SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,554 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 20 September 2026

17,386 results · page 177 of 348

CVESummaryPriorityPublished
CVE-2016-9091Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability.HIGH 7.2EPSS 10.1%5 April 2017
CVE-2016-3740Heap-based buffer overflow in the CreateFXPDFConvertor function in ConvertToPdf_x86.dll in Foxit Reader 7.3.4.311 allows remote attackers to execute arbitrary code via a large SamplesPerPixel value in a crafted TIFF image that is mishandled during PDF…HIGH 7.8EPSS 15.4%4 April 2017
CVE-2017-7413In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has PGP features enabled in their preferences, and attempts to encrypt an…HIGH 8.8EPSS 40.4%4 April 2017
CVE-2016-10229udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.CRITICAL 9.8EPSS 12.8%4 April 2017
CVE-2017-7397BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7).HIGH 7.5EPSS 11.1%3 April 2017
CVE-2014-1677Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.HIGH 7.5EPSS 17.7%3 April 2017
CVE-2017-1001000The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a…HIGH 7.5EPSS 84.9%3 April 2017
CVE-2015-4624Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.HIGH 7.5EPSS 37.0%31 March 2017
CVE-2014-3931Multi-Router Looking Glass (MRLG) Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 29.0%31 March 2017
CVE-2017-7309A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted 'config_option' parameter.MEDIUM 4.8EPSS 57.3%31 March 2017
CVE-2017-6182In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.CRITICAL 9.8EPSS 16.7%30 March 2017
CVE-2017-7310A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary…HIGH 7.8EPSS 53.7%29 March 2017
CVE-2017-7308The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or…HIGH 7.8EPSS 17.8%29 March 2017
CVE-2017-7285A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP…HIGH 7.5EPSS 19.3%29 March 2017
CVE-2016-8749Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.CRITICAL 9.8EPSS 10.6%28 March 2017
CVE-2017-6542The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded…CRITICAL 9.8EPSS 21.8%27 March 2017
CVE-2017-5850httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Range header.HIGH 7.5EPSS 17.2%27 March 2017
CVE-2017-7269Microsoft Windows Server Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 99.8%27 March 2017
CVE-2017-2641In Moodle 2.x and 3.x, SQL injection can occur via user preferences.CRITICAL 9.8EPSS 14.5%26 March 2017
CVE-2017-7240The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and is prone to a directory traversal attack; therefore, an unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in…HIGH 7.5EPSS 17.4%24 March 2017
CVE-2017-5334Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy…CRITICAL 9.8EPSS 32.8%24 March 2017
CVE-2017-5869Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a ..HIGH 8.8EPSS 34.6%24 March 2017
CVE-2015-8556Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.CRITICAL 10.0EPSS 13.4%24 March 2017
CVE-2017-6517Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.CRITICAL 9.8EPSS 46.3%23 March 2017
CVE-2014-8731PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.CRITICAL 9.8EPSS 11.8%23 March 2017
CVE-2014-7279The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.CRITICAL 9.8EPSS 11.7%23 March 2017
CVE-2017-6361QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.CRITICAL 9.8EPSS 56.8%23 March 2017
CVE-2017-6360QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.CRITICAL 9.8EPSS 66.1%23 March 2017
CVE-2017-6359QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.CRITICAL 9.8EPSS 26.9%23 March 2017
CVE-2017-6972AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.CRITICAL 9.8EPSS 14.6%22 March 2017
CVE-2017-7230A buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrary code via a GET request.CRITICAL 9.8EPSS 13.8%22 March 2017
CVE-2017-6971AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code, aka…HIGH 8.8EPSS 16.2%22 March 2017
CVE-2016-6816This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response.HIGH 7.1EPSS 39.6%20 March 2017
CVE-2017-5930The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.LOW 2.7EPSS 15.0%20 March 2017
CVE-2017-3881Cisco IOS and IOS XE Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.0%17 March 2017
CVE-2017-6880Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long MLST command.CRITICAL 9.8EPSS 14.3%17 March 2017
CVE-2015-3884Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pages in qdPM 8.3 allows remote attackers to execute arbitrary code by uploading a file with an executable…HIGH 8.8EPSS 14.4%17 March 2017
CVE-2014-8722GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>.xml.bak, (3) data/other/authorization.xml, or (4) data/other/appid.xml.HIGH 7.5EPSS 14.4%17 March 2017
CVE-2017-0154Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet…MEDIUM 4.4EPSS 10.6%17 March 2017
CVE-2017-0151A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.HIGH 7.5EPSS 15.2%17 March 2017
CVE-2017-0150A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.HIGH 7.5EPSS 15.2%17 March 2017
CVE-2017-0149Microsoft Internet Explorer Memory Corruption VulnerabilityKEVHIGH 8.8EPSS 29.2%17 March 2017
CVE-2017-0148Microsoft SMBv1 Server Remote Code Execution VulnerabilityKEVHIGH 8.1EPSS 99.4%17 March 2017
CVE-2017-0147Microsoft Windows SMBv1 Information Disclosure VulnerabilityKEVHIGH 7.5EPSS 99.7%17 March 2017
CVE-2017-0146Microsoft Windows SMB Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 89.9%17 March 2017
CVE-2017-0145Microsoft SMBv1 Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 89.8%17 March 2017
CVE-2017-0144Microsoft SMBv1 Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 99.2%17 March 2017
CVE-2017-0143Microsoft Windows Server Message Block (SMBv1) Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 93.3%17 March 2017
CVE-2017-0141A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.HIGH 7.5EPSS 48.2%17 March 2017
CVE-2017-0140Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and…MEDIUM 4.2EPSS 28.5%17 March 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.