Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,540 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 163 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-17692 | Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property. | HIGH 7.5EPSS 78.8% | 21 December 2017 |
| CVE-2017-17411 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. | CRITICAL 9.8EPSS 87.9% | 21 December 2017 |
| CVE-2017-5259 | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp. | HIGH 8.8EPSS 30.6% | 20 December 2017 |
| CVE-2017-5255 | In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell… | HIGH 8.8EPSS 74.6% | 20 December 2017 |
| CVE-2017-5254 | In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism. | HIGH 8.8EPSS 53.7% | 20 December 2017 |
| CVE-2012-2576 | SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the… | CRITICAL 9.8EPSS 59.4% | 20 December 2017 |
| CVE-2017-15049 | The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler. | HIGH 8.8EPSS 17.0% | 19 December 2017 |
| CVE-2017-15048 | Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler. | HIGH 8.8EPSS 10.2% | 19 December 2017 |
| CVE-2017-17759 | Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request (which reaches an older version of a West Wind Web… | CRITICAL 9.8EPSS 11.3% | 19 December 2017 |
| CVE-2017-17106 | Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. | CRITICAL 9.8EPSS 15.3% | 19 December 2017 |
| CVE-2017-17105 | Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a… | CRITICAL 9.8EPSS 84.6% | 19 December 2017 |
| CVE-2017-16949 | Improper input sanitization allows the attacker to override the settings for allowed file extensions and upload file size, related to inc/cores/file-uploader.php and file-uploader/file-uploader-class.php. | CRITICAL 9.8EPSS 19.2% | 19 December 2017 |
| CVE-2017-17739 | The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files. | CRITICAL 9.8EPSS 11.9% | 18 December 2017 |
| CVE-2017-17733 | Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request. | CRITICAL 9.8EPSS 44.1% | 18 December 2017 |
| CVE-2017-17731 | DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php. | CRITICAL 9.8EPSS 13.2% | 18 December 2017 |
| CVE-2017-3195 | Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges. | CRITICAL 9.8EPSS 21.4% | 16 December 2017 |
| CVE-2017-3192 | The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. | CRITICAL 9.8EPSS 39.5% | 16 December 2017 |
| CVE-2017-3191 | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. | CRITICAL 9.8EPSS 62.5% | 16 December 2017 |
| CVE-2017-12373 | A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle… | MEDIUM 5.9EPSS 12.8% | 15 December 2017 |
| CVE-2017-17405 | Ruby before 2.4.3 allows Net::FTP command injection. | HIGH 8.8EPSS 73.8% | 15 December 2017 |
| CVE-2017-17672 | In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's… | CRITICAL 9.8EPSS 15.2% | 14 December 2017 |
| CVE-2017-17664 | A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. | MEDIUM 5.9EPSS 32.4% | 13 December 2017 |
| CVE-2017-17427 | Radware Alteon devices with a firmware version between 31.0.0.0-31.0.3.0 are vulnerable to an adaptive-chosen ciphertext attack ("Bleichenbacher attack"). | MEDIUM 5.9EPSS 15.6% | 13 December 2017 |
| CVE-2017-17382 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging… | MEDIUM 5.9EPSS 13.8% | 13 December 2017 |
| CVE-2017-13099 | wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. | MEDIUM 5.9EPSS 24.9% | 13 December 2017 |
| CVE-2017-13098 | BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. | MEDIUM 5.9EPSS 24.3% | 13 December 2017 |
| CVE-2017-11935 | Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability". | HIGH 7.8EPSS 18.9% | 12 December 2017 |
| CVE-2017-11934 | Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in memory, aka "Microsoft Office Information Disclosure Vulnerability". | MEDIUM 5.5EPSS 12.6% | 12 December 2017 |
| CVE-2017-11918 | ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine… | HIGH 7.5EPSS 62.6% | 12 December 2017 |
| CVE-2017-11914 | ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory… | HIGH 7.5EPSS 62.6% | 12 December 2017 |
| CVE-2017-11911 | ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption… | HIGH 7.5EPSS 65.5% | 12 December 2017 |
| CVE-2017-11909 | ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption… | HIGH 7.5EPSS 65.5% | 12 December 2017 |
| CVE-2017-11907 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as… | HIGH 7.5EPSS 64.7% | 12 December 2017 |
| CVE-2017-11906 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to… | MEDIUM 5.3EPSS 25.1% | 12 December 2017 |
| CVE-2017-11903 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as… | HIGH 7.5EPSS 46.8% | 12 December 2017 |
| CVE-2017-11893 | ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine… | HIGH 7.5EPSS 68.5% | 12 December 2017 |
| CVE-2017-11890 | Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the… | HIGH 7.5EPSS 50.1% | 12 December 2017 |
| CVE-2017-11885 | Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow a remote code execution vulnerability due to… | MEDIUM 6.6EPSS 45.5% | 12 December 2017 |
| CVE-2017-1000385 | This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack). | MEDIUM 5.9EPSS 22.1% | 12 December 2017 |
| CVE-2017-17562 | Embedthis GoAhead Remote Code Execution Vulnerability | KEVHIGH 8.1EPSS 96.3% | 12 December 2017 |
| CVE-2017-17560 | This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root. | CRITICAL 9.8EPSS 73.4% | 12 December 2017 |
| CVE-2017-15944 | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 11 December 2017 |
| CVE-2017-15708 | In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). | CRITICAL 9.8EPSS 17.7% | 11 December 2017 |
| CVE-2017-16416 | The vulnerability is caused by a computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that handles Enhanced Metafile Format Plus (EMF+) data. | HIGH 8.8EPSS 11.2% | 9 December 2017 |
| CVE-2017-16415 | The vulnerability is caused by a computation that writes data past the end of the intended buffer; the computation is a part of the functionality that handles font encodings. | HIGH 8.8EPSS 11.2% | 9 December 2017 |
| CVE-2017-16413 | The vulnerability is caused by a computation that writes data past the end of the intended buffer; the computation is part of the XPS to PDF conversion module, when processing TIFF files. | HIGH 8.8EPSS 11.2% | 9 December 2017 |
| CVE-2017-16396 | The vulnerability is caused by a buffer access with an incorrect length value in the TIFF processing module. | HIGH 8.8EPSS 12.8% | 9 December 2017 |
| CVE-2017-16395 | The vulnerability is caused by a buffer access with an incorrect length value in the image conversion module when processing Enhanced Metafile Format (EMF). | HIGH 8.8EPSS 12.8% | 9 December 2017 |
| CVE-2017-16393 | This vulnerability is an instance of a use after free vulnerability in the JavaScript engine. | HIGH 8.8EPSS 16.9% | 9 December 2017 |
| CVE-2017-16392 | The vulnerability is caused by a buffer access with an incorrect length value in the JPEG processing module. | HIGH 8.8EPSS 12.8% | 9 December 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.