Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 92 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-0165 | An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Windows Elevation of Privilege… | EXPLOIT ✓HIGH 7.8EPSS 3.34% | 12 April 2017 |
| CVE-2017-0160 | Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability." | EXPLOIT ✓HIGH 7.8EPSS 17.8% | 12 April 2017 |
| CVE-2017-0058 | A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. | EXPLOIT ✓MEDIUM 4.7EPSS 3.65% | 12 April 2017 |
| CVE-2017-7588 | On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. | EXPLOITCRITICAL 9.8EPSS 33.6% | 12 April 2017 |
| CVE-2015-7893 | SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript. | EXPLOIT ✓HIGH 8.8EPSS 7.38% | 11 April 2017 |
| CVE-2017-6088 | Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to… | EXPLOITHIGH 7.2EPSS 5.83% | 11 April 2017 |
| CVE-2017-7462 | Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory. | EXPLOITCRITICAL 9.8EPSS 13.0% | 11 April 2017 |
| CVE-2017-7461 | Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM.1.6.16.05 allows remote attackers to read arbitrary files via a request to a vendor-supplied CGI script that is used to read HTML… | EXPLOITMEDIUM 4.9EPSS 10.7% | 11 April 2017 |
| CVE-2017-7185 | Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash)… | EXPLOITHIGH 7.5EPSS 12.3% | 10 April 2017 |
| CVE-2017-5607 | Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window… | EXPLOIT ✓LOW 3.5EPSS 5.85% | 10 April 2017 |
| CVE-2017-6190 | Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. | EXPLOITHIGH 7.5EPSS 18.4% | 10 April 2017 |
| CVE-2015-8258 | AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability." | EXPLOITHIGH 7.5EPSS 8.76% | 10 April 2017 |
| CVE-2015-8255 | AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi. | EXPLOITHIGH 8.8EPSS 2.17% | 10 April 2017 |
| CVE-2017-6019 | An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. | EXPLOIT ✓HIGH 7.5EPSS 36.9% | 7 April 2017 |
| CVE-2017-0569 | An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. | EXPLOIT ✓HIGH 7.0EPSS 7.69% | 7 April 2017 |
| CVE-2017-0561 | A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 29.8% | 7 April 2017 |
| CVE-2016-7786 | Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. | EXPLOITHIGH 8.8EPSS 6.98% | 7 April 2017 |
| CVE-2017-7571 | public/rolechangeadmin in Faveo 1.9.3 allows CSRF. | EXPLOIT ✓HIGH 8.0EPSS 2.25% | 6 April 2017 |
| CVE-2017-6884 | Zyxel EMG2926 Routers Command Injection Vulnerability | KEVEXPLOITHIGH 8.8EPSS 34.4% | 6 April 2017 |
| CVE-2017-7237 | The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port… | EXPLOITCRITICAL 9.8EPSS 6.72% | 6 April 2017 |
| CVE-2017-7447 | HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code. | EXPLOITHIGH 8.8EPSS 3.49% | 5 April 2017 |
| CVE-2017-7446 | HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges. | EXPLOITHIGH 8.8EPSS 3.09% | 5 April 2017 |
| CVE-2017-6340 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creating a new report. | EXPLOIT ✓MEDIUM 5.4EPSS 2.46% | 5 April 2017 |
| CVE-2017-6339 | It also allows administrators to upload their own certificates signed by a root CA. | EXPLOIT ✓MEDIUM 6.5EPSS 4.07% | 5 April 2017 |
| CVE-2017-6338 | Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or… | EXPLOIT ✓MEDIUM 6.5EPSS 3.92% | 5 April 2017 |
| CVE-2016-9091 | Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. | EXPLOIT ×2 ✓HIGH 7.2EPSS 10.1% | 5 April 2017 |
| CVE-2017-7358 | In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out. | EXPLOITHIGH 7.3EPSS 2.67% | 5 April 2017 |
| CVE-2017-2671 | The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic)… | EXPLOIT ✓MEDIUM 5.5EPSS 1.46% | 5 April 2017 |
| CVE-2017-7398 | D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. | EXPLOITHIGH 8.8EPSS 3.01% | 4 April 2017 |
| CVE-2017-7228 | The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the caller to drive hypervisor memory accesses outside of the guest provided input/output arrays. | EXPLOIT ✓HIGH 8.2EPSS 1.57% | 4 April 2017 |
| CVE-2017-7397 | BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7). | EXPLOITHIGH 7.5EPSS 11.1% | 3 April 2017 |
| CVE-2017-7402 | Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg. | EXPLOITCRITICAL 9.8EPSS 5.02% | 3 April 2017 |
| CVE-2014-1677 | Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information. | EXPLOITHIGH 7.5EPSS 17.7% | 3 April 2017 |
| CVE-2016-8769 | Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. | EXPLOIT ✓MEDIUM 6.7EPSS 1.58% | 2 April 2017 |
| CVE-2014-3222 | In Huawei eSpace Meeting with software V100R001C03SPC201 and the earlier versions, attackers that obtain the permissions assigned to common users can elevate privileges to access and set specific key resources. | EXPLOITHIGH 7.0EPSS 0.64% | 2 April 2017 |
| CVE-2017-2490 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 4.26% | 2 April 2017 |
| CVE-2017-2489 | It allows attackers to obtain sensitive information from kernel memory via a crafted app. | EXPLOIT ✓MEDIUM 5.5EPSS 2.31% | 2 April 2017 |
| CVE-2017-2483 | A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 5.64% | 2 April 2017 |
| CVE-2017-2482 | A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 5.11% | 2 April 2017 |
| CVE-2017-2480 | It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. | EXPLOIT ✓MEDIUM 6.5EPSS 4.31% | 2 April 2017 |
| CVE-2017-2479 | It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. | EXPLOIT ✓MEDIUM 6.5EPSS 6.33% | 2 April 2017 |
| CVE-2017-2478 | A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app. | EXPLOIT ✓HIGH 7.0EPSS 4.75% | 2 April 2017 |
| CVE-2017-2476 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 6.47% | 2 April 2017 |
| CVE-2017-2474 | An off-by-one error allows attackers to execute arbitrary code in a privileged context via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 4.76% | 2 April 2017 |
| CVE-2017-2473 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 4.71% | 2 April 2017 |
| CVE-2017-2472 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 4.58% | 2 April 2017 |
| CVE-2017-2471 | A use-after-free vulnerability allows remote attackers to execute arbitrary code via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 8.51% | 2 April 2017 |
| CVE-2017-2470 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 6.27% | 2 April 2017 |
| CVE-2017-2469 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 6.27% | 2 April 2017 |
| CVE-2017-2468 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 7.79% | 2 April 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.