Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,605 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
17,391 results · page 204 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2015-5540 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to… | EXPLOIT ✓HIGH 10.0EPSS 45.5% | 14 August 2015 |
| CVE-2015-5539 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to… | EXPLOIT ✓HIGH 10.0EPSS 45.5% | 14 August 2015 |
| CVE-2015-5134 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to… | EXPLOIT ✓HIGH 10.0EPSS 50.3% | 14 August 2015 |
| CVE-2015-5133 | Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute… | EXPLOIT ✓HIGH 10.0EPSS 50.7% | 14 August 2015 |
| CVE-2015-5132 | Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute… | EXPLOIT ✓HIGH 10.0EPSS 50.7% | 14 August 2015 |
| CVE-2015-5131 | Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute… | EXPLOIT ✓HIGH 10.0EPSS 50.7% | 14 August 2015 |
| CVE-2015-5130 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to… | EXPLOIT ✓HIGH 10.0EPSS 50.3% | 14 August 2015 |
| CVE-2015-5129 | Heap-based buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to… | HIGH 10.0EPSS 10.3% | 14 August 2015 |
| CVE-2015-5127 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to… | EXPLOIT ✓HIGH 10.0EPSS 50.3% | 14 August 2015 |
| CVE-2015-4666 | Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter. | EXPLOITMEDIUM 5.0EPSS 16.2% | 13 August 2015 |
| CVE-2015-3253 | The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object. | CRITICAL 9.8EPSS 41.0% | 13 August 2015 |
| CVE-2015-5165 | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors. | HIGH 9.3EPSS 13.3% | 12 August 2015 |
| CVE-2015-3184 | mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name. | MEDIUM 5.0EPSS 10.6% | 12 August 2015 |
| CVE-2015-4495 | Mozilla Firefox Security Feature Bypass Vulnerability | KEVEXPLOITHIGH 8.8EPSS 71.3% | 8 August 2015 |
| CVE-2015-3440 | Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. | EXPLOIT ✓MEDIUM 4.3EPSS 16.9% | 3 August 2015 |
| CVE-2015-1489 | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to gain privileges via unspecified vectors. | EXPLOIT ✓HIGH 8.5EPSS 25.4% | 1 August 2015 |
| CVE-2015-1487 | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtain administrator privileges, via a crafted filename. | EXPLOIT ✓MEDIUM 5.5EPSS 52.0% | 1 August 2015 |
| CVE-2015-1486 | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative session. | EXPLOIT ✓HIGH 7.5EPSS 68.3% | 1 August 2015 |
| CVE-2015-5477 | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries. | EXPLOIT ×2 ✓HIGH 7.8EPSS 91.3% | 29 July 2015 |
| CVE-2015-3224 | request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection… | EXPLOIT ✓MEDIUM 4.3EPSS 44.7% | 26 July 2015 |
| CVE-2015-1283 | Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have… | MEDIUM 6.8EPSS 18.4% | 23 July 2015 |
| CVE-2015-3185 | The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote… | MEDIUM 4.3EPSS 16.3% | 20 July 2015 |
| CVE-2015-3183 | The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large… | MEDIUM 5.0EPSS 73.3% | 20 July 2015 |
| CVE-2015-2863 | Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks… | EXPLOITMEDIUM 4.3EPSS 10.3% | 20 July 2015 |
| CVE-2015-0253 | The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a… | MEDIUM 5.0EPSS 13.0% | 20 July 2015 |
| CVE-2015-2426 | Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 86.6% | 20 July 2015 |
| CVE-2015-5374 | A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module… | EXPLOITHIGH 7.8EPSS 74.5% | 18 July 2015 |
| CVE-2015-4748 | Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security. | HIGH 7.6EPSS 44.9% | 16 July 2015 |
| CVE-2015-2590 | Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 25.5% | 16 July 2015 |
| CVE-2015-5097 | Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows… | HIGH 10.0EPSS 18.9% | 15 July 2015 |
| CVE-2015-1763 | Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 does not prevent use of uninitialized memory in certain attempts to execute virtual functions, which allows remote authenticated users to execute arbitrary code via a… | HIGH 8.5EPSS 11.9% | 14 July 2015 |
| CVE-2015-1762 | Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transactional replication is configured, does not prevent use of uninitialized memory in unspecified function calls, which allows remote authenticated users to… | HIGH 7.1EPSS 10.4% | 14 July 2015 |
| CVE-2015-1761 | Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incorrect class during casts of unspecified pointers, which allows remote authenticated users to gain privileges by leveraging certain write access, aka "SQL… | MEDIUM 6.5EPSS 18.5% | 14 July 2015 |
| CVE-2015-2417 | OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted… | MEDIUM 5.0EPSS 10.2% | 14 July 2015 |
| CVE-2015-2416 | OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted… | MEDIUM 5.0EPSS 10.2% | 14 July 2015 |
| CVE-2015-2387 | Microsoft ATM Font Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 34.9% | 14 July 2015 |
| CVE-2015-2425 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 44.7% | 14 July 2015 |
| CVE-2015-2424 | Microsoft PowerPoint Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 38.5% | 14 July 2015 |
| CVE-2015-2422 | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 13.0% | 14 July 2015 |
| CVE-2015-2421 | Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass." | MEDIUM 4.3EPSS 13.3% | 14 July 2015 |
| CVE-2015-2419 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVEXPLOITHIGH 8.8EPSS 53.1% | 14 July 2015 |
| CVE-2015-2415 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka… | HIGH 9.3EPSS 13.6% | 14 July 2015 |
| CVE-2015-2414 | Microsoft Internet Explorer 8 through 11 allows remote attackers to obtain sensitive browsing-history information via vectors related to image caching, aka "Internet Explorer Information Disclosure Vulnerability." | MEDIUM 4.3EPSS 15.5% | 14 July 2015 |
| CVE-2015-2413 | Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted module-resource request, aka "Internet Explorer Information Disclosure Vulnerability." | MEDIUM 4.3EPSS 15.5% | 14 July 2015 |
| CVE-2015-2412 | Microsoft Internet Explorer 10 and 11 allows remote attackers to read arbitrary local files via a crafted pathname, aka "Internet Explorer Information Disclosure Vulnerability." | MEDIUM 4.3EPSS 17.9% | 14 July 2015 |
| CVE-2015-2411 | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 13.0% | 14 July 2015 |
| CVE-2015-2410 | Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted stylesheet, aka "Internet Explorer Information Disclosure Vulnerability." | MEDIUM 4.3EPSS 15.5% | 14 July 2015 |
| CVE-2015-2408 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 20.9% | 14 July 2015 |
| CVE-2015-2406 | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 13.0% | 14 July 2015 |
| CVE-2015-2404 | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 13.0% | 14 July 2015 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.