SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 93 of 501

CVESummaryPriorityPublished
CVE-2017-2466It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 6.87%2 April 2017
CVE-2017-2464It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 9.28%2 April 2017
CVE-2017-2460It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 6.79%2 April 2017
CVE-2017-2459It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 6.74%2 April 2017
CVE-2017-2457It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 6.30%2 April 2017
CVE-2017-2456A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.EXPLOITHIGH 7.0EPSS 4.24%2 April 2017
CVE-2017-2455It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 6.77%2 April 2017
CVE-2017-2454It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 6.77%2 April 2017
CVE-2017-2447It allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted web site.EXPLOITHIGH 8.1EPSS 5.14%2 April 2017
CVE-2017-2446It allows remote attackers to execute arbitrary code via a crafted web site that leverages the mishandling of strict mode functions.EXPLOIT ×2HIGH 8.8EPSS 8.26%2 April 2017
CVE-2017-2445It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted frame objects.EXPLOITMEDIUM 6.1EPSS 4.27%2 April 2017
CVE-2017-2443It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.EXPLOITHIGH 7.8EPSS 4.13%2 April 2017
CVE-2017-2442It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.EXPLOITMEDIUM 6.5EPSS 6.17%2 April 2017
CVE-2017-2388It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.EXPLOITMEDIUM 5.5EPSS 3.60%2 April 2017
CVE-2017-2367It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.EXPLOITMEDIUM 6.5EPSS 6.17%2 April 2017
CVE-2015-4624Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.EXPLOITHIGH 7.5EPSS 37.0%31 March 2017
CVE-2017-6412In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.EXPLOITHIGH 8.1EPSS 7.54%30 March 2017
CVE-2017-6182In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.EXPLOITCRITICAL 9.8EPSS 16.7%30 March 2017
CVE-2017-7310A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary…EXPLOIT ×3HIGH 7.8EPSS 53.7%29 March 2017
CVE-2017-7308The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or…EXPLOIT ×3HIGH 7.8EPSS 17.8%29 March 2017
CVE-2017-7285A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP…EXPLOITHIGH 7.5EPSS 19.3%29 March 2017
CVE-2017-5671Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users to conduct a BusyBox jailbreak…EXPLOITHIGH 8.8EPSS 1.40%29 March 2017
CVE-2017-7183The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2) write TFTP protocol message.EXPLOITHIGH 7.5EPSS 5.95%27 March 2017
CVE-2017-6542The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded…EXPLOITCRITICAL 9.8EPSS 21.8%27 March 2017
CVE-2017-5899Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a ..EXPLOITHIGH 7.0EPSS 1.01%27 March 2017
CVE-2017-5850httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Range header.EXPLOITHIGH 7.5EPSS 17.2%27 March 2017
CVE-2015-8309Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."EXPLOITMEDIUM 4.3EPSS 6.72%27 March 2017
CVE-2017-7269Microsoft Windows Server Buffer Overflow VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 99.8%27 March 2017
CVE-2017-2641In Moodle 2.x and 3.x, SQL injection can occur via user preferences.EXPLOITCRITICAL 9.8EPSS 14.5%26 March 2017
CVE-2017-7240The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and is prone to a directory traversal attack; therefore, an unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in…EXPLOITHIGH 7.5EPSS 17.4%24 March 2017
CVE-2017-6087EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in the (1) acknowledge, (2) delete, or (3) ownDisown function in…EXPLOITHIGH 8.8EPSS 7.18%24 March 2017
CVE-2017-5869Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a ..EXPLOITHIGH 8.8EPSS 34.6%24 March 2017
CVE-2015-8556Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.EXPLOITCRITICAL 10.0EPSS 13.4%24 March 2017
CVE-2014-7279The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.EXPLOITCRITICAL 9.8EPSS 11.7%23 March 2017
CVE-2017-6361QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.EXPLOITCRITICAL 9.8EPSS 56.8%23 March 2017
CVE-2017-6360QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.EXPLOITCRITICAL 9.8EPSS 66.1%23 March 2017
CVE-2017-6359QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.EXPLOITCRITICAL 9.8EPSS 26.9%23 March 2017
CVE-2017-6191Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename.EXPLOITHIGH 7.8EPSS 6.68%23 March 2017
CVE-2017-5227QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.EXPLOITHIGH 7.5EPSS 6.44%23 March 2017
CVE-2017-6972AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.EXPLOITCRITICAL 9.8EPSS 14.6%22 March 2017
CVE-2017-6971AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code, aka…EXPLOITHIGH 8.8EPSS 16.2%22 March 2017
CVE-2017-6970AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen socket, aka AlienVault ID ENG-104863.EXPLOITHIGH 8.4EPSS 1.68%22 March 2017
CVE-2016-6816This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response.EXPLOITHIGH 7.1EPSS 39.6%20 March 2017
CVE-2017-6805Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.3EPSS 7.80%20 March 2017
CVE-2017-6803Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin…EXPLOITHIGH 8.8EPSS 4.35%20 March 2017
CVE-2017-6550Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.EXPLOITCRITICAL 9.8EPSS 3.97%20 March 2017
CVE-2017-6178The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference.EXPLOITHIGH 7.8EPSS 1.04%20 March 2017
CVE-2016-8855Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev.EXPLOITMEDIUM 6.1EPSS 2.19%19 March 2017
CVE-2017-7178CSRF was discovered in the web UI in Deluge before 1.3.14.EXPLOITHIGH 8.8EPSS 4.02%18 March 2017
CVE-2017-3881Cisco IOS and IOS XE Remote Code Execution VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 99.0%17 March 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.