Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,554 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 20 September 2026
17,386 results · page 176 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-6554 | pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACT_NEWFILESENT action. | HIGH 7.2EPSS 15.6% | 14 April 2017 |
| CVE-2016-5312 | Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. | MEDIUM 6.5EPSS 53.7% | 14 April 2017 |
| CVE-2016-1713 | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a… | HIGH 7.3EPSS 16.6% | 14 April 2017 |
| CVE-2015-6568 | Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for… | HIGH 8.8EPSS 10.5% | 14 April 2017 |
| CVE-2015-6567 | Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. | HIGH 8.8EPSS 10.8% | 14 April 2017 |
| CVE-2017-7456 | Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials. | HIGH 7.5EPSS 29.3% | 14 April 2017 |
| CVE-2017-7455 | Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control. | HIGH 7.5EPSS 15.9% | 14 April 2017 |
| CVE-2016-4970 | handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop). | HIGH 7.5EPSS 11.3% | 13 April 2017 |
| CVE-2016-2555 | SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php. | CRITICAL 9.8EPSS 79.6% | 13 April 2017 |
| CVE-2016-6808 | Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42. | CRITICAL 9.8EPSS 22.7% | 12 April 2017 |
| CVE-2017-7722 | By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell. | CRITICAL 10.0EPSS 12.7% | 12 April 2017 |
| CVE-2017-3064 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline. | HIGH 7.8EPSS 13.5% | 12 April 2017 |
| CVE-2017-3061 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. | CRITICAL 9.8EPSS 24.7% | 12 April 2017 |
| CVE-2017-3055 | Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in JPEG 2000 parsing of the fragment list tag. | HIGH 7.8EPSS 14.5% | 12 April 2017 |
| CVE-2017-3048 | Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in the image conversion engine, related to internal scan line representation in TIFF files. | HIGH 7.8EPSS 13.7% | 12 April 2017 |
| CVE-2017-3044 | Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JPEG 2000 engine, related to image scaling. | HIGH 7.8EPSS 20.4% | 12 April 2017 |
| CVE-2017-3042 | Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in image conversion, related to parsing offsets in TIFF files. | HIGH 7.8EPSS 14.5% | 12 April 2017 |
| CVE-2017-3022 | Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability when parsing the header of a JPEG 2000 file. | LOW 3.3EPSS 11.8% | 12 April 2017 |
| CVE-2017-3006 | Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creative Cloud desktop applications. | HIGH 8.8EPSS 10.8% | 12 April 2017 |
| CVE-2017-0211 | An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE… | MEDIUM 5.5EPSS 14.0% | 12 April 2017 |
| CVE-2017-0210 | Microsoft Internet Explorer Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 22.3% | 12 April 2017 |
| CVE-2017-0208 | An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memory. | MEDIUM 4.3EPSS 15.3% | 12 April 2017 |
| CVE-2017-0207 | Microsoft Outlook for Mac 2011 allows remote attackers to spoof web content via a crafted email with specific HTML tags, aka "Microsoft Browser Spoofing Vulnerability." | MEDIUM 6.5EPSS 10.5% | 12 April 2017 |
| CVE-2017-0205 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. | HIGH 7.5EPSS 23.6% | 12 April 2017 |
| CVE-2017-0204 | Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass… | MEDIUM 5.5EPSS 19.0% | 12 April 2017 |
| CVE-2017-0202 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. | HIGH 7.5EPSS 45.6% | 12 April 2017 |
| CVE-2017-0201 | A remote code execution vulnerability exists in Internet Explorer in the way that the JScript and VBScript engines render when handling objects in memory. | HIGH 7.5EPSS 13.9% | 12 April 2017 |
| CVE-2017-0200 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. | HIGH 7.5EPSS 13.8% | 12 April 2017 |
| CVE-2017-0199 | Microsoft Office and WordPad Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 99.9% | 12 April 2017 |
| CVE-2017-0197 | Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office DLL Loading Vulnerability." | HIGH 7.8EPSS 19.1% | 12 April 2017 |
| CVE-2017-0194 | Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability." | MEDIUM 5.5EPSS 25.5% | 12 April 2017 |
| CVE-2017-0160 | Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability." | HIGH 7.8EPSS 17.8% | 12 April 2017 |
| CVE-2017-0158 | An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption… | HIGH 7.5EPSS 12.8% | 12 April 2017 |
| CVE-2017-0106 | Microsoft Excel 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office… | HIGH 7.8EPSS 28.4% | 12 April 2017 |
| CVE-2017-0093 | A remote code execution vulnerability in Microsoft Edge exists in the way that the Scripting Engine renders when handling objects in memory in Microsoft browsers. | HIGH 7.5EPSS 13.7% | 12 April 2017 |
| CVE-2017-7588 | On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. | CRITICAL 9.8EPSS 33.6% | 12 April 2017 |
| CVE-2016-7552 | On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. | CRITICAL 9.8EPSS 93.2% | 12 April 2017 |
| CVE-2016-7547 | A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface. | CRITICAL 9.8EPSS 92.7% | 12 April 2017 |
| CVE-2016-1908 | The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding… | CRITICAL 9.8EPSS 13.7% | 11 April 2017 |
| CVE-2017-7462 | Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory. | CRITICAL 9.8EPSS 13.0% | 11 April 2017 |
| CVE-2017-7461 | Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM.1.6.16.05 allows remote attackers to read arbitrary files via a request to a vendor-supplied CGI script that is used to read HTML… | MEDIUM 4.9EPSS 10.7% | 11 April 2017 |
| CVE-2017-7185 | Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash)… | HIGH 7.5EPSS 12.3% | 10 April 2017 |
| CVE-2017-5983 | The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized… | CRITICAL 9.8EPSS 16.4% | 10 April 2017 |
| CVE-2017-6190 | Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. | HIGH 7.5EPSS 18.4% | 10 April 2017 |
| CVE-2017-6019 | An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. | HIGH 7.5EPSS 36.9% | 7 April 2017 |
| CVE-2017-0561 | A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. | CRITICAL 9.8EPSS 29.8% | 7 April 2017 |
| CVE-2017-7581 | SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed. | CRITICAL 9.8EPSS 48.4% | 7 April 2017 |
| CVE-2017-7577 | XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request. | CRITICAL 9.8EPSS 29.0% | 7 April 2017 |
| CVE-2016-8735 | Apache Tomcat Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 90.3% | 6 April 2017 |
| CVE-2017-6884 | Zyxel EMG2926 Routers Command Injection Vulnerability | KEVHIGH 8.8EPSS 36.5% | 6 April 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.