SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,554 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 20 September 2026

17,386 results · page 176 of 348

CVESummaryPriorityPublished
CVE-2017-6554pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACT_NEWFILESENT action.HIGH 7.2EPSS 15.6%14 April 2017
CVE-2016-5312Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a ..MEDIUM 6.5EPSS 53.7%14 April 2017
CVE-2016-1713Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a…HIGH 7.3EPSS 16.6%14 April 2017
CVE-2015-6568Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for…HIGH 8.8EPSS 10.5%14 April 2017
CVE-2015-6567Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly.HIGH 8.8EPSS 10.8%14 April 2017
CVE-2017-7456Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.HIGH 7.5EPSS 29.3%14 April 2017
CVE-2017-7455Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.HIGH 7.5EPSS 15.9%14 April 2017
CVE-2016-4970handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).HIGH 7.5EPSS 11.3%13 April 2017
CVE-2016-2555SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.CRITICAL 9.8EPSS 79.6%13 April 2017
CVE-2016-6808Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.CRITICAL 9.8EPSS 22.7%12 April 2017
CVE-2017-7722By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.CRITICAL 10.0EPSS 12.7%12 April 2017
CVE-2017-3064Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline.HIGH 7.8EPSS 13.5%12 April 2017
CVE-2017-3061Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser.CRITICAL 9.8EPSS 24.7%12 April 2017
CVE-2017-3055Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in JPEG 2000 parsing of the fragment list tag.HIGH 7.8EPSS 14.5%12 April 2017
CVE-2017-3048Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in the image conversion engine, related to internal scan line representation in TIFF files.HIGH 7.8EPSS 13.7%12 April 2017
CVE-2017-3044Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JPEG 2000 engine, related to image scaling.HIGH 7.8EPSS 20.4%12 April 2017
CVE-2017-3042Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in image conversion, related to parsing offsets in TIFF files.HIGH 7.8EPSS 14.5%12 April 2017
CVE-2017-3022Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability when parsing the header of a JPEG 2000 file.LOW 3.3EPSS 11.8%12 April 2017
CVE-2017-3006Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creative Cloud desktop applications.HIGH 8.8EPSS 10.8%12 April 2017
CVE-2017-0211An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE…MEDIUM 5.5EPSS 14.0%12 April 2017
CVE-2017-0210Microsoft Internet Explorer Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 22.3%12 April 2017
CVE-2017-0208An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memory.MEDIUM 4.3EPSS 15.3%12 April 2017
CVE-2017-0207Microsoft Outlook for Mac 2011 allows remote attackers to spoof web content via a crafted email with specific HTML tags, aka "Microsoft Browser Spoofing Vulnerability."MEDIUM 6.5EPSS 10.5%12 April 2017
CVE-2017-0205A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory.HIGH 7.5EPSS 23.6%12 April 2017
CVE-2017-0204Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass…MEDIUM 5.5EPSS 19.0%12 April 2017
CVE-2017-0202A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.HIGH 7.5EPSS 45.6%12 April 2017
CVE-2017-0201A remote code execution vulnerability exists in Internet Explorer in the way that the JScript and VBScript engines render when handling objects in memory.HIGH 7.5EPSS 13.9%12 April 2017
CVE-2017-0200A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory.HIGH 7.5EPSS 13.8%12 April 2017
CVE-2017-0199Microsoft Office and WordPad Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 99.9%12 April 2017
CVE-2017-0197Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office DLL Loading Vulnerability."HIGH 7.8EPSS 19.1%12 April 2017
CVE-2017-0194Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."MEDIUM 5.5EPSS 25.5%12 April 2017
CVE-2017-0160Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."HIGH 7.8EPSS 17.8%12 April 2017
CVE-2017-0158An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption…HIGH 7.5EPSS 12.8%12 April 2017
CVE-2017-0106Microsoft Excel 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office…HIGH 7.8EPSS 28.4%12 April 2017
CVE-2017-0093A remote code execution vulnerability in Microsoft Edge exists in the way that the Scripting Engine renders when handling objects in memory in Microsoft browsers.HIGH 7.5EPSS 13.7%12 April 2017
CVE-2017-7588On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt.CRITICAL 9.8EPSS 33.6%12 April 2017
CVE-2016-7552On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root.CRITICAL 9.8EPSS 93.2%12 April 2017
CVE-2016-7547A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface.CRITICAL 9.8EPSS 92.7%12 April 2017
CVE-2016-1908The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding…CRITICAL 9.8EPSS 13.7%11 April 2017
CVE-2017-7462Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.CRITICAL 9.8EPSS 13.0%11 April 2017
CVE-2017-7461Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM.1.6.16.05 allows remote attackers to read arbitrary files via a request to a vendor-supplied CGI script that is used to read HTML…MEDIUM 4.9EPSS 10.7%11 April 2017
CVE-2017-7185Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash)…HIGH 7.5EPSS 12.3%10 April 2017
CVE-2017-5983The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized…CRITICAL 9.8EPSS 16.4%10 April 2017
CVE-2017-6190Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a ..HIGH 7.5EPSS 18.4%10 April 2017
CVE-2017-6019An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830.HIGH 7.5EPSS 36.9%7 April 2017
CVE-2017-0561A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC.CRITICAL 9.8EPSS 29.8%7 April 2017
CVE-2017-7581SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.CRITICAL 9.8EPSS 48.4%7 April 2017
CVE-2017-7577XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.CRITICAL 9.8EPSS 29.0%7 April 2017
CVE-2016-8735Apache Tomcat Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 90.3%6 April 2017
CVE-2017-6884Zyxel EMG2926 Routers Command Injection VulnerabilityKEVHIGH 8.8EPSS 36.5%6 April 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.