Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 31 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2016-0162 | Microsoft Internet Explorer Information Disclosure Vulnerability | KEVMEDIUM 4.3EPSS 22.1% | 12 April 2016 |
| CVE-2016-0151 | Microsoft Windows CSRSS Security Feature Bypass Vulnerability | KEVHIGH 7.8EPSS 63.2% | 12 April 2016 |
| CVE-2016-3976 | SAP NetWeaver Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 46.6% | 7 April 2016 |
| CVE-2016-1019 | Adobe Flash Player Arbitrary Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 22.5% | 7 April 2016 |
| CVE-2016-1646 | Google Chromium V8 Out-of-Bounds Read Vulnerability | KEVHIGH 8.8EPSS 48.1% | 29 March 2016 |
| CVE-2016-1010 | Adobe Flash Player and AIR Integer Overflow Vulnerability | KEVHIGH 8.8EPSS 19.4% | 12 March 2016 |
| CVE-2016-0099 | Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 37.2% | 9 March 2016 |
| CVE-2016-2388 | SAP NetWeaver Information Disclosure Vulnerability | KEVMEDIUM 5.3EPSS 51.6% | 16 February 2016 |
| CVE-2016-2386 | SAP NetWeaver SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 71.1% | 16 February 2016 |
| CVE-2016-0752 | Ruby on Rails Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 95.5% | 16 February 2016 |
| CVE-2016-0984 | Adobe Flash Player and AIR Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 54.8% | 10 February 2016 |
| CVE-2016-0040 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 24.5% | 10 February 2016 |
| CVE-2016-0034 | Microsoft Silverlight Runtime Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 69.6% | 13 January 2016 |
| CVE-2015-7450 | IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. | KEVCRITICAL 9.8EPSS 97.7% | 2 January 2016 |
| CVE-2015-8651 | Adobe Flash Player Integer Overflow Vulnerability | KEVHIGH 8.8EPSS 67.9% | 28 December 2015 |
| CVE-2015-7755 | Juniper ScreenOS Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 61.4% | 19 December 2015 |
| CVE-2015-6175 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 5.17% | 9 December 2015 |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 4.96% | 7 December 2015 |
| CVE-2015-5317 | Jenkins User Interface (UI) Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 22.4% | 25 November 2015 |
| CVE-2015-4852 | Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 96.0% | 18 November 2015 |
| CVE-2015-4902 | Oracle Java SE Integrity Check Vulnerability | KEVMEDIUM 5.3EPSS 13.4% | 22 October 2015 |
| CVE-2015-7645 | Adobe Flash Player Arbitrary Code Execution Vulnerability | KEVHIGH 7.8EPSS 65.6% | 15 October 2015 |
| CVE-2015-2546 | Microsoft Win32k Memory Corruption Vulnerability | KEVHIGH 8.2EPSS 10.2% | 9 September 2015 |
| CVE-2015-2545 | Microsoft Office Malformed EPS File Vulnerability | KEVHIGH 7.8EPSS 86.1% | 9 September 2015 |
| CVE-2015-2502 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 51.1% | 19 August 2015 |
| CVE-2015-1769 | Microsoft Windows Mount Manager Privilege Escalation Vulnerability | KEVMEDIUM 6.6EPSS 4.11% | 15 August 2015 |
| CVE-2015-1642 | Microsoft Office Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 53.2% | 15 August 2015 |
| CVE-2015-3246 | Red Hat Libuser Race Condition Vulnerability | KEVMEDIUM 5.1EPSS 8.80% | 11 August 2015 |
| CVE-2015-4495 | Mozilla Firefox Security Feature Bypass Vulnerability | KEVHIGH 8.8EPSS 71.4% | 8 August 2015 |
| CVE-2015-2426 | Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 86.7% | 20 July 2015 |
| CVE-2015-2590 | Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 25.5% | 16 July 2015 |
| CVE-2015-2387 | Microsoft ATM Font Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 35.1% | 14 July 2015 |
| CVE-2015-2425 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 44.9% | 14 July 2015 |
| CVE-2015-2424 | Microsoft PowerPoint Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 38.5% | 14 July 2015 |
| CVE-2015-2419 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 53.4% | 14 July 2015 |
| CVE-2015-5123 | Adobe Flash Player Use-After-Free Vulnerability | KEVCRITICAL 9.8EPSS 18.5% | 14 July 2015 |
| CVE-2015-5122 | Adobe Flash Player Use-After-Free Vulnerability | KEVCRITICAL 9.8EPSS 93.7% | 14 July 2015 |
| CVE-2015-5119 | Adobe Flash Player Use-After-Free Vulnerability | KEVCRITICAL 9.8EPSS 99.3% | 8 July 2015 |
| CVE-2015-3113 | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 23 June 2015 |
| CVE-2015-2360 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 15.0% | 10 June 2015 |
| CVE-2015-1770 | Microsoft Office Uninitialized Memory Use Vulnerability | KEVHIGH 8.8EPSS 35.1% | 10 June 2015 |
| CVE-2015-4068 | Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability | KEVCRITICAL 9.1EPSS 63.6% | 29 May 2015 |
| CVE-2015-1671 | Microsoft Windows Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 54.6% | 13 May 2015 |
| CVE-2014-8361 | Realtek SDK Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 1 May 2015 |
| CVE-2015-3035 | TP-Link Multiple Archer Devices Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 83.9% | 22 April 2015 |
| CVE-2015-1701 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 56.2% | 21 April 2015 |
| CVE-2015-3043 | Adobe Flash Player Memory Corruption Vulnerability | KEVCRITICAL 9.8EPSS 73.9% | 14 April 2015 |
| CVE-2015-1641 | Microsoft Office Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 96.8% | 14 April 2015 |
| CVE-2015-1635 | Microsoft HTTP.sys Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 14 April 2015 |
| CVE-2015-1130 | Apple OS X Authentication Bypass Vulnerability | KEVHIGH 7.8EPSS 9.89% | 10 April 2015 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.