SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

1,710 results · page 28 of 35

CVESummaryPriorityPublished
CVE-2018-0171Cisco IOS and IOS XE Software Smart Install Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.5%28 March 2018
CVE-2018-0167Cisco IOS, XR, and XE Software Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 3.35%28 March 2018
CVE-2018-0161Cisco IOS Software Resource Management Errors VulnerabilityKEVMEDIUM 6.3EPSS 4.12%28 March 2018
CVE-2018-0159Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service VulnerabilityKEVHIGH 7.5EPSS 6.87%28 March 2018
CVE-2018-0158Cisco IOS and XE Software Internet Key Exchange Memory Leak VulnerabilityKEVHIGH 8.6EPSS 7.19%28 March 2018
CVE-2018-0156Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service VulnerabilityKEVHIGH 7.5EPSS 8.60%28 March 2018
CVE-2018-0155Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service VulnerabilityKEVHIGH 8.6EPSS 7.74%28 March 2018
CVE-2018-0154Cisco IOS Software Integrated Services Module for VPN Denial-of-Service VulnerabilityKEVHIGH 7.5EPSS 7.07%28 March 2018
CVE-2018-0151Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 14.2%28 March 2018
CVE-2018-6882Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 25.3%27 March 2018
CVE-2017-12319Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service VulnerabilityKEVMEDIUM 5.9EPSS 5.24%27 March 2018
CVE-2018-7445MikroTik RouterOS Stack-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 60.8%19 March 2018
CVE-2018-0147Cisco Secure Access Control System Java Deserialization VulnerabilityKEVCRITICAL 9.8EPSS 18.2%8 March 2018
CVE-2018-6530D-Link Multiple Routers OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 96.7%6 March 2018
CVE-2018-2380SAP Customer Relationship Management (CRM) Path Traversal VulnerabilityKEVMEDIUM 6.6EPSS 28.9%1 March 2018
CVE-2018-6789Exim Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 82.1%8 February 2018
CVE-2018-0125Cisco VPN Routers Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 55.2%8 February 2018
CVE-2018-4878Adobe Flash Player Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 89.5%6 February 2018
CVE-2017-1000353Jenkins Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.7%29 January 2018
CVE-2018-0802Microsoft Office Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 93.3%10 January 2018
CVE-2018-0798Microsoft Office Memory Corruption VulnerabilityKEVHIGH 8.8EPSS 95.1%10 January 2018
CVE-2017-1000486Primetek Primefaces Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 94.1%3 January 2018
CVE-2017-17562Embedthis GoAhead Remote Code Execution VulnerabilityKEVHIGH 8.1EPSS 96.3%12 December 2017
CVE-2017-15944Palo Alto Networks PAN-OS Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 98.3%11 December 2017
CVE-2017-11882Microsoft Office Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 99.9%15 November 2017
CVE-2017-16651Roundcube Webmail File Disclosure VulnerabilityKEVHIGH 7.8EPSS 36.9%9 November 2017
CVE-2017-5070Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 31.2%27 October 2017
CVE-2017-11292Adobe Flash Player Type Confusion VulnerabilityKEVHIGH 8.8EPSS 11.9%22 October 2017
CVE-2017-10271Oracle Corporation WebLogic Server Remote Code Execution VulnerabilityKEVHIGH 7.5EPSS 100.0%19 October 2017
CVE-2017-11826Microsoft Office Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 81.3%13 October 2017
CVE-2017-11774Microsoft Office Outlook Security Feature Bypass VulnerabilityKEVHIGH 7.8EPSS 59.9%13 October 2017
CVE-2017-1000253Linux Kernel PIE Stack Buffer Corruption Vulnerability KEVHIGH 7.8EPSS 10.7%5 October 2017
CVE-2017-12149Red Hat JBoss Application Server Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 90.7%4 October 2017
CVE-2017-12617Apache Tomcat Remote Code Execution VulnerabilityKEVHIGH 8.1EPSS 100.0%4 October 2017
CVE-2017-12240Cisco IOS and IOS XE Software DHCP Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 13.9%29 September 2017
CVE-2017-12238Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service VulnerabilityKEVMEDIUM 6.5EPSS 2.03%29 September 2017
CVE-2017-12237Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service VulnerabilityKEVHIGH 7.5EPSS 7.13%29 September 2017
CVE-2017-12235Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service VulnerabilityKEVHIGH 7.5EPSS 7.13%29 September 2017
CVE-2017-12234Cisco IOS Software Common Industrial Protocol Request Denial-of-Service VulnerabilityKEVHIGH 7.5EPSS 7.13%29 September 2017
CVE-2017-12233Cisco IOS Software Common Industrial Protocol Request Denial-of-Service VulnerabilityKEVHIGH 7.5EPSS 7.13%29 September 2017
CVE-2017-12232Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service VulnerabilityKEVMEDIUM 6.5EPSS 2.17%29 September 2017
CVE-2017-12231Cisco IOS Software Network Address Translation Denial-of-Service VulnerabilityKEVHIGH 7.5EPSS 7.13%29 September 2017
CVE-2015-1187D-Link and TRENDnet Multiple Devices Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 82.9%21 September 2017
CVE-2017-12615Apache Tomcat on Windows Remote Code Execution VulnerabilityKEVHIGH 8.1EPSS 99.6%19 September 2017
CVE-2017-9805Apache Struts Deserialization of Untrusted Data VulnerabilityKEVHIGH 8.1EPSS 99.4%15 September 2017
CVE-2017-8759Microsoft .NET Framework Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 88.7%13 September 2017
CVE-2017-6627Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service VulnerabilityKEVHIGH 7.5EPSS 6.04%7 September 2017
CVE-2017-11357Telerik UI for ASP.NET AJAX Insecure Direct Object Reference VulnerabilityKEVCRITICAL 9.8EPSS 77.7%23 August 2017
CVE-2017-11317Telerik UI for ASP.NET AJAX Unrestricted File Upload VulnerabilityKEVCRITICAL 9.8EPSS 84.2%23 August 2017
CVE-2017-6327Symantec Messaging Gateway Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 35.3%11 August 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.