SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 96 of 501

CVESummaryPriorityPublished
CVE-2017-6097A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress.EXPLOITHIGH 7.2EPSS 3.49%21 February 2017
CVE-2017-6096A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress.EXPLOITHIGH 7.2EPSS 3.49%21 February 2017
CVE-2017-6095A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress.EXPLOITCRITICAL 9.8EPSS 3.90%21 February 2017
CVE-2017-5881GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file.EXPLOITHIGH 7.8EPSS 8.43%21 February 2017
CVE-2016-9316Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote…EXPLOITMEDIUM 5.4EPSS 3.55%21 February 2017
CVE-2016-9315Privilege Escalation Vulnerability in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least…EXPLOITHIGH 8.8EPSS 7.15%21 February 2017
CVE-2016-9314Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to backup…EXPLOITHIGH 7.8EPSS 3.65%21 February 2017
CVE-2016-9269Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to run arbitrary…EXPLOITCRITICAL 9.9EPSS 11.2%21 February 2017
CVE-2017-0038gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to…EXPLOITMEDIUM 5.5EPSS 71.9%20 February 2017
CVE-2017-2373It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 7.09%20 February 2017
CVE-2017-2371The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site.EXPLOITMEDIUM 6.5EPSS 5.77%20 February 2017
CVE-2017-2370It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted app.EXPLOITHIGH 7.8EPSS 19.2%20 February 2017
CVE-2017-2369It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 7.15%20 February 2017
CVE-2017-2365It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.EXPLOITMEDIUM 6.5EPSS 6.70%20 February 2017
CVE-2017-2364It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.EXPLOITMEDIUM 6.5EPSS 6.33%20 February 2017
CVE-2017-2363It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.EXPLOITMEDIUM 6.5EPSS 6.62%20 February 2017
CVE-2017-2362It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 6.87%20 February 2017
CVE-2017-2361The issue involves the "Help Viewer" component, which allows XSS attacks via a crafted web site.EXPLOITMEDIUM 6.1EPSS 11.0%20 February 2017
CVE-2017-2360It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.EXPLOITHIGH 7.8EPSS 8.59%20 February 2017
CVE-2017-2353It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.EXPLOITHIGH 7.8EPSS 6.39%20 February 2017
CVE-2016-7661It allows local users to gain privileges via unspecified vectors related to Mach port name references.EXPLOIT ×2HIGH 7.8EPSS 1.12%20 February 2017
CVE-2016-7660It allows local users to gain privileges via unspecified vectors related to Mach port name references.EXPLOITHIGH 7.8EPSS 1.08%20 February 2017
CVE-2016-7644It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.EXPLOITHIGH 7.8EPSS 14.7%20 February 2017
CVE-2016-7637It allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.EXPLOIT ×2HIGH 7.8EPSS 1.06%20 February 2017
CVE-2016-7633It allows local users to gain privileges or cause a denial of service (use-after-free) via unspecified vectors.EXPLOITHIGH 7.8EPSS 1.15%20 February 2017
CVE-2016-7626It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted certificate profile.EXPLOITHIGH 8.8EPSS 6.13%20 February 2017
CVE-2016-7621It allows local users to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via unspecified vectors.EXPLOITHIGH 7.8EPSS 1.32%20 February 2017
CVE-2016-7617It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (type confusion) via a crafted app.EXPLOIT ×2HIGH 7.8EPSS 9.35%20 February 2017
CVE-2016-7612It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.EXPLOITHIGH 7.8EPSS 8.24%20 February 2017
CVE-2016-7608The issue involves the "IOFireWireFamily" component, which allows local users to obtain sensitive information from kernel memory via unspecified vectors.EXPLOITMEDIUM 5.5EPSS 1.08%20 February 2017
CVE-2016-4669It allows local users to execute arbitrary code in a privileged context or cause a denial of service (MIG code mishandling and system crash) via unspecified vectors.EXPLOITHIGH 7.8EPSS 3.50%20 February 2017
CVE-2017-6074The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double…EXPLOIT ×2HIGH 7.8EPSS 5.96%18 February 2017
CVE-2017-5344The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution.EXPLOITCRITICAL 9.8EPSS 4.52%17 February 2017
CVE-2016-4316Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to…EXPLOITMEDIUM 6.1EPSS 4.23%17 February 2017
CVE-2016-4315Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.EXPLOITMEDIUM 5.7EPSS 2.78%17 February 2017
CVE-2016-4314Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a ..EXPLOITMEDIUM 4.9EPSS 10.6%17 February 2017
CVE-2016-4312XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files, cause a denial of service,…EXPLOITHIGH 7.5EPSS 5.54%17 February 2017
CVE-2016-4311Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an…EXPLOITHIGH 8.8EPSS 3.19%17 February 2017
CVE-2017-0313All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of…EXPLOITHIGH 7.8EPSS 1.30%15 February 2017
CVE-2017-0312All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscapeID 0x100008b where user provided input is used as the limit for a loop may lead to denial of service or potential…EXPLOITHIGH 7.8EPSS 1.24%15 February 2017
CVE-2016-8972IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client.EXPLOITHIGH 7.8EPSS 1.38%15 February 2017
CVE-2016-6079IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.EXPLOITHIGH 7.8EPSS 2.39%15 February 2017
CVE-2016-3694Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote attackers to execute arbitrary SQL commands via the (1) orders_status or (2) customers_status…EXPLOITCRITICAL 9.8EPSS 3.05%15 February 2017
CVE-2017-5991An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465.EXPLOITHIGH 7.5EPSS 15.2%15 February 2017
CVE-2017-2992Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header.EXPLOITHIGH 8.8EPSS 32.7%15 February 2017
CVE-2017-2988Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing garbage collection.EXPLOITHIGH 8.8EPSS 18.1%15 February 2017
CVE-2017-2986Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (FLV) codec.EXPLOITHIGH 8.8EPSS 30.9%15 February 2017
CVE-2017-2985Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class.EXPLOITHIGH 8.8EPSS 21.8%15 February 2017
CVE-2017-5972The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets,…EXPLOITHIGH 7.5EPSS 23.9%14 February 2017
CVE-2016-9351The directory traversal/file upload error allows an attacker to upload and unpack a zip file.EXPLOITHIGH 7.0EPSS 4.18%13 February 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.