Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,554 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 20 September 2026
17,386 results · page 175 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-0290 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and… | HIGH 7.8EPSS 81.4% | 9 May 2017 |
| CVE-2017-7927 | The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password. | HIGH 7.3EPSS 36.7% | 6 May 2017 |
| CVE-2017-7925 | The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information. | CRITICAL 9.8EPSS 51.4% | 6 May 2017 |
| CVE-2017-7921 | Hikvision Multiple Products Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 6 May 2017 |
| CVE-2017-8303 | An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter. | CRITICAL 9.8EPSS 24.2% | 5 May 2017 |
| CVE-2016-7055 | This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker's direct choice. | MEDIUM 5.9EPSS 14.2% | 4 May 2017 |
| CVE-2017-3733 | During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). | HIGH 7.5EPSS 12.9% | 4 May 2017 |
| CVE-2017-3732 | The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. | MEDIUM 5.9EPSS 15.4% | 4 May 2017 |
| CVE-2017-3731 | If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. | HIGH 7.5EPSS 57.6% | 4 May 2017 |
| CVE-2017-3730 | In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. | HIGH 7.5EPSS 55.3% | 4 May 2017 |
| CVE-2016-7054 | In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. | HIGH 7.5EPSS 32.4% | 4 May 2017 |
| CVE-2016-7053 | In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference. | HIGH 7.5EPSS 21.7% | 4 May 2017 |
| CVE-2017-8779 | rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory… | HIGH 7.5EPSS 81.2% | 4 May 2017 |
| CVE-2017-8295 | WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this… | MEDIUM 5.9EPSS 26.7% | 4 May 2017 |
| CVE-2016-10367 | In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch), an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP… | HIGH 7.5EPSS 16.1% | 3 May 2017 |
| CVE-2017-5689 | Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability | KEVCRITICAL 9.8EPSS 92.2% | 2 May 2017 |
| CVE-2016-5810 | upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors. | MEDIUM 4.9EPSS 15.4% | 2 May 2017 |
| CVE-2015-8257 | The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4)… | HIGH 8.8EPSS 17.7% | 2 May 2017 |
| CVE-2017-7981 | Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. | HIGH 8.8EPSS 16.1% | 29 April 2017 |
| CVE-2017-6553 | Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon. | CRITICAL 9.8EPSS 42.3% | 29 April 2017 |
| CVE-2017-7895 | The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted… | CRITICAL 9.8EPSS 10.8% | 28 April 2017 |
| CVE-2017-5135 | Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. | CRITICAL 9.1EPSS 17.5% | 27 April 2017 |
| CVE-2017-3066 | Adobe ColdFusion Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 90.6% | 27 April 2017 |
| CVE-2017-8291 | Artifex Ghostscript Type Confusion Vulnerability | KEVHIGH 7.8EPSS 97.0% | 27 April 2017 |
| CVE-2017-8225 | An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI. | CRITICAL 9.8EPSS 35.4% | 25 April 2017 |
| CVE-2017-8220 | TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placing shell commands in a "host=" line within HTTP POST data. | CRITICAL 9.9EPSS 36.6% | 25 April 2017 |
| CVE-2017-5040 | V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neutering check, which allowed a remote attacker to read values in memory via a crafted HTML page. | MEDIUM 4.3EPSS 22.3% | 24 April 2017 |
| CVE-2017-5030 | Google Chromium V8 Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 41.7% | 24 April 2017 |
| CVE-2017-3623 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). | CRITICAL 10.0EPSS 22.0% | 24 April 2017 |
| CVE-2017-3599 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). | HIGH 7.5EPSS 89.9% | 24 April 2017 |
| CVE-2017-3549 | Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). | CRITICAL 9.1EPSS 15.8% | 24 April 2017 |
| CVE-2017-3548 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). | MEDIUM 6.5EPSS 50.8% | 24 April 2017 |
| CVE-2017-3528 | Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc.)). | MEDIUM 5.4EPSS 14.6% | 24 April 2017 |
| CVE-2017-3506 | Oracle WebLogic Server OS Command Injection Vulnerability | KEVHIGH 7.4EPSS 96.3% | 24 April 2017 |
| CVE-2015-7247 | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration backup, which allows remote attackers to obtain… | CRITICAL 9.8EPSS 10.2% | 24 April 2017 |
| CVE-2015-7246 | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative access. | CRITICAL 9.8EPSS 14.3% | 24 April 2017 |
| CVE-2015-7245 | Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. | HIGH 7.5EPSS 45.5% | 24 April 2017 |
| CVE-2016-3109 | The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code. | CRITICAL 9.8EPSS 28.1% | 21 April 2017 |
| CVE-2016-1561 | ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image. | HIGH 7.5EPSS 74.3% | 21 April 2017 |
| CVE-2016-1560 | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH… | CRITICAL 9.8EPSS 72.3% | 21 April 2017 |
| CVE-2017-8051 | Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands. | CRITICAL 9.8EPSS 16.5% | 21 April 2017 |
| CVE-2016-1555 | NETGEAR Multiple WAP Devices Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 21 April 2017 |
| CVE-2017-7692 | SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mishandled in a popen call. | HIGH 8.8EPSS 32.2% | 20 April 2017 |
| CVE-2017-5653 | JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers. | MEDIUM 5.3EPSS 11.2% | 18 April 2017 |
| CVE-2017-5645 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | CRITICAL 9.8EPSS 89.8% | 17 April 2017 |
| CVE-2017-5648 | While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. | CRITICAL 9.1EPSS 13.2% | 17 April 2017 |
| CVE-2017-5647 | A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file… | HIGH 7.5EPSS 16.8% | 17 April 2017 |
| CVE-2015-8256 | Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras. | MEDIUM 6.1EPSS 50.8% | 17 April 2017 |
| CVE-2017-7615 | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php. | HIGH 8.8EPSS 90.9% | 16 April 2017 |
| CVE-2017-7696 | SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in the width and height parameters to otp_logon_ui_resources/qr, aka SAP Security Note 2389042. | HIGH 7.5EPSS 36.2% | 14 April 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.