SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,540 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 163 of 348

CVESummaryPriorityPublished
CVE-2017-17692Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.HIGH 7.5EPSS 78.8%21 December 2017
CVE-2017-17411This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0.CRITICAL 9.8EPSS 87.9%21 December 2017
CVE-2017-5259In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.HIGH 8.8EPSS 30.6%20 December 2017
CVE-2017-5255In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell…HIGH 8.8EPSS 74.6%20 December 2017
CVE-2017-5254In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism.HIGH 8.8EPSS 53.7%20 December 2017
CVE-2012-2576SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the…CRITICAL 9.8EPSS 59.4%20 December 2017
CVE-2017-15049The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.HIGH 8.8EPSS 17.0%19 December 2017
CVE-2017-15048Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.HIGH 8.8EPSS 10.2%19 December 2017
CVE-2017-17759Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request (which reaches an older version of a West Wind Web…CRITICAL 9.8EPSS 11.3%19 December 2017
CVE-2017-17106Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request.CRITICAL 9.8EPSS 15.3%19 December 2017
CVE-2017-17105Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a…CRITICAL 9.8EPSS 84.6%19 December 2017
CVE-2017-16949Improper input sanitization allows the attacker to override the settings for allowed file extensions and upload file size, related to inc/cores/file-uploader.php and file-uploader/file-uploader-class.php.CRITICAL 9.8EPSS 19.2%19 December 2017
CVE-2017-17739The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.CRITICAL 9.8EPSS 11.9%18 December 2017
CVE-2017-17733Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.CRITICAL 9.8EPSS 44.1%18 December 2017
CVE-2017-17731DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.CRITICAL 9.8EPSS 13.2%18 December 2017
CVE-2017-3195Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.CRITICAL 9.8EPSS 21.4%16 December 2017
CVE-2017-3192The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page.CRITICAL 9.8EPSS 39.5%16 December 2017
CVE-2017-3191D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.CRITICAL 9.8EPSS 62.5%16 December 2017
CVE-2017-12373A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle…MEDIUM 5.9EPSS 12.8%15 December 2017
CVE-2017-17405Ruby before 2.4.3 allows Net::FTP command injection.HIGH 8.8EPSS 73.8%15 December 2017
CVE-2017-17672In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's…CRITICAL 9.8EPSS 15.2%14 December 2017
CVE-2017-17664A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9.MEDIUM 5.9EPSS 32.4%13 December 2017
CVE-2017-17427Radware Alteon devices with a firmware version between 31.0.0.0-31.0.3.0 are vulnerable to an adaptive-chosen ciphertext attack ("Bleichenbacher attack").MEDIUM 5.9EPSS 15.6%13 December 2017
CVE-2017-17382Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging…MEDIUM 5.9EPSS 13.8%13 December 2017
CVE-2017-13099wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated.MEDIUM 5.9EPSS 24.9%13 December 2017
CVE-2017-13098BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated.MEDIUM 5.9EPSS 24.3%13 December 2017
CVE-2017-11935Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".HIGH 7.8EPSS 18.9%12 December 2017
CVE-2017-11934Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in memory, aka "Microsoft Office Information Disclosure Vulnerability".MEDIUM 5.5EPSS 12.6%12 December 2017
CVE-2017-11918ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine…HIGH 7.5EPSS 62.6%12 December 2017
CVE-2017-11914ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory…HIGH 7.5EPSS 62.6%12 December 2017
CVE-2017-11911ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption…HIGH 7.5EPSS 65.5%12 December 2017
CVE-2017-11909ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption…HIGH 7.5EPSS 65.5%12 December 2017
CVE-2017-11907Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as…HIGH 7.5EPSS 64.7%12 December 2017
CVE-2017-11906Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to…MEDIUM 5.3EPSS 25.1%12 December 2017
CVE-2017-11903Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as…HIGH 7.5EPSS 46.8%12 December 2017
CVE-2017-11893ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine…HIGH 7.5EPSS 68.5%12 December 2017
CVE-2017-11890Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the…HIGH 7.5EPSS 50.1%12 December 2017
CVE-2017-11885Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow a remote code execution vulnerability due to…MEDIUM 6.6EPSS 45.5%12 December 2017
CVE-2017-1000385This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).MEDIUM 5.9EPSS 22.1%12 December 2017
CVE-2017-17562Embedthis GoAhead Remote Code Execution VulnerabilityKEVHIGH 8.1EPSS 96.3%12 December 2017
CVE-2017-17560This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.CRITICAL 9.8EPSS 73.4%12 December 2017
CVE-2017-15944Palo Alto Networks PAN-OS Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 98.3%11 December 2017
CVE-2017-15708In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI).CRITICAL 9.8EPSS 17.7%11 December 2017
CVE-2017-16416The vulnerability is caused by a computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that handles Enhanced Metafile Format Plus (EMF+) data.HIGH 8.8EPSS 11.2%9 December 2017
CVE-2017-16415The vulnerability is caused by a computation that writes data past the end of the intended buffer; the computation is a part of the functionality that handles font encodings.HIGH 8.8EPSS 11.2%9 December 2017
CVE-2017-16413The vulnerability is caused by a computation that writes data past the end of the intended buffer; the computation is part of the XPS to PDF conversion module, when processing TIFF files.HIGH 8.8EPSS 11.2%9 December 2017
CVE-2017-16396The vulnerability is caused by a buffer access with an incorrect length value in the TIFF processing module.HIGH 8.8EPSS 12.8%9 December 2017
CVE-2017-16395The vulnerability is caused by a buffer access with an incorrect length value in the image conversion module when processing Enhanced Metafile Format (EMF).HIGH 8.8EPSS 12.8%9 December 2017
CVE-2017-16393This vulnerability is an instance of a use after free vulnerability in the JavaScript engine.HIGH 8.8EPSS 16.9%9 December 2017
CVE-2017-16392The vulnerability is caused by a buffer access with an incorrect length value in the JPEG processing module.HIGH 8.8EPSS 12.8%9 December 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.