Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 95 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-5359 | EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI. | EXPLOITHIGH 7.5EPSS 7.32% | 15 March 2017 |
| CVE-2017-5358 | Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect API function. | EXPLOITCRITICAL 9.8EPSS 8.57% | 15 March 2017 |
| CVE-2017-6366 | Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to… | EXPLOITHIGH 8.8EPSS 3.31% | 15 March 2017 |
| CVE-2017-6060 | Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. | EXPLOIT ✓HIGH 7.8EPSS 6.80% | 15 March 2017 |
| CVE-2016-8025 | SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain product information via a crafted HTTP request parameter. | EXPLOIT ✓MEDIUM 6.2EPSS 5.66% | 14 March 2017 |
| CVE-2016-8024 | Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to obtain sensitive information via the server HTTP response spoofing. | EXPLOIT ✓HIGH 8.1EPSS 7.29% | 14 March 2017 |
| CVE-2016-8023 | Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to bypass server authentication via a crafted authentication cookie. | EXPLOIT ✓HIGH 8.1EPSS 7.50% | 14 March 2017 |
| CVE-2016-8022 | Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to execute arbitrary code or cause a denial of service via a crafted authentication cookie. | EXPLOIT ✓HIGH 7.5EPSS 13.4% | 14 March 2017 |
| CVE-2016-8021 | Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to spoof update server and execute arbitrary code via a crafted input file. | EXPLOIT ✓MEDIUM 5.0EPSS 4.05% | 14 March 2017 |
| CVE-2016-8020 | Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to execute arbitrary code via a crafted HTTP request parameter. | EXPLOIT ✓HIGH 8.0EPSS 9.00% | 14 March 2017 |
| CVE-2016-8019 | Cross-site scripting (XSS) vulnerability in attributes in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows unauthenticated remote attackers to inject arbitrary web script or HTML via a crafted user input. | EXPLOIT ✓MEDIUM 6.1EPSS 5.22% | 14 March 2017 |
| CVE-2016-8018 | Cross-site request forgery (CSRF) vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to execute unauthorized commands via a crafted user input. | EXPLOIT ✓MEDIUM 4.3EPSS 2.72% | 14 March 2017 |
| CVE-2016-8017 | Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to read files on the webserver via a crafted user input. | EXPLOIT ✓MEDIUM 4.1EPSS 7.34% | 14 March 2017 |
| CVE-2016-8016 | Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to obtain the existence of unauthorized files on the system via a URL parameter. | EXPLOIT ✓LOW 3.4EPSS 5.33% | 14 March 2017 |
| CVE-2017-6896 | Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value. | EXPLOITHIGH 8.8EPSS 2.69% | 14 March 2017 |
| CVE-2017-6516 | A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. | EXPLOIT ✓MEDIUM 6.7EPSS 5.39% | 14 March 2017 |
| CVE-2017-6367 | In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. | EXPLOITHIGH 7.5EPSS 6.53% | 14 March 2017 |
| CVE-2013-4659 | Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. | EXPLOIT ×2CRITICAL 9.8EPSS 10.2% | 14 March 2017 |
| CVE-2017-6823 | Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. | EXPLOITHIGH 8.8EPSS 7.51% | 12 March 2017 |
| CVE-2017-6444 | The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets. | EXPLOITHIGH 7.5EPSS 13.5% | 12 March 2017 |
| CVE-2017-5638 | Apache Struts Remote Code Execution Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 100.0% | 11 March 2017 |
| CVE-2017-6506 | In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. | EXPLOIT ✓CRITICAL 9.8EPSS 7.99% | 10 March 2017 |
| CVE-2017-6427 | A Buffer Overflow was discovered in EvoStream Media Server 1.7.1. | EXPLOITHIGH 7.5EPSS 5.48% | 10 March 2017 |
| CVE-2017-6465 | Remote Code Execution was discovered in FTPShell Client 6.53. | EXPLOIT ✓CRITICAL 9.8EPSS 43.4% | 10 March 2017 |
| CVE-2017-6529 | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID parameter. | EXPLOITHIGH 8.8EPSS 2.36% | 9 March 2017 |
| CVE-2017-6528 | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file). | EXPLOITHIGH 8.1EPSS 2.48% | 9 March 2017 |
| CVE-2017-6527 | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID… | EXPLOITHIGH 7.5EPSS 48.8% | 9 March 2017 |
| CVE-2017-6526 | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected administrative web shell (cgi-bin/dna/sysAdmin.cgi POST requests). | EXPLOITCRITICAL 9.8EPSS 43.2% | 9 March 2017 |
| CVE-2017-6558 | iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the… | EXPLOITCRITICAL 9.8EPSS 9.77% | 9 March 2017 |
| CVE-2017-6552 | An attacker can exploit this issue to render the affected system unresponsive, resulting in a denial-of-service condition for telephone, Internet, and TV services. | EXPLOITHIGH 7.5EPSS 3.70% | 9 March 2017 |
| CVE-2017-6549 | Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P,… | EXPLOITHIGH 8.8EPSS 6.54% | 9 March 2017 |
| CVE-2017-6548 | Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and… | EXPLOITCRITICAL 9.8EPSS 17.1% | 9 March 2017 |
| CVE-2017-6547 | Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750,… | EXPLOITMEDIUM 6.1EPSS 1.95% | 9 March 2017 |
| CVE-2016-6255 | Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler. | EXPLOITHIGH 7.5EPSS 23.4% | 7 March 2017 |
| CVE-2017-6411 | Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password. | EXPLOITHIGH 8.8EPSS 3.02% | 6 March 2017 |
| CVE-2017-5633 | Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted… | EXPLOITHIGH 8.0EPSS 3.94% | 6 March 2017 |
| CVE-2017-6351 | The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. | EXPLOITHIGH 8.1EPSS 4.83% | 6 March 2017 |
| CVE-2017-6334 | NETGEAR DGN2200 Devices OS Command Injection Vulnerability | KEVEXPLOIT ×3 ✓HIGH 8.8EPSS 72.6% | 6 March 2017 |
| CVE-2017-6478 | paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter). | EXPLOITMEDIUM 6.1EPSS 2.57% | 5 March 2017 |
| CVE-2017-6104 | Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0. | EXPLOITHIGH 7.5EPSS 5.74% | 2 March 2017 |
| CVE-2017-0037 | Microsoft Edge and Internet Explorer Type Confusion Vulnerability | KEVEXPLOIT ×3 ✓HIGH 8.1EPSS 80.4% | 26 February 2017 |
| CVE-2016-2226 | Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow. | EXPLOIT ✓HIGH 7.8EPSS 11.8% | 24 February 2017 |
| CVE-2017-6206 | D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Information Disclosure attacks via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 10.8% | 23 February 2017 |
| CVE-2017-6187 | Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request. | EXPLOITCRITICAL 9.8EPSS 26.7% | 22 February 2017 |
| CVE-2017-6077 | NETGEAR DGN2200 Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 68.7% | 22 February 2017 |
| CVE-2017-5586 | OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries. | EXPLOITCRITICAL 9.8EPSS 17.4% | 22 February 2017 |
| CVE-2016-9684 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. | EXPLOITCRITICAL 9.8EPSS 5.24% | 22 February 2017 |
| CVE-2016-9683 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. | EXPLOITCRITICAL 9.8EPSS 9.12% | 22 February 2017 |
| CVE-2016-9682 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. | EXPLOITCRITICAL 9.8EPSS 18.6% | 22 February 2017 |
| CVE-2017-6098 | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. | EXPLOITHIGH 7.2EPSS 3.46% | 21 February 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.