Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 28 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-0171 | Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.5% | 28 March 2018 |
| CVE-2018-0167 | Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 3.35% | 28 March 2018 |
| CVE-2018-0161 | Cisco IOS Software Resource Management Errors Vulnerability | KEVMEDIUM 6.3EPSS 4.12% | 28 March 2018 |
| CVE-2018-0159 | Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 6.87% | 28 March 2018 |
| CVE-2018-0158 | Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability | KEVHIGH 8.6EPSS 7.19% | 28 March 2018 |
| CVE-2018-0156 | Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 8.60% | 28 March 2018 |
| CVE-2018-0155 | Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability | KEVHIGH 8.6EPSS 7.74% | 28 March 2018 |
| CVE-2018-0154 | Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 7.07% | 28 March 2018 |
| CVE-2018-0151 | Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 14.2% | 28 March 2018 |
| CVE-2018-6882 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 25.3% | 27 March 2018 |
| CVE-2017-12319 | Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability | KEVMEDIUM 5.9EPSS 5.24% | 27 March 2018 |
| CVE-2018-7445 | MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 60.8% | 19 March 2018 |
| CVE-2018-0147 | Cisco Secure Access Control System Java Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 18.2% | 8 March 2018 |
| CVE-2018-6530 | D-Link Multiple Routers OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 96.7% | 6 March 2018 |
| CVE-2018-2380 | SAP Customer Relationship Management (CRM) Path Traversal Vulnerability | KEVMEDIUM 6.6EPSS 28.9% | 1 March 2018 |
| CVE-2018-6789 | Exim Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 82.1% | 8 February 2018 |
| CVE-2018-0125 | Cisco VPN Routers Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 55.2% | 8 February 2018 |
| CVE-2018-4878 | Adobe Flash Player Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 89.5% | 6 February 2018 |
| CVE-2017-1000353 | Jenkins Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 29 January 2018 |
| CVE-2018-0802 | Microsoft Office Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 93.3% | 10 January 2018 |
| CVE-2018-0798 | Microsoft Office Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 95.1% | 10 January 2018 |
| CVE-2017-1000486 | Primetek Primefaces Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 94.1% | 3 January 2018 |
| CVE-2017-17562 | Embedthis GoAhead Remote Code Execution Vulnerability | KEVHIGH 8.1EPSS 96.3% | 12 December 2017 |
| CVE-2017-15944 | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 11 December 2017 |
| CVE-2017-11882 | Microsoft Office Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 99.9% | 15 November 2017 |
| CVE-2017-16651 | Roundcube Webmail File Disclosure Vulnerability | KEVHIGH 7.8EPSS 36.9% | 9 November 2017 |
| CVE-2017-5070 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 31.2% | 27 October 2017 |
| CVE-2017-11292 | Adobe Flash Player Type Confusion Vulnerability | KEVHIGH 8.8EPSS 11.9% | 22 October 2017 |
| CVE-2017-10271 | Oracle Corporation WebLogic Server Remote Code Execution Vulnerability | KEVHIGH 7.5EPSS 100.0% | 19 October 2017 |
| CVE-2017-11826 | Microsoft Office Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 81.3% | 13 October 2017 |
| CVE-2017-11774 | Microsoft Office Outlook Security Feature Bypass Vulnerability | KEVHIGH 7.8EPSS 59.9% | 13 October 2017 |
| CVE-2017-1000253 | Linux Kernel PIE Stack Buffer Corruption Vulnerability | KEVHIGH 7.8EPSS 10.7% | 5 October 2017 |
| CVE-2017-12149 | Red Hat JBoss Application Server Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 90.7% | 4 October 2017 |
| CVE-2017-12617 | Apache Tomcat Remote Code Execution Vulnerability | KEVHIGH 8.1EPSS 100.0% | 4 October 2017 |
| CVE-2017-12240 | Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 13.9% | 29 September 2017 |
| CVE-2017-12238 | Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability | KEVMEDIUM 6.5EPSS 2.03% | 29 September 2017 |
| CVE-2017-12237 | Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 7.13% | 29 September 2017 |
| CVE-2017-12235 | Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 7.13% | 29 September 2017 |
| CVE-2017-12234 | Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 7.13% | 29 September 2017 |
| CVE-2017-12233 | Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 7.13% | 29 September 2017 |
| CVE-2017-12232 | Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability | KEVMEDIUM 6.5EPSS 2.17% | 29 September 2017 |
| CVE-2017-12231 | Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 7.13% | 29 September 2017 |
| CVE-2015-1187 | D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 82.9% | 21 September 2017 |
| CVE-2017-12615 | Apache Tomcat on Windows Remote Code Execution Vulnerability | KEVHIGH 8.1EPSS 99.6% | 19 September 2017 |
| CVE-2017-9805 | Apache Struts Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.1EPSS 99.4% | 15 September 2017 |
| CVE-2017-8759 | Microsoft .NET Framework Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 88.7% | 13 September 2017 |
| CVE-2017-6627 | Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 6.04% | 7 September 2017 |
| CVE-2017-11357 | Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability | KEVCRITICAL 9.8EPSS 77.7% | 23 August 2017 |
| CVE-2017-11317 | Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability | KEVCRITICAL 9.8EPSS 84.2% | 23 August 2017 |
| CVE-2017-6327 | Symantec Messaging Gateway Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 35.3% | 11 August 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.