SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 98 of 501

CVESummaryPriorityPublished
CVE-2016-6896Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a ..EXPLOITHIGH 7.1EPSS 31.1%18 January 2017
CVE-2016-7998The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action.EXPLOITHIGH 8.8EPSS 11.2%18 January 2017
CVE-2016-7982Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action.EXPLOITHIGH 7.5EPSS 15.7%18 January 2017
CVE-2016-7980Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted…EXPLOITHIGH 8.8EPSS 4.29%18 January 2017
CVE-2016-2233Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC servers to cause a denial of service (crash) via a large number of options in a CAP LS message.EXPLOITHIGH 7.5EPSS 27.2%18 January 2017
CVE-2016-2087Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a ..EXPLOITHIGH 7.4EPSS 7.72%18 January 2017
CVE-2017-5521NETGEAR Multiple Devices Exposure of Sensitive Information VulnerabilityKEVEXPLOITHIGH 8.1EPSS 89.2%17 January 2017
CVE-2017-5223To form a remote vulnerability, the msgHTML method must be called, passed an unfiltered, user-supplied HTML document, and must not set a base directory.EXPLOITMEDIUM 5.5EPSS 2.05%16 January 2017
CVE-2017-5487wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a…EXPLOITMEDIUM 5.3EPSS 77.0%15 January 2017
CVE-2017-5473Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user_prefs.lua, admin/delete_user.lua, and…EXPLOITHIGH 8.8EPSS 3.07%14 January 2017
CVE-2016-9813The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.EXPLOITMEDIUM 5.5EPSS 11.4%13 January 2017
CVE-2016-7434The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.EXPLOITHIGH 7.5EPSS 52.9%13 January 2017
CVE-2016-9299The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.EXPLOITCRITICAL 9.8EPSS 86.9%12 January 2017
CVE-2016-6772An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code within the context of a privileged process.EXPLOITHIGH 7.8EPSS 5.04%12 January 2017
CVE-2016-4808Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed…EXPLOITHIGH 8.8EPSS 1.67%11 January 2017
CVE-2016-4807Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).EXPLOITMEDIUM 4.8EPSS 2.94%11 January 2017
CVE-2016-4806Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.EXPLOITHIGH 7.5EPSS 7.20%11 January 2017
CVE-2017-2935Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format.EXPLOITHIGH 8.8EPSS 29.9%11 January 2017
CVE-2017-2934Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Texture Format files.EXPLOITHIGH 8.8EPSS 29.9%11 January 2017
CVE-2017-2933Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression.EXPLOITHIGH 8.8EPSS 29.9%11 January 2017
CVE-2017-2932Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript MovieClip class.EXPLOITHIGH 8.8EPSS 24.6%11 January 2017
CVE-2017-2931Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the parsing of SWF metadata.EXPLOITHIGH 8.8EPSS 21.1%11 January 2017
CVE-2017-2930Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurrency error when manipulating a display list.EXPLOIT ×2HIGH 8.8EPSS 25.1%11 January 2017
CVE-2015-4594eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability.EXPLOITCRITICAL 9.8EPSS 4.17%10 January 2017
CVE-2015-4593eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote attackers to hijack the authentication of content administrators for requests that could lead to the…EXPLOITHIGH 8.8EPSS 3.17%10 January 2017
CVE-2015-4592eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input.EXPLOITHIGH 8.8EPSS 2.59%10 January 2017
CVE-2015-4591eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter.EXPLOITMEDIUM 6.1EPSS 5.50%10 January 2017
CVE-2016-10010sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.EXPLOITHIGH 7.0EPSS 4.24%5 January 2017
CVE-2016-10009Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.EXPLOITHIGH 7.3EPSS 37.9%5 January 2017
CVE-2016-1004Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016.EXPLOITUnscoredEPSS —31 December 2016
CVE-2016-1003Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —31 December 2016
CVE-2016-10074The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail…EXPLOIT ×3CRITICAL 9.8EPSS 36.9%30 December 2016
CVE-2016-10045The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal…EXPLOIT ×3CRITICAL 9.8EPSS 97.7%30 December 2016
CVE-2016-10034The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently…EXPLOIT ×3CRITICAL 9.8EPSS 31.9%30 December 2016
CVE-2016-10033PHPMailer Command Injection VulnerabilityKEVEXPLOIT ×9CRITICAL 9.8EPSS 99.7%30 December 2016
CVE-2016-10081/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Run a plugin" action.EXPLOITHIGH 7.8EPSS 8.98%29 December 2016
CVE-2016-7084tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allows guest OS users to execute arbitrary code on the host OS or cause a denial of…EXPLOITHIGH 7.8EPSS 1.61%29 December 2016
CVE-2016-7083VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS or cause a denial of service (host…EXPLOITHIGH 7.8EPSS 1.61%29 December 2016
CVE-2016-9793The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have…EXPLOITHIGH 7.8EPSS 1.57%28 December 2016
CVE-2016-10031WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges.EXPLOITHIGH 7.5EPSS 1.20%27 December 2016
CVE-2016-7288The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 7.5EPSS 68.4%20 December 2016
CVE-2016-7287The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."EXPLOITHIGH 7.5EPSS 66.2%20 December 2016
CVE-2016-7286The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 7.5EPSS 65.2%20 December 2016
CVE-2016-7274Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute…EXPLOITHIGH 8.8EPSS 36.5%20 December 2016
CVE-2016-9951A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields.EXPLOITMEDIUM 6.5EPSS 6.69%17 December 2016
CVE-2016-9950There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields.EXPLOITHIGH 7.8EPSS 10.2%17 December 2016
CVE-2016-9949In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{".EXPLOITHIGH 7.8EPSS 26.1%17 December 2016
CVE-2016-7454CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an attacker to change the Wi-Fi password, open the remote management interface, or reset the router.EXPLOITHIGH 8.0EPSS 1.71%17 December 2016
CVE-2016-9838An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5.EXPLOITHIGH 7.5EPSS 11.6%16 December 2016
CVE-2016-9566base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file.EXPLOITHIGH 7.8EPSS 4.51%15 December 2016

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.