOITHIGH 7.5EPSS 15.9%14 April 2017
CVE-2015-8356Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) xls_profile parameter to admin/mcart_xls_import.php or the (2) xls_iblock_id, (3)…EXPLOITHIGH 8.0EPSS 2.73%14 April 2017
CVE-2017-7725Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.EXPLOITMEDIUM 6.1EPSS 2.75%13 April 2017
CVE-2016-2555SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.EXPLOITCRITICAL 9.8EPSS 79.6%13 April 2017
CVE-2016-1915Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale parameter to (1) mydevice/index.jsp or (2)…EXPLOITMEDIUM 6.1EPSS 3.95%13 April 2017
CVE-2016-1914Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1)…EXPLOITHIGH 8.8EPSS 4.10%13 April 2017
CVE-2015-8284SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.EXPLOITHIGH 8.8EPSS 4.18%13 April 2017
CVE-2015-8283Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.EXPLOITMEDIUM 6.5EPSS 6.85%13 April 2017
CVE-2015-8282SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.EXPLOITCRITICAL 9.8EPSS 6.58%13 April 2017
CVE-2016-4337SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.EXPLOITCRITICAL 9.8EPSS 2.32%12 April 2017
CVE-2015-7564Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an…EXPLOITCRITICAL 9.8EPSS 3.39%12 April 2017
CVE-2015-7563Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.EXPLOITHIGH 8.8EPSS 3.13%12 April 2017
CVE-2015-7562Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) label value of an item or (2) name of a role.EXPLOITMEDIUM 6.1EPSS 1.83%12 April 2017
CVE-2017-3064Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline.EXPLOITHIGH 7.8EPSS 13.5%12 April 2017
CVE-2017-3061Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser.EXPLOITCRITICAL 9.8EPSS 24.7%12 April 2017
CVE-2017-3006Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creative Cloud desktop applications.EXPLOITHIGH 8.8EPSS 10.8%12 April 2017
CVE-2017-0211An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE…EXPLOITMEDIUM 5.5EPSS 14.0%12 April 2017
CVE-2017-0202A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.EXPLOITHIGH 7.5EPSS 45.6%12 April 2017
CVE-2017-0199Microsoft Office and WordPad Remote Code Execution VulnerabilityKEVEXPLOIT ×3HIGH 7.8EPSS 99.9%12 April 2017
CVE-2017-0167An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Windows kernel improperly handles objects in memory.EXPLOITMEDIUM 5.5EPSS 5.54%12 April 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.