SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,560 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%Updated 20 September 2026

17,391 results · page 183 of 348

CVESummaryPriorityPublished
CVE-2016-7266Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, and Excel 2016 for Mac mishandle a registry check, which allows user-assisted remote attackers to execute arbitrary…HIGH 7.8EPSS 22.2%20 December 2016
CVE-2016-7265Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers…HIGH 7.1EPSS 22.6%20 December 2016
CVE-2016-7264Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, Excel for Mac 2011, and Excel 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted…HIGH 7.1EPSS 23.2%20 December 2016
CVE-2016-7263Microsoft Excel for Mac 2011 and Excel 2016 for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."HIGH 7.8EPSS 19.1%20 December 2016
CVE-2016-7262Microsoft Office Security Feature Bypass VulnerabilityKEVHIGH 7.8EPSS 57.7%20 December 2016
CVE-2016-7257The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka…MEDIUM 6.5EPSS 22.5%20 December 2016
CVE-2016-7206Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7280.MEDIUM 6.1EPSS 11.6%20 December 2016
CVE-2016-7181Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability."HIGH 7.5EPSS 13.9%20 December 2016
CVE-2016-9949In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{".HIGH 7.8EPSS 17.7%17 December 2016
CVE-2016-9838An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5.HIGH 7.5EPSS 14.1%16 December 2016
CVE-2016-9565MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server.CRITICAL 9.8EPSS 22.7%15 December 2016
CVE-2016-7892Adobe Flash Player Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 18.8%15 December 2016
CVE-2016-7870Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class for specific search strategies.HIGH 8.8EPSS 10.7%15 December 2016
CVE-2016-7869Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to backtrack search functionality.HIGH 8.8EPSS 11.1%15 December 2016
CVE-2016-7868Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to alternation functionality.HIGH 8.8EPSS 11.0%15 December 2016
CVE-2016-7867Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to bookmarking in searches.HIGH 8.8EPSS 10.7%15 December 2016
CVE-2016-7866Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability.CRITICAL 9.8EPSS 15.8%15 December 2016
CVE-2016-6277NETGEAR Multiple Routers Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 99.8%14 December 2016
CVE-2016-2334Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.HIGH 7.8EPSS 14.7%13 December 2016
CVE-2016-5841Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable.CRITICAL 9.8EPSS 13.4%13 December 2016
CVE-2016-6321Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the…HIGH 7.5EPSS 15.7%9 December 2016
CVE-2016-8858The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests.HIGH 7.5EPSS 29.5%9 December 2016
CVE-2016-8655Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the…HIGH 7.8EPSS 11.1%8 December 2016
CVE-2016-8740The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via…HIGH 7.5EPSS 79.1%5 December 2016
CVE-2016-9796Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024.CRITICAL 9.8EPSS 13.4%3 December 2016
CVE-2015-1328The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by…HIGH 7.8EPSS 37.7%28 November 2016
CVE-2016-1248vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.HIGH 7.8EPSS 25.3%23 November 2016
CVE-2016-9563SAP NetWeaver XML External Entity (XXE) VulnerabilityKEVMEDIUM 6.5EPSS 24.2%23 November 2016
CVE-2016-9150Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows remote attackers to execute arbitrary code via…CRITICAL 9.8EPSS 34.8%19 November 2016
CVE-2016-5195Linux Kernel Race Condition VulnerabilityKEVHIGH 7.0EPSS 83.5%10 November 2016
CVE-2016-7256Microsoft Windows Open Type Font Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 64.6%10 November 2016
CVE-2016-7255Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 81.0%10 November 2016
CVE-2016-7254Microsoft SQL Server 2012 SP2 and 2012 SP3 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability."HIGH 8.8EPSS 11.9%10 November 2016
CVE-2016-7253The agent in Microsoft SQL Server 2012 SP2, 2012 SP3, 2014 SP1, 2014 SP2, and 2016 does not properly check the atxcore.dll ACL, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Server Agent Elevation of…HIGH 8.8EPSS 11.9%10 November 2016
CVE-2016-7252Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability."MEDIUM 6.5EPSS 17.6%10 November 2016
CVE-2016-7250Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability."HIGH 8.8EPSS 12.0%10 November 2016
CVE-2016-7249Microsoft SQL Server 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability."HIGH 8.8EPSS 11.9%10 November 2016
CVE-2016-7248Microsoft Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Video Control Remote Code…HIGH 7.8EPSS 21.8%10 November 2016
CVE-2016-7245Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, and Office 2016 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."HIGH 7.8EPSS 19.6%10 November 2016
CVE-2016-7244Microsoft Office 2007 SP3 allows remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."MEDIUM 5.5EPSS 16.5%10 November 2016
CVE-2016-7243The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different…HIGH 7.5EPSS 15.2%10 November 2016
CVE-2016-7242The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different…HIGH 7.5EPSS 16.3%10 November 2016
CVE-2016-7241Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."HIGH 7.5EPSS 71.5%10 November 2016
CVE-2016-7240The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different…HIGH 7.5EPSS 66.5%10 November 2016
CVE-2016-7239The RegEx class in the XSS filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Browser…LOW 3.1EPSS 11.6%10 November 2016
CVE-2016-7237Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016…MEDIUM 6.5EPSS 66.9%10 November 2016
CVE-2016-7236Microsoft Excel 2010 SP2, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."HIGH 7.8EPSS 20.7%10 November 2016
CVE-2016-7235Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption…HIGH 7.8EPSS 19.6%10 November 2016
CVE-2016-7234Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Excel for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation…HIGH 7.8EPSS 20.6%10 November 2016
CVE-2016-7233Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain…MEDIUM 6.5EPSS 22.4%10 November 2016

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.