SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,560 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%Updated 20 September 2026

17,391 results · page 180 of 348

CVESummaryPriorityPublished
CVE-2017-5638Apache Struts Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%11 March 2017
CVE-2017-6506In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution.CRITICAL 9.8EPSS 11.7%10 March 2017
CVE-2017-6465Remote Code Execution was discovered in FTPShell Client 6.53.CRITICAL 9.8EPSS 50.3%10 March 2017
CVE-2017-6527An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID…HIGH 7.5EPSS 56.6%9 March 2017
CVE-2017-6526An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected administrative web shell (cgi-bin/dna/sysAdmin.cgi POST requests).CRITICAL 9.8EPSS 57.4%9 March 2017
CVE-2017-6558iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the…CRITICAL 9.8EPSS 15.3%9 March 2017
CVE-2017-6548Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and…CRITICAL 9.8EPSS 21.3%9 March 2017
CVE-2017-5178If Tableau Server is used with Windows integrated security (Active Directory), the software is not vulnerable.CRITICAL 9.8EPSS 13.6%8 March 2017
CVE-2016-6255Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.HIGH 7.5EPSS 26.6%7 March 2017
CVE-2017-6416A buffer overflow vulnerability in SMTP connection verification leads to arbitrary code execution.CRITICAL 9.8EPSS 10.9%6 March 2017
CVE-2017-6334NETGEAR DGN2200 Devices OS Command Injection VulnerabilityKEVHIGH 8.8EPSS 72.6%6 March 2017
CVE-2016-7406Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.CRITICAL 9.8EPSS 10.5%3 March 2017
CVE-2016-6883MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher variant attack.MEDIUM 5.9EPSS 13.9%3 March 2017
CVE-2015-8813The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.HIGH 8.2EPSS 11.2%3 March 2017
CVE-2017-6403NetBackup Cloud Storage Service uses a hardcoded username and password.CRITICAL 9.8EPSS 26.7%2 March 2017
CVE-2017-5982Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.HIGH 7.5EPSS 77.6%28 February 2017
CVE-2017-6343The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of…HIGH 8.1EPSS 60.3%27 February 2017
CVE-2017-6342This allows sniffing sensitive information identified in CVE-2017-6341 without prior knowledge of the password.CRITICAL 9.8EPSS 12.8%27 February 2017
CVE-2017-0037Microsoft Edge and Internet Explorer Type Confusion VulnerabilityKEVHIGH 8.1EPSS 80.4%26 February 2017
CVE-2017-6206D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Information Disclosure attacks via unspecified vectors.HIGH 7.5EPSS 16.2%23 February 2017
CVE-2017-6187Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request.CRITICAL 9.8EPSS 33.1%22 February 2017
CVE-2017-6077NETGEAR DGN2200 Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 68.7%22 February 2017
CVE-2017-5586OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.CRITICAL 9.8EPSS 25.3%22 February 2017
CVE-2016-9683The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface.CRITICAL 9.8EPSS 11.6%22 February 2017
CVE-2016-9682The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface.CRITICAL 9.8EPSS 23.3%22 February 2017
CVE-2016-9269Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to run arbitrary…CRITICAL 9.9EPSS 13.4%21 February 2017
CVE-2017-0038gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to…MEDIUM 5.5EPSS 82.1%20 February 2017
CVE-2017-2370It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted app.HIGH 7.8EPSS 11.3%20 February 2017
CVE-2017-2361The issue involves the "Help Viewer" component, which allows XSS attacks via a crafted web site.MEDIUM 6.1EPSS 17.1%20 February 2017
CVE-2016-8652The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.MEDIUM 5.9EPSS 48.2%17 February 2017
CVE-2016-4314Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a ..MEDIUM 4.9EPSS 12.4%17 February 2017
CVE-2016-10134SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.CRITICAL 9.8EPSS 83.4%17 February 2017
CVE-2017-5991An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465.HIGH 7.5EPSS 15.2%15 February 2017
CVE-2017-2992Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header.HIGH 8.8EPSS 32.7%15 February 2017
CVE-2017-2988Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing garbage collection.HIGH 8.8EPSS 18.1%15 February 2017
CVE-2017-2986Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (FLV) codec.HIGH 8.8EPSS 30.9%15 February 2017
CVE-2017-2985Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class.HIGH 8.8EPSS 21.8%15 February 2017
CVE-2017-2984Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the h264 decoder routine.HIGH 8.8EPSS 18.2%15 February 2017
CVE-2017-5972The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets,…HIGH 7.5EPSS 23.9%14 February 2017
CVE-2017-5162Lack of authentication for remote service gives access to application set up and configuration.CRITICAL 9.8EPSS 12.6%13 February 2017
CVE-2016-9361An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A…CRITICAL 9.8EPSS 19.9%13 February 2017
CVE-2016-9343By sending malformed common industrial protocol (CIP) packet, an attacker may be able to overflow a stack-based buffer and execute code on the controller or initiate a nonrecoverable fault resulting in a denial of service.CRITICAL 10.0EPSS 10.5%13 February 2017
CVE-2016-6210sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference…MEDIUM 5.9EPSS 88.9%13 February 2017
CVE-2017-5941Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).CRITICAL 9.8EPSS 61.0%9 February 2017
CVE-2017-3807A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow.HIGH 8.8EPSS 14.8%9 February 2017
CVE-2016-9244A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory.HIGH 7.5EPSS 74.0%9 February 2017
CVE-2016-2148Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.CRITICAL 9.8EPSS 27.1%9 February 2017
CVE-2015-6024ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the DIA_IPADDRESS parameter.CRITICAL 9.8EPSS 26.1%9 February 2017
CVE-2015-6023ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intended access restrictions via a direct request.HIGH 7.3EPSS 11.0%9 February 2017
CVE-2016-6175Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.CRITICAL 9.8EPSS 19.7%7 February 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.