Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,540 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 169 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-9312 | Unrestricted File Upload vulnerability in Photo Gallery 1.2.5. | HIGH 8.8EPSS 45.4% | 28 August 2017 |
| CVE-2014-5302 | Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code. | HIGH 8.8EPSS 10.7% | 28 August 2017 |
| CVE-2014-5301 | Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. | HIGH 8.8EPSS 78.4% | 28 August 2017 |
| CVE-2015-4181 | Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. | HIGH 7.5EPSS 11.6% | 25 August 2017 |
| CVE-2015-1395 | Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. | HIGH 7.5EPSS 11.3% | 25 August 2017 |
| CVE-2014-7859 | Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-326 before 2.10 build 03, and DNS-327L before 1.04b01 allows remote attackers to execute arbitrary code by crafting… | CRITICAL 9.8EPSS 20.9% | 25 August 2017 |
| CVE-2014-7858 | The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username cookie parameter to an arbitrary string. | CRITICAL 9.8EPSS 15.2% | 25 August 2017 |
| CVE-2014-7857 | D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass authentication and log in with administrator… | CRITICAL 9.8EPSS 15.2% | 25 August 2017 |
| CVE-2015-8352 | Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. | CRITICAL 9.8EPSS 15.6% | 24 August 2017 |
| CVE-2015-7258 | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection. | HIGH 8.8EPSS 12.9% | 24 August 2017 |
| CVE-2017-9506 | The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server… | MEDIUM 6.1EPSS 71.6% | 23 August 2017 |
| CVE-2017-11357 | Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability | KEVCRITICAL 9.8EPSS 77.7% | 23 August 2017 |
| CVE-2017-11317 | Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability | KEVCRITICAL 9.8EPSS 84.2% | 23 August 2017 |
| CVE-2017-12965 | Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter. | CRITICAL 9.8EPSS 15.7% | 23 August 2017 |
| CVE-2017-11610 | The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups. | HIGH 8.8EPSS 87.4% | 23 August 2017 |
| CVE-2017-12787 | A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug… | CRITICAL 9.8EPSS 24.6% | 22 August 2017 |
| CVE-2017-12786 | Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when… | CRITICAL 9.8EPSS 25.3% | 22 August 2017 |
| CVE-2017-12785 | The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, is prone to a buffer overflow in the "show log cli" command. | CRITICAL 9.8EPSS 16.0% | 22 August 2017 |
| CVE-2015-2857 | Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter. | CRITICAL 9.8EPSS 84.2% | 22 August 2017 |
| CVE-2017-10661 | Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel… | HIGH 7.0EPSS 13.4% | 19 August 2017 |
| CVE-2015-7944 | The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2, when used in SSL mode, allows remote… | HIGH 7.5EPSS 14.2% | 18 August 2017 |
| CVE-2017-12943 | D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, as demonstrated by discovering the admin password. | CRITICAL 9.8EPSS 39.2% | 18 August 2017 |
| CVE-2017-12936 | The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting. | HIGH 8.8EPSS 25.1% | 18 August 2017 |
| CVE-2017-11661 | The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file. | HIGH 7.5EPSS 10.8% | 17 August 2017 |
| CVE-2017-7546 | PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password. | CRITICAL 9.8EPSS 61.6% | 16 August 2017 |
| CVE-2017-9800 | A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. | CRITICAL 9.8EPSS 18.9% | 11 August 2017 |
| CVE-2017-6327 | Symantec Messaging Gateway Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 35.9% | 11 August 2017 |
| CVE-2017-3123 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format… | HIGH 8.8EPSS 14.4% | 11 August 2017 |
| CVE-2017-3117 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the plugin that handles links within the PDF. | HIGH 8.8EPSS 18.9% | 11 August 2017 |
| CVE-2017-3106 | Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. | HIGH 8.8EPSS 22.3% | 11 August 2017 |
| CVE-2017-11272 | Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability. | HIGH 7.5EPSS 13.0% | 11 August 2017 |
| CVE-2017-11263 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the internal data structure manipulation related to document encoding. | HIGH 8.8EPSS 26.1% | 11 August 2017 |
| CVE-2017-11259 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format… | HIGH 8.8EPSS 12.8% | 11 August 2017 |
| CVE-2017-11244 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format… | MEDIUM 6.5EPSS 10.1% | 11 August 2017 |
| CVE-2017-11241 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF)… | HIGH 8.8EPSS 14.7% | 11 August 2017 |
| CVE-2017-11230 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the JPEG 2000 engine. | MEDIUM 6.5EPSS 10.1% | 11 August 2017 |
| CVE-2017-11220 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in an internal data structure. | HIGH 8.8EPSS 14.7% | 11 August 2017 |
| CVE-2017-11211 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the JPEG parser. | HIGH 8.8EPSS 27.1% | 11 August 2017 |
| CVE-2017-11210 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the font parsing, where the font is embedded in the XML Paper… | MEDIUM 6.5EPSS 11.5% | 11 August 2017 |
| CVE-2017-11209 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability that occurs when reading a JPEG file embedded within XML Paper… | MEDIUM 6.5EPSS 11.5% | 11 August 2017 |
| CVE-2017-7675 | The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. | HIGH 7.5EPSS 10.1% | 11 August 2017 |
| CVE-2017-8658 | A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | CRITICAL 9.8EPSS 20.1% | 11 August 2017 |
| CVE-2016-8745 | Sharing a Processor can result in information leakage between requests including, not not limited to, session ID and the response body. | HIGH 7.5EPSS 16.0% | 10 August 2017 |
| CVE-2017-8518 | Microsoft Edge allows a remote code execution vulnerability due to the way it accesses objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | HIGH 7.5EPSS 10.2% | 10 August 2017 |
| CVE-2016-5018 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web… | CRITICAL 9.1EPSS 10.3% | 10 August 2017 |
| CVE-2015-0786 | Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary code via unspecified vectors. | CRITICAL 9.8EPSS 23.6% | 9 August 2017 |
| CVE-2017-8691 | Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow an attacker to execute code remotely on a target system when the Windows font library fails to properly handle specially crafted embedded fonts, aka "Express Compressed Fonts Remote Code… | HIGH 8.8EPSS 19.8% | 8 August 2017 |
| CVE-2017-8671 | Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling… | HIGH 7.5EPSS 69.3% | 8 August 2017 |
| CVE-2017-8670 | Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in… | HIGH 7.5EPSS 68.7% | 8 August 2017 |
| CVE-2017-8657 | Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling… | HIGH 7.5EPSS 54.6% | 8 August 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.