Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 30 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-0059 | Microsoft Internet Explorer Information Disclosure Vulnerability | KEVMEDIUM 4.3EPSS 62.0% | 17 March 2017 |
| CVE-2017-0022 | Microsoft XML Core Services Information Disclosure Vulnerability | KEVMEDIUM 6.5EPSS 18.1% | 17 March 2017 |
| CVE-2017-0005 | Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 11.0% | 17 March 2017 |
| CVE-2017-0001 | Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 3.11% | 17 March 2017 |
| CVE-2017-5638 | Apache Struts Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 11 March 2017 |
| CVE-2017-6334 | NETGEAR DGN2200 Devices OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 72.2% | 6 March 2017 |
| CVE-2017-0037 | Microsoft Edge and Internet Explorer Type Confusion Vulnerability | KEVHIGH 8.1EPSS 80.4% | 26 February 2017 |
| CVE-2017-6077 | NETGEAR DGN2200 Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 68.2% | 22 February 2017 |
| CVE-2016-10174 | NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 83.5% | 30 January 2017 |
| CVE-2016-5198 | Google Chromium V8 Out-of-Bounds Memory Vulnerability | KEVHIGH 8.8EPSS 34.2% | 19 January 2017 |
| CVE-2017-5521 | NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability | KEVHIGH 8.1EPSS 89.4% | 17 January 2017 |
| CVE-2016-10033 | PHPMailer Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 30 December 2016 |
| CVE-2016-7262 | Microsoft Office Security Feature Bypass Vulnerability | KEVHIGH 7.8EPSS 57.9% | 20 December 2016 |
| CVE-2016-7892 | Adobe Flash Player Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 18.8% | 15 December 2016 |
| CVE-2016-6277 | NETGEAR Multiple Routers Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 99.8% | 14 December 2016 |
| CVE-2016-9563 | SAP NetWeaver XML External Entity (XXE) Vulnerability | KEVMEDIUM 6.5EPSS 23.8% | 23 November 2016 |
| CVE-2016-8562 | Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability | KEVHIGH 7.5EPSS 3.62% | 18 November 2016 |
| CVE-2016-5195 | Linux Kernel Race Condition Vulnerability | KEVHIGH 7.0EPSS 83.5% | 10 November 2016 |
| CVE-2016-7256 | Microsoft Windows Open Type Font Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 64.8% | 10 November 2016 |
| CVE-2016-7255 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 81.0% | 10 November 2016 |
| CVE-2016-7201 | Microsoft Edge Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 79.7% | 10 November 2016 |
| CVE-2016-7200 | Microsoft Edge Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 82.5% | 10 November 2016 |
| CVE-2016-7855 | Adobe Flash Player Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 25.2% | 1 November 2016 |
| CVE-2016-7193 | Microsoft Office Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 57.7% | 14 October 2016 |
| CVE-2016-3393 | Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 68.7% | 14 October 2016 |
| CVE-2016-3298 | Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability | KEVMEDIUM 6.5EPSS 32.8% | 14 October 2016 |
| CVE-2016-6415 | Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 87.3% | 19 September 2016 |
| CVE-2016-3351 | Microsoft Internet Explorer and Edge Information Disclosure Vulnerability | KEVMEDIUM 6.5EPSS 26.3% | 14 September 2016 |
| CVE-2016-4657 | Apple iOS Webkit Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 66.8% | 25 August 2016 |
| CVE-2016-4656 | Apple iOS Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 23.6% | 25 August 2016 |
| CVE-2016-4655 | Apple iOS Information Disclosure Vulnerability | KEVMEDIUM 5.5EPSS 33.4% | 25 August 2016 |
| CVE-2016-6367 | Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 22.6% | 18 August 2016 |
| CVE-2016-6366 | Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 87.6% | 18 August 2016 |
| CVE-2016-3309 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 20.6% | 9 August 2016 |
| CVE-2016-3643 | SolarWinds Virtualization Manager Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 3.70% | 17 June 2016 |
| CVE-2016-4171 | Adobe Flash Player Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 20.2% | 16 June 2016 |
| CVE-2016-3235 | Microsoft Office OLE DLL Side Loading Vulnerability | KEVHIGH 7.8EPSS 43.4% | 16 June 2016 |
| CVE-2016-4523 | Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 30.7% | 9 June 2016 |
| CVE-2016-4437 | Apache Shiro Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 93.0% | 7 June 2016 |
| CVE-2016-3088 | Apache ActiveMQ Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 98.5% | 1 June 2016 |
| CVE-2010-5326 | SAP NetWeaver Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 17.4% | 13 May 2016 |
| CVE-2016-4117 | Adobe Flash Player Arbitrary Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 94.4% | 11 May 2016 |
| CVE-2016-0189 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 94.1% | 11 May 2016 |
| CVE-2016-0185 | Microsoft Windows Media Center Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 69.9% | 11 May 2016 |
| CVE-2016-3718 | ImageMagick Server-Side Request Forgery (SSRF) Vulnerability | KEVMEDIUM 5.5EPSS 76.9% | 5 May 2016 |
| CVE-2016-3715 | ImageMagick Arbitrary File Deletion Vulnerability | KEVMEDIUM 5.5EPSS 75.4% | 5 May 2016 |
| CVE-2016-3714 | ImageMagick Improper Input Validation Vulnerability | KEVHIGH 8.4EPSS 97.5% | 5 May 2016 |
| CVE-2016-3427 | Oracle Java SE and JRockit Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 92.3% | 21 April 2016 |
| CVE-2016-0167 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 5.73% | 12 April 2016 |
| CVE-2016-0165 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 13.8% | 12 April 2016 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.