Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,540 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 166 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2015-2780 | Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in an unspecified directory. | CRITICAL 9.8EPSS 15.1% | 16 October 2017 |
| CVE-2014-9148 | Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur. | CRITICAL 9.8EPSS 11.4% | 16 October 2017 |
| CVE-2014-9147 | Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/. | HIGH 7.5EPSS 11.4% | 16 October 2017 |
| CVE-2017-15363 | Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension before 1.7.1 for TYPO3, allows remote attackers to read arbitrary files via the file parameter. | HIGH 7.5EPSS 15.3% | 15 October 2017 |
| CVE-2017-12629 | Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. | CRITICAL 9.8EPSS 91.9% | 14 October 2017 |
| CVE-2017-8718 | The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to take control of an affected… | HIGH 7.8EPSS 24.0% | 13 October 2017 |
| CVE-2017-8717 | The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to take control of an affected… | HIGH 7.8EPSS 24.9% | 13 October 2017 |
| CVE-2017-11826 | Microsoft Office Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 81.2% | 13 October 2017 |
| CVE-2017-11825 | Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in the security context of the current user, due to how Microsoft Office handles files in memory, aka… | HIGH 7.8EPSS 22.9% | 13 October 2017 |
| CVE-2017-11819 | Microsoft Windows 7 SP1 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft browsers handle objects in memory, aka "Windows Shell Remote Code Execution Vulnerability". | HIGH 7.5EPSS 14.2% | 13 October 2017 |
| CVE-2017-11816 | The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an… | MEDIUM 5.5EPSS 20.0% | 13 October 2017 |
| CVE-2017-11815 | The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information… | MEDIUM 5.3EPSS 13.3% | 13 October 2017 |
| CVE-2017-11812 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting… | HIGH 7.5EPSS 47.3% | 13 October 2017 |
| CVE-2017-11811 | ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka… | HIGH 7.5EPSS 65.5% | 13 October 2017 |
| CVE-2017-11810 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the… | HIGH 7.5EPSS 54.8% | 13 October 2017 |
| CVE-2017-11809 | ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka… | HIGH 7.5EPSS 68.0% | 13 October 2017 |
| CVE-2017-11802 | ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka… | HIGH 7.5EPSS 69.2% | 13 October 2017 |
| CVE-2017-11799 | ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka… | HIGH 7.5EPSS 63.7% | 13 October 2017 |
| CVE-2017-11793 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the… | HIGH 7.5EPSS 49.6% | 13 October 2017 |
| CVE-2017-11781 | The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a denial of… | HIGH 7.5EPSS 14.4% | 13 October 2017 |
| CVE-2017-11779 | The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to… | HIGH 8.1EPSS 33.3% | 13 October 2017 |
| CVE-2017-11774 | Microsoft Office Outlook Security Feature Bypass Vulnerability | KEVHIGH 7.8EPSS 59.6% | 13 October 2017 |
| CVE-2017-11771 | The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code… | CRITICAL 9.8EPSS 64.1% | 13 October 2017 |
| CVE-2017-11769 | The Microsoft Windows TRIE component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles loading dll files, aka "TRIE Remote Code Execution Vulnerability". | HIGH 7.8EPSS 19.6% | 13 October 2017 |
| CVE-2017-11763 | The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution… | HIGH 8.8EPSS 17.1% | 13 October 2017 |
| CVE-2017-11762 | The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution… | HIGH 8.8EPSS 17.1% | 13 October 2017 |
| CVE-2017-15277 | If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette. | MEDIUM 6.5EPSS 19.2% | 12 October 2017 |
| CVE-2017-5791 | The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI. | CRITICAL 9.8EPSS 68.9% | 11 October 2017 |
| CVE-2017-5789 | HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified vectors. | CRITICAL 9.8EPSS 17.9% | 11 October 2017 |
| CVE-2017-0903 | RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. | CRITICAL 9.8EPSS 15.9% | 11 October 2017 |
| CVE-2013-6924 | Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php. | CRITICAL 9.8EPSS 15.2% | 11 October 2017 |
| CVE-2015-2856 | Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrary files via a .. | HIGH 7.5EPSS 56.6% | 10 October 2017 |
| CVE-2017-5637 | Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. | HIGH 7.5EPSS 73.1% | 10 October 2017 |
| CVE-2017-14980 | Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login. | CRITICAL 9.8EPSS 22.5% | 10 October 2017 |
| CVE-2014-0030 | The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. | CRITICAL 9.8EPSS 16.9% | 10 October 2017 |
| CVE-2015-2673 | The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbitrary code via… | HIGH 8.8EPSS 18.9% | 6 October 2017 |
| CVE-2017-14084 | A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulnerable installations. | HIGH 8.1EPSS 10.1% | 6 October 2017 |
| CVE-2017-12263 | A vulnerability in the web interface of Cisco License Manager software could allow an unauthenticated, remote attacker to download and view files within the application that should be restricted, aka Directory Traversal. | HIGH 7.5EPSS 11.5% | 5 October 2017 |
| CVE-2017-1000253 | Linux Kernel PIE Stack Buffer Corruption Vulnerability | KEVHIGH 7.8EPSS 10.7% | 5 October 2017 |
| CVE-2017-1000119 | October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server. | HIGH 7.2EPSS 61.3% | 5 October 2017 |
| CVE-2017-1000117 | A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. | HIGH 8.8EPSS 77.8% | 5 October 2017 |
| CVE-2017-1000112 | Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. | HIGH 7.0EPSS 20.8% | 5 October 2017 |
| CVE-2017-12149 | Red Hat JBoss Application Server Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 90.7% | 4 October 2017 |
| CVE-2017-14491 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | CRITICAL 9.8EPSS 84.9% | 4 October 2017 |
| CVE-2017-12617 | Apache Tomcat Remote Code Execution Vulnerability | KEVHIGH 8.1EPSS 100.0% | 4 October 2017 |
| CVE-2017-6090 | Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the… | HIGH 8.8EPSS 96.2% | 3 October 2017 |
| CVE-2017-14496 | Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request. | HIGH 7.5EPSS 66.3% | 3 October 2017 |
| CVE-2017-14495 | Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation. | HIGH 7.5EPSS 84.3% | 3 October 2017 |
| CVE-2017-14494 | dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests. | MEDIUM 5.9EPSS 67.5% | 3 October 2017 |
| CVE-2017-14493 | Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request. | CRITICAL 9.8EPSS 83.6% | 3 October 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.