Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,540 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 167 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-14492 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request. | CRITICAL 9.8EPSS 93.3% | 3 October 2017 |
| CVE-2017-13704 | As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash. | HIGH 7.5EPSS 65.4% | 3 October 2017 |
| CVE-2017-14955 | Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report. | MEDIUM 5.9EPSS 12.1% | 2 October 2017 |
| CVE-2017-14942 | Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie. | CRITICAL 9.8EPSS 60.9% | 30 September 2017 |
| CVE-2017-14867 | Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell… | HIGH 8.8EPSS 36.0% | 29 September 2017 |
| CVE-2017-12240 | Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 13.8% | 29 September 2017 |
| CVE-2017-14849 | Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules. | HIGH 7.5EPSS 54.4% | 28 September 2017 |
| CVE-2015-8249 | The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter. | CRITICAL 9.8EPSS 73.6% | 28 September 2017 |
| CVE-2015-4667 | Multiple hardcoded credentials in Xsuite 2.x. | CRITICAL 9.8EPSS 11.1% | 25 September 2017 |
| CVE-2017-14719 | Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components. | HIGH 7.5EPSS 12.4% | 23 September 2017 |
| CVE-2017-14627 | Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside… | HIGH 7.8EPSS 19.9% | 23 September 2017 |
| CVE-2017-14706 | DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservices/download/index.php, and then reading the iToken field in the reply. | CRITICAL 9.8EPSS 28.2% | 22 September 2017 |
| CVE-2017-14081 | Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations. | HIGH 8.8EPSS 16.6% | 22 September 2017 |
| CVE-2017-14079 | Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations. | HIGH 8.8EPSS 10.9% | 22 September 2017 |
| CVE-2017-14078 | SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations. | CRITICAL 9.8EPSS 50.2% | 22 September 2017 |
| CVE-2017-11395 | Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authenticated access to execute arbitrary code on vulnerable installations. | HIGH 8.8EPSS 14.1% | 22 September 2017 |
| CVE-2017-12929 | Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. | HIGH 8.8EPSS 10.1% | 21 September 2017 |
| CVE-2015-1187 | D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 82.9% | 21 September 2017 |
| CVE-2015-2826 | WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information. | MEDIUM 5.3EPSS 12.8% | 20 September 2017 |
| CVE-2017-12611 | In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack. | CRITICAL 9.8EPSS 87.1% | 20 September 2017 |
| CVE-2017-7924 | An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA, 1763-L16BBB, and 1763-L16DWD. | HIGH 7.5EPSS 22.2% | 20 September 2017 |
| CVE-2015-4074 | Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. | HIGH 7.5EPSS 56.5% | 20 September 2017 |
| CVE-2017-8770 | There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesystem on the device via a crafted getpage parameter. | HIGH 7.5EPSS 10.3% | 20 September 2017 |
| CVE-2014-8686 | CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available. | CRITICAL 9.8EPSS 37.2% | 19 September 2017 |
| CVE-2014-8684 | CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to… | CRITICAL 9.8EPSS 71.7% | 19 September 2017 |
| CVE-2017-6315 | Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx. | CRITICAL 9.8EPSS 16.6% | 19 September 2017 |
| CVE-2017-10784 | The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted… | HIGH 8.8EPSS 16.4% | 19 September 2017 |
| CVE-2017-14143 | The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to bypass an intended protection mechanism and consequently conduct PHP object injection attacks and… | CRITICAL 9.8EPSS 77.4% | 19 September 2017 |
| CVE-2014-9618 | The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL. | CRITICAL 9.8EPSS 72.7% | 19 September 2017 |
| CVE-2014-9611 | Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/index.php. | CRITICAL 9.8EPSS 12.7% | 19 September 2017 |
| CVE-2017-12616 | When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request. | HIGH 7.5EPSS 70.1% | 19 September 2017 |
| CVE-2017-12615 | Apache Tomcat on Windows Remote Code Execution Vulnerability | KEVHIGH 8.1EPSS 99.6% | 19 September 2017 |
| CVE-2017-9798 | Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. | HIGH 7.5EPSS 95.0% | 18 September 2017 |
| CVE-2017-14244 | An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and… | CRITICAL 9.8EPSS 17.1% | 17 September 2017 |
| CVE-2017-14243 | An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administrative settings and obtain cleartext credentials from HTML source, as demonstrated by info.cgi,… | CRITICAL 9.8EPSS 14.8% | 17 September 2017 |
| CVE-2014-9463 | functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php. | HIGH 8.8EPSS 14.8% | 15 September 2017 |
| CVE-2017-9805 | Apache Struts Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.1EPSS 99.4% | 15 September 2017 |
| CVE-2017-0785 | A information disclosure vulnerability in the Android system (bluetooth). | MEDIUM 6.5EPSS 12.4% | 14 September 2017 |
| CVE-2017-0781 | A remote code execution vulnerability in the Android system (bluetooth). | HIGH 8.8EPSS 22.9% | 14 September 2017 |
| CVE-2017-13067 | QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. | CRITICAL 9.8EPSS 16.7% | 14 September 2017 |
| CVE-2017-1002008 | Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges. | CRITICAL 9.8EPSS 16.9% | 14 September 2017 |
| CVE-2017-1002003 | Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com. | CRITICAL 9.8EPSS 12.3% | 14 September 2017 |
| CVE-2017-1002002 | Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/ | CRITICAL 9.8EPSS 12.6% | 14 September 2017 |
| CVE-2017-1002001 | Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com. | CRITICAL 9.8EPSS 11.1% | 14 September 2017 |
| CVE-2017-1002000 | Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content. | CRITICAL 9.8EPSS 27.4% | 14 September 2017 |
| CVE-2017-8759 | Microsoft .NET Framework Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 88.7% | 13 September 2017 |
| CVE-2017-8757 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way Microsoft Edge handles objects in memory, aka "Microsoft Edge Remote… | HIGH 7.5EPSS 16.4% | 13 September 2017 |
| CVE-2017-8755 | Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the scripting engine handles objects in memory in Microsoft Edge, aka… | HIGH 7.5EPSS 71.3% | 13 September 2017 |
| CVE-2017-8751 | Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". | HIGH 7.5EPSS 50.4% | 13 September 2017 |
| CVE-2017-8749 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the… | HIGH 7.5EPSS 10.8% | 13 September 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.