Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 97 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2016-9349 | An attacker could traverse the file system and extract files that can result in information disclosure. | EXPLOIT ×2HIGH 7.5EPSS 6.07% | 13 February 2017 |
| CVE-2016-9332 | An attacker could provide unexpected values and cause the program to crash or excessive consumption of resources could result in a denial-of-service condition. | EXPLOITHIGH 7.5EPSS 6.40% | 13 February 2017 |
| CVE-2016-8377 | A stack-based buffer overflow vulnerability exists when the software application connects to a malicious server, resulting in a stack buffer overflow. | EXPLOITHIGH 8.0EPSS 8.91% | 13 February 2017 |
| CVE-2016-5809 | There is no CSRF Token generated to authenticate the user during a session. | EXPLOITHIGH 8.8EPSS 1.88% | 13 February 2017 |
| CVE-2016-6210 | sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference… | EXPLOIT ×2MEDIUM 5.9EPSS 88.6% | 13 February 2017 |
| CVE-2017-5941 | Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE). | EXPLOIT ×3CRITICAL 9.8EPSS 61.0% | 9 February 2017 |
| CVE-2017-5180 | Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors… | EXPLOITHIGH 8.8EPSS 0.80% | 9 February 2017 |
| CVE-2017-3813 | A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user. | EXPLOITHIGH 7.8EPSS 1.83% | 9 February 2017 |
| CVE-2017-3807 | A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow. | EXPLOIT ✓HIGH 8.8EPSS 12.8% | 9 February 2017 |
| CVE-2016-9244 | A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. | EXPLOIT ×2HIGH 7.5EPSS 62.5% | 9 February 2017 |
| CVE-2015-6024 | ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the DIA_IPADDRESS parameter. | EXPLOITCRITICAL 9.8EPSS 20.0% | 9 February 2017 |
| CVE-2015-6023 | ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intended access restrictions via a direct request. | EXPLOITHIGH 7.3EPSS 12.3% | 9 February 2017 |
| CVE-2017-0412 | An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. | EXPLOIT ✓HIGH 7.8EPSS 4.64% | 8 February 2017 |
| CVE-2017-0411 | An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. | EXPLOIT ✓HIGH 7.8EPSS 4.89% | 8 February 2017 |
| CVE-2016-7400 | Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action,… | EXPLOITCRITICAL 9.8EPSS 3.95% | 7 February 2017 |
| CVE-2016-6175 | Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header. | EXPLOIT ✓CRITICAL 9.8EPSS 15.3% | 7 February 2017 |
| CVE-2016-2539 | Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving a… | EXPLOIT ✓HIGH 8.8EPSS 3.83% | 7 February 2017 |
| CVE-2015-2794 | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx. | EXPLOIT ✓CRITICAL 9.8EPSS 55.1% | 6 February 2017 |
| CVE-2017-5630 | PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess… | EXPLOITHIGH 7.5EPSS 12.5% | 1 February 2017 |
| CVE-2016-3053 | IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. | EXPLOIT ✓HIGH 7.8EPSS 2.38% | 1 February 2017 |
| CVE-2016-10079 | SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515. | EXPLOITHIGH 7.5EPSS 5.44% | 1 February 2017 |
| CVE-2016-10043 | The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS command injection attacks. | EXPLOITCRITICAL 10.0EPSS 6.19% | 31 January 2017 |
| CVE-2016-2399 | Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted hdlr MP4 atom. | EXPLOITHIGH 7.8EPSS 9.08% | 30 January 2017 |
| CVE-2016-10176 | The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. | EXPLOITCRITICAL 9.8EPSS 72.2% | 30 January 2017 |
| CVE-2016-10175 | The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. | EXPLOITCRITICAL 9.8EPSS 55.2% | 30 January 2017 |
| CVE-2016-10174 | NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 83.3% | 30 January 2017 |
| CVE-2016-9554 | The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. | EXPLOIT ✓HIGH 7.2EPSS 21.3% | 28 January 2017 |
| CVE-2016-9553 | The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. | EXPLOIT ✓HIGH 7.2EPSS 16.3% | 28 January 2017 |
| CVE-2017-5329 | Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation. | EXPLOIT ✓HIGH 7.8EPSS 0.98% | 27 January 2017 |
| CVE-2017-3316 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). | EXPLOITHIGH 8.4EPSS 6.34% | 27 January 2017 |
| CVE-2017-3248 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). | EXPLOITCRITICAL 9.8EPSS 90.9% | 27 January 2017 |
| CVE-2017-3241 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). | EXPLOIT ✓CRITICAL 9.0EPSS 62.2% | 27 January 2017 |
| CVE-2017-5594 | In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. | EXPLOIT ✓HIGH 7.5EPSS 7.03% | 25 January 2017 |
| CVE-2016-7567 | Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a crafted string. | EXPLOITCRITICAL 9.8EPSS 12.5% | 23 January 2017 |
| CVE-2016-6603 | ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header. | EXPLOITCRITICAL 9.8EPSS 48.8% | 23 January 2017 |
| CVE-2016-6602 | ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. | EXPLOITCRITICAL 9.8EPSS 48.3% | 23 January 2017 |
| CVE-2016-6601 | Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. | EXPLOITHIGH 7.5EPSS 96.9% | 23 January 2017 |
| CVE-2016-6600 | Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. | EXPLOITCRITICAL 9.8EPSS 88.0% | 23 January 2017 |
| CVE-2016-5237 | Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to modify the files and possibly gain privileges as demonstrated by a Trojan horse Steam.exe file. | EXPLOITMEDIUM 4.8EPSS 0.74% | 23 January 2017 |
| CVE-2016-4793 | The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header. | EXPLOITHIGH 7.5EPSS 4.18% | 23 January 2017 |
| CVE-2016-4340 | The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors. | EXPLOITHIGH 8.8EPSS 7.77% | 23 January 2017 |
| CVE-2016-4338 | The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary… | EXPLOITHIGH 8.1EPSS 17.3% | 23 January 2017 |
| CVE-2016-4010 | Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data. | EXPLOIT ✓CRITICAL 9.8EPSS 97.5% | 23 January 2017 |
| CVE-2016-10156 | A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. | EXPLOITHIGH 7.8EPSS 1.19% | 23 January 2017 |
| CVE-2016-6253 | mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox. | EXPLOIT ×2 ✓HIGH 7.8EPSS 8.40% | 20 January 2017 |
| CVE-2014-2045 | Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 300 allow remote attackers to inject arbitrary web script or HTML via the username when (1) logging in or (2) creating an account in… | EXPLOITMEDIUM 6.1EPSS 5.12% | 20 January 2017 |
| CVE-2016-5725 | Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command. | EXPLOIT ✓MEDIUM 5.9EPSS 18.2% | 19 January 2017 |
| CVE-2016-6283 | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action. | EXPLOIT ✓MEDIUM 6.1EPSS 4.07% | 18 January 2017 |
| CVE-2016-3411 | Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 103609. | EXPLOITMEDIUM 6.1EPSS 4.70% | 18 January 2017 |
| CVE-2016-6897 | Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by… | EXPLOIT ✓MEDIUM 6.5EPSS 28.5% | 18 January 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.