Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,560 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%Updated 20 September 2026
17,391 results · page 180 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-5638 | Apache Struts Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 11 March 2017 |
| CVE-2017-6506 | In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. | CRITICAL 9.8EPSS 11.7% | 10 March 2017 |
| CVE-2017-6465 | Remote Code Execution was discovered in FTPShell Client 6.53. | CRITICAL 9.8EPSS 50.3% | 10 March 2017 |
| CVE-2017-6527 | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID… | HIGH 7.5EPSS 56.6% | 9 March 2017 |
| CVE-2017-6526 | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected administrative web shell (cgi-bin/dna/sysAdmin.cgi POST requests). | CRITICAL 9.8EPSS 57.4% | 9 March 2017 |
| CVE-2017-6558 | iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the… | CRITICAL 9.8EPSS 15.3% | 9 March 2017 |
| CVE-2017-6548 | Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and… | CRITICAL 9.8EPSS 21.3% | 9 March 2017 |
| CVE-2017-5178 | If Tableau Server is used with Windows integrated security (Active Directory), the software is not vulnerable. | CRITICAL 9.8EPSS 13.6% | 8 March 2017 |
| CVE-2016-6255 | Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler. | HIGH 7.5EPSS 26.6% | 7 March 2017 |
| CVE-2017-6416 | A buffer overflow vulnerability in SMTP connection verification leads to arbitrary code execution. | CRITICAL 9.8EPSS 10.9% | 6 March 2017 |
| CVE-2017-6334 | NETGEAR DGN2200 Devices OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 72.6% | 6 March 2017 |
| CVE-2016-7406 | Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument. | CRITICAL 9.8EPSS 10.5% | 3 March 2017 |
| CVE-2016-6883 | MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher variant attack. | MEDIUM 5.9EPSS 13.9% | 3 March 2017 |
| CVE-2015-8813 | The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter. | HIGH 8.2EPSS 11.2% | 3 March 2017 |
| CVE-2017-6403 | NetBackup Cloud Storage Service uses a hardcoded username and password. | CRITICAL 9.8EPSS 26.7% | 2 March 2017 |
| CVE-2017-5982 | Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd. | HIGH 7.5EPSS 77.6% | 28 February 2017 |
| CVE-2017-6343 | The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of… | HIGH 8.1EPSS 60.3% | 27 February 2017 |
| CVE-2017-6342 | This allows sniffing sensitive information identified in CVE-2017-6341 without prior knowledge of the password. | CRITICAL 9.8EPSS 12.8% | 27 February 2017 |
| CVE-2017-0037 | Microsoft Edge and Internet Explorer Type Confusion Vulnerability | KEVHIGH 8.1EPSS 80.4% | 26 February 2017 |
| CVE-2017-6206 | D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Information Disclosure attacks via unspecified vectors. | HIGH 7.5EPSS 16.2% | 23 February 2017 |
| CVE-2017-6187 | Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request. | CRITICAL 9.8EPSS 33.1% | 22 February 2017 |
| CVE-2017-6077 | NETGEAR DGN2200 Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 68.7% | 22 February 2017 |
| CVE-2017-5586 | OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries. | CRITICAL 9.8EPSS 25.3% | 22 February 2017 |
| CVE-2016-9683 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. | CRITICAL 9.8EPSS 11.6% | 22 February 2017 |
| CVE-2016-9682 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. | CRITICAL 9.8EPSS 23.3% | 22 February 2017 |
| CVE-2016-9269 | Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to run arbitrary… | CRITICAL 9.9EPSS 13.4% | 21 February 2017 |
| CVE-2017-0038 | gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to… | MEDIUM 5.5EPSS 82.1% | 20 February 2017 |
| CVE-2017-2370 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted app. | HIGH 7.8EPSS 11.3% | 20 February 2017 |
| CVE-2017-2361 | The issue involves the "Help Viewer" component, which allows XSS attacks via a crafted web site. | MEDIUM 6.1EPSS 17.1% | 20 February 2017 |
| CVE-2016-8652 | The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username. | MEDIUM 5.9EPSS 48.2% | 17 February 2017 |
| CVE-2016-4314 | Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. | MEDIUM 4.9EPSS 12.4% | 17 February 2017 |
| CVE-2016-10134 | SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php. | CRITICAL 9.8EPSS 83.4% | 17 February 2017 |
| CVE-2017-5991 | An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. | HIGH 7.5EPSS 15.2% | 15 February 2017 |
| CVE-2017-2992 | Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. | HIGH 8.8EPSS 32.7% | 15 February 2017 |
| CVE-2017-2988 | Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing garbage collection. | HIGH 8.8EPSS 18.1% | 15 February 2017 |
| CVE-2017-2986 | Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (FLV) codec. | HIGH 8.8EPSS 30.9% | 15 February 2017 |
| CVE-2017-2985 | Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. | HIGH 8.8EPSS 21.8% | 15 February 2017 |
| CVE-2017-2984 | Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the h264 decoder routine. | HIGH 8.8EPSS 18.2% | 15 February 2017 |
| CVE-2017-5972 | The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets,… | HIGH 7.5EPSS 23.9% | 14 February 2017 |
| CVE-2017-5162 | Lack of authentication for remote service gives access to application set up and configuration. | CRITICAL 9.8EPSS 12.6% | 13 February 2017 |
| CVE-2016-9361 | An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A… | CRITICAL 9.8EPSS 19.9% | 13 February 2017 |
| CVE-2016-9343 | By sending malformed common industrial protocol (CIP) packet, an attacker may be able to overflow a stack-based buffer and execute code on the controller or initiate a nonrecoverable fault resulting in a denial of service. | CRITICAL 10.0EPSS 10.5% | 13 February 2017 |
| CVE-2016-6210 | sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference… | MEDIUM 5.9EPSS 88.9% | 13 February 2017 |
| CVE-2017-5941 | Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE). | CRITICAL 9.8EPSS 61.0% | 9 February 2017 |
| CVE-2017-3807 | A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow. | HIGH 8.8EPSS 14.8% | 9 February 2017 |
| CVE-2016-9244 | A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. | HIGH 7.5EPSS 74.0% | 9 February 2017 |
| CVE-2016-2148 | Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing. | CRITICAL 9.8EPSS 27.1% | 9 February 2017 |
| CVE-2015-6024 | ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the DIA_IPADDRESS parameter. | CRITICAL 9.8EPSS 26.1% | 9 February 2017 |
| CVE-2015-6023 | ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intended access restrictions via a direct request. | HIGH 7.3EPSS 11.0% | 9 February 2017 |
| CVE-2016-6175 | Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header. | CRITICAL 9.8EPSS 19.7% | 7 February 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.