SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 99 of 501

CVESummaryPriorityPublished
CVE-2016-9565MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server.EXPLOITCRITICAL 9.8EPSS 18.8%15 December 2016
CVE-2016-7866Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability.EXPLOITCRITICAL 9.8EPSS 15.4%15 December 2016
CVE-2016-6854Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature.EXPLOITMEDIUM 6.1EPSS 2.92%15 December 2016
CVE-2016-6853Script code and references to external websites can be injected to the names of PGP public keys.EXPLOITMEDIUM 6.1EPSS 2.92%15 December 2016
CVE-2016-6851This allows cross-site scripting attacks against arbitrary users since no prior authentication is needed.EXPLOITMEDIUM 6.1EPSS 3.28%15 December 2016
CVE-2016-5740This code gets executed within the context of the user's current session.EXPLOITMEDIUM 6.1EPSS 5.16%15 December 2016
CVE-2016-6277NETGEAR Multiple Routers Remote Code Execution VulnerabilityKEVEXPLOIT ×2HIGH 8.8EPSS 99.8%14 December 2016
CVE-2016-6664mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before…EXPLOITHIGH 7.0EPSS 2.97%13 December 2016
CVE-2016-6663Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x…EXPLOITHIGH 7.0EPSS 3.77%13 December 2016
CVE-2016-8655Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the…EXPLOIT ×3HIGH 7.8EPSS 11.1%8 December 2016
CVE-2016-8740The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via…EXPLOITHIGH 7.5EPSS 77.0%5 December 2016
CVE-2016-9796Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024.EXPLOITCRITICAL 9.8EPSS 9.88%3 December 2016
CVE-2016-1247The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before…EXPLOITHIGH 7.8EPSS 4.86%29 November 2016
CVE-2015-1328The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by…EXPLOIT ×3HIGH 7.8EPSS 39.0%28 November 2016
CVE-2016-6754A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website.EXPLOITHIGH 8.8EPSS 4.90%25 November 2016
CVE-2016-6707An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process.EXPLOITHIGH 7.8EPSS 8.13%25 November 2016
CVE-2016-9151Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows local users to gain privileges via crafted values of unspecified environment variables.EXPLOIT ×2HIGH 7.8EPSS 1.23%19 November 2016
CVE-2016-9150Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows remote attackers to execute arbitrary code via…EXPLOITCRITICAL 9.8EPSS 25.2%19 November 2016
CVE-2016-5195Linux Kernel Race Condition VulnerabilityKEVEXPLOIT ×5HIGH 7.0EPSS 83.5%10 November 2016
CVE-2016-7255Microsoft Win32k Privilege Escalation VulnerabilityKEVEXPLOIT ×3HIGH 7.8EPSS 81.0%10 November 2016
CVE-2016-7241Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."EXPLOITHIGH 7.5EPSS 70.5%10 November 2016
CVE-2016-7240The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different…EXPLOITHIGH 7.5EPSS 60.8%10 November 2016
CVE-2016-7237Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016…EXPLOITMEDIUM 6.5EPSS 67.3%10 November 2016
CVE-2016-7226Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."EXPLOITMEDIUM 6.1EPSS 5.17%10 November 2016
CVE-2016-7225Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."EXPLOITMEDIUM 6.1EPSS 5.17%10 November 2016
CVE-2016-7224Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a…EXPLOITMEDIUM 6.1EPSS 5.17%10 November 2016
CVE-2016-7216The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."EXPLOITMEDIUM 5.5EPSS 4.22%10 November 2016
CVE-2016-7203The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different…EXPLOITHIGH 7.5EPSS 59.1%10 November 2016
CVE-2016-7202The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption…EXPLOIT ×2HIGH 7.5EPSS 71.4%10 November 2016
CVE-2016-7201Microsoft Edge Memory Corruption VulnerabilityKEVEXPLOIT ×2HIGH 8.8EPSS 80.1%10 November 2016
CVE-2016-7200Microsoft Edge Memory Corruption VulnerabilityKEVEXPLOIT ×2HIGH 8.8EPSS 82.9%10 November 2016
CVE-2016-8812For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnerability in the kernel mode layer (nvstreamkms.sys) allowing a user to cause a stack buffer overflow with…EXPLOITHIGH 8.8EPSS 1.64%8 November 2016
CVE-2016-8811For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an…EXPLOITHIGH 7.8EPSS 1.60%8 November 2016
CVE-2016-8810For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100009a where a value passed…EXPLOITHIGH 7.8EPSS 1.53%8 November 2016
CVE-2016-8809For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70001b2 where the size of an…EXPLOITHIGH 7.8EPSS 1.60%8 November 2016
CVE-2016-8808For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000d5 where a value passed…EXPLOITHIGH 7.8EPSS 1.60%8 November 2016
CVE-2016-8807For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x10000e9 where a value is passed…EXPLOITHIGH 7.8EPSS 1.69%8 November 2016
CVE-2016-8806For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x5000027 where a pointer passed…EXPLOITHIGH 7.8EPSS 1.66%8 November 2016
CVE-2016-8805For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000014 where a value passed…EXPLOITHIGH 7.8EPSS 1.53%8 November 2016
CVE-2016-7391For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100010b where a missing array…EXPLOITHIGH 7.8EPSS 1.59%8 November 2016
CVE-2016-7390For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000194 where a value passed…EXPLOITHIGH 7.8EPSS 1.53%8 November 2016
CVE-2016-7387For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x600000D where a value passed…EXPLOITHIGH 7.8EPSS 1.45%8 November 2016
CVE-2016-7386For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000D4 which may lead to…EXPLOITMEDIUM 5.5EPSS 1.41%8 November 2016
CVE-2016-7385For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x700010d where a value passed…EXPLOITHIGH 7.8EPSS 1.44%8 November 2016
CVE-2016-7384For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) where unchecked input/output lengths in UVMLiteController…EXPLOITHIGH 7.8EPSS 1.41%8 November 2016
CVE-2016-7851This vulnerability could be exploited in cross-site scripting attacks.EXPLOITMEDIUM 6.1EPSS 4.65%8 November 2016
CVE-2016-9111Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable.EXPLOITMEDIUM 6.8EPSS 1.11%7 November 2016
CVE-2016-8870The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow…EXPLOITHIGH 8.1EPSS 83.0%4 November 2016
CVE-2016-8869The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.EXPLOITCRITICAL 9.8EPSS 97.1%4 November 2016
CVE-2016-9018Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.EXPLOITMEDIUM 5.5EPSS 4.80%28 October 2016

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.