Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,560 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%Updated 20 September 2026
17,391 results · page 182 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2016-7478 | Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876. | HIGH 7.5EPSS 42.4% | 11 January 2017 |
| CVE-2017-2966 | Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the image conversion engine related to parsing malformed TIFF segments. | HIGH 7.8EPSS 10.6% | 11 January 2017 |
| CVE-2017-2960 | Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to parsing of EXIF metadata. | HIGH 7.8EPSS 18.5% | 11 January 2017 |
| CVE-2017-2959 | Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the image conversion engine, related to parsing of color profile metadata. | HIGH 7.8EPSS 11.5% | 11 January 2017 |
| CVE-2017-2949 | Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the XSLT engine. | HIGH 7.8EPSS 20.4% | 11 January 2017 |
| CVE-2017-2946 | Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability when parsing the segment for storing non-graphic information. | HIGH 7.8EPSS 24.2% | 11 January 2017 |
| CVE-2017-2935 | Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. | HIGH 8.8EPSS 29.9% | 11 January 2017 |
| CVE-2017-2934 | Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Texture Format files. | HIGH 8.8EPSS 29.9% | 11 January 2017 |
| CVE-2017-2933 | Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression. | HIGH 8.8EPSS 29.9% | 11 January 2017 |
| CVE-2017-2932 | Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript MovieClip class. | HIGH 8.8EPSS 24.6% | 11 January 2017 |
| CVE-2017-2931 | Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the parsing of SWF metadata. | HIGH 8.8EPSS 21.1% | 11 January 2017 |
| CVE-2017-2930 | Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurrency error when manipulating a display list. | HIGH 8.8EPSS 25.1% | 11 January 2017 |
| CVE-2017-0004 | The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to cause a denial of service (reboot) via a crafted authentication request, aka "Local… | HIGH 7.5EPSS 91.4% | 10 January 2017 |
| CVE-2017-0003 | Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." | HIGH 7.8EPSS 24.7% | 10 January 2017 |
| CVE-2017-0002 | Microsoft Edge allows remote attackers to bypass the Same Origin Policy via vectors involving the about:blank URL and data: URLs, aka "Microsoft Edge Elevation of Privilege Vulnerability." | HIGH 8.8EPSS 14.9% | 10 January 2017 |
| CVE-2016-8706 | An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution. | HIGH 8.1EPSS 45.7% | 6 January 2017 |
| CVE-2016-8705 | Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution. | CRITICAL 9.8EPSS 19.9% | 6 January 2017 |
| CVE-2016-8704 | An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution. | CRITICAL 9.8EPSS 23.2% | 6 January 2017 |
| CVE-2016-8334 | A large out-of-bounds read on the heap vulnerability in Foxit PDF Reader can potentially be abused for information disclosure. | LOW 3.3EPSS 18.6% | 6 January 2017 |
| CVE-2016-10009 | Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket. | HIGH 7.3EPSS 37.4% | 5 January 2017 |
| CVE-2016-10108 | Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data. | CRITICAL 9.8EPSS 97.8% | 3 January 2017 |
| CVE-2016-10107 | Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header. | CRITICAL 9.8EPSS 11.2% | 3 January 2017 |
| CVE-2016-10074 | The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail… | CRITICAL 9.8EPSS 41.8% | 30 December 2016 |
| CVE-2016-10045 | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal… | CRITICAL 9.8EPSS 97.7% | 30 December 2016 |
| CVE-2016-10034 | The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently… | CRITICAL 9.8EPSS 38.4% | 30 December 2016 |
| CVE-2016-10033 | PHPMailer Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 30 December 2016 |
| CVE-2016-7456 | VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session. | CRITICAL 9.8EPSS 32.8% | 29 December 2016 |
| CVE-2016-7298 | Microsoft Office 2007 SP3, Office 2010 SP2, Word Viewer, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory… | HIGH 7.8EPSS 22.6% | 20 December 2016 |
| CVE-2016-7297 | The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than… | HIGH 7.5EPSS 26.8% | 20 December 2016 |
| CVE-2016-7296 | The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than… | HIGH 7.5EPSS 16.7% | 20 December 2016 |
| CVE-2016-7291 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from… | HIGH 7.1EPSS 22.8% | 20 December 2016 |
| CVE-2016-7290 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from… | HIGH 7.1EPSS 22.8% | 20 December 2016 |
| CVE-2016-7289 | Microsoft Publisher 2010 SP2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." | HIGH 7.8EPSS 25.1% | 20 December 2016 |
| CVE-2016-7288 | The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than… | HIGH 7.5EPSS 70.4% | 20 December 2016 |
| CVE-2016-7287 | The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." | HIGH 7.5EPSS 68.9% | 20 December 2016 |
| CVE-2016-7286 | The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than… | HIGH 7.5EPSS 68.9% | 20 December 2016 |
| CVE-2016-7284 | Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." | MEDIUM 4.3EPSS 15.0% | 20 December 2016 |
| CVE-2016-7283 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 8.8EPSS 17.8% | 20 December 2016 |
| CVE-2016-7282 | Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability." | MEDIUM 6.1EPSS 10.3% | 20 December 2016 |
| CVE-2016-7281 | The Web Workers implementation in Microsoft Internet Explorer 10 and 11 and Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Browser Security Feature Bypass Vulnerability." | MEDIUM 5.3EPSS 13.7% | 20 December 2016 |
| CVE-2016-7279 | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." | HIGH 7.5EPSS 15.5% | 20 December 2016 |
| CVE-2016-7278 | Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows Hyperlink Object Library Information Disclosure Vulnerability." | MEDIUM 5.3EPSS 14.7% | 20 December 2016 |
| CVE-2016-7277 | Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." | CRITICAL 9.6EPSS 18.0% | 20 December 2016 |
| CVE-2016-7276 | Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted… | HIGH 7.1EPSS 25.1% | 20 December 2016 |
| CVE-2016-7274 | Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute… | HIGH 8.8EPSS 42.5% | 20 December 2016 |
| CVE-2016-7273 | The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Remote Code Execution Vulnerability." | HIGH 8.8EPSS 19.0% | 20 December 2016 |
| CVE-2016-7272 | The Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to… | HIGH 8.8EPSS 39.3% | 20 December 2016 |
| CVE-2016-7270 | The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key… | HIGH 7.5EPSS 20.0% | 20 December 2016 |
| CVE-2016-7268 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive… | HIGH 7.1EPSS 22.6% | 20 December 2016 |
| CVE-2016-7267 | Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability." | MEDIUM 5.5EPSS 19.4% | 20 December 2016 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.