SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,914 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 82 of 501

CVESummaryPriorityPublished
CVE-2017-8708The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure…EXPLOITMEDIUM 4.7EPSS 3.68%13 September 2017
CVE-2017-8687The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure…EXPLOITMEDIUM 5.5EPSS 4.23%13 September 2017
CVE-2017-8685Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability".EXPLOITMEDIUM 5.5EPSS 3.04%13 September 2017
CVE-2017-8684Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1, allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information…EXPLOITMEDIUM 5.5EPSS 4.27%13 September 2017
CVE-2017-8683Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an attacker to execute remote code by…EXPLOITMEDIUM 5.5EPSS 22.6%13 September 2017
CVE-2017-8682Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office…EXPLOITHIGH 8.8EPSS 49.8%13 September 2017
CVE-2017-8681The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure…EXPLOITMEDIUM 5.5EPSS 4.23%13 September 2017
CVE-2017-8680The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 allows an information disclosure vulnerability when it improperly handles objects in memory,…EXPLOITMEDIUM 5.5EPSS 4.23%13 September 2017
CVE-2017-8678The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure…EXPLOITMEDIUM 5.5EPSS 4.23%13 September 2017
CVE-2017-11764Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting…EXPLOITHIGH 7.5EPSS 64.4%13 September 2017
CVE-2017-14396In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.EXPLOITCRITICAL 9.8EPSS 2.92%12 September 2017
CVE-2017-8918XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.EXPLOITMEDIUM 5.5EPSS 2.21%12 September 2017
CVE-2017-14344This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier.EXPLOITHIGH 7.8EPSS 1.84%12 September 2017
CVE-2017-1000251The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote…EXPLOITHIGH 8.0EPSS 16.2%12 September 2017
CVE-2017-14335On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.EXPLOITHIGH 7.5EPSS 27.8%12 September 2017
CVE-2017-14266tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to CVE-2016-6160.EXPLOITHIGH 7.8EPSS 3.59%12 September 2017
CVE-2017-3133A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.EXPLOITMEDIUM 6.1EPSS 10.7%12 September 2017
CVE-2017-3132A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.EXPLOITMEDIUM 6.1EPSS 8.11%12 September 2017
CVE-2017-3131A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.EXPLOITMEDIUM 5.4EPSS 7.68%12 September 2017
CVE-2015-8351PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to…EXPLOITCRITICAL 9.0EPSS 37.0%11 September 2017
CVE-2017-14153This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier.EXPLOITHIGH 7.8EPSS 1.82%11 September 2017
CVE-2017-14075This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier.EXPLOITHIGH 7.8EPSS 1.82%11 September 2017
CVE-2015-4523Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanism and consequently write to arbitrary files, cause a denial of service (host reboot or reset to factory…EXPLOITCRITICAL 9.3EPSS 4.47%11 September 2017
CVE-2017-9095XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.EXPLOITMEDIUM 5.5EPSS 3.66%8 September 2017
CVE-2017-14219XSS (persistent) on the Intelbras Wireless N 150Mbps router with firmware WRN 240 allows attackers to steal wireless credentials without being connected to the network, related to userRpm/popupSiteSurveyRpm.htm and userRpm/WlanSecurityRpm.htm.EXPLOITMEDIUM 6.1EPSS 1.44%7 September 2017
CVE-2015-3314SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.EXPLOITHIGH 8.1EPSS 4.87%7 September 2017
CVE-2015-3313SQL injection vulnerability in WordPress Community Events plugin before 1.4.EXPLOITCRITICAL 9.8EPSS 8.34%7 September 2017
CVE-2015-3222syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.EXPLOITHIGH 7.0EPSS 1.99%7 September 2017
CVE-2017-9834SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action to wp-admin/admin-ajax.php.EXPLOITCRITICAL 9.8EPSS 4.07%7 September 2017
CVE-2017-14147An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply browsing to the link http://[Default-Router-IP]/restoreinfo.cgi & execute it.EXPLOITCRITICAL 9.8EPSS 65.6%7 September 2017
CVE-2017-13754Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter before 6.50b allows remote attackers to inject arbitrary web script or HTML via the "server name" field in actions/ChangeConfiguration.html.EXPLOITMEDIUM 5.4EPSS 3.88%7 September 2017
CVE-2017-13713T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user parameter to cgi-bin/webupg.EXPLOITHIGH 8.8EPSS 9.12%7 September 2017
CVE-2017-11567Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save.EXPLOITHIGH 8.8EPSS 4.13%7 September 2017
CVE-2015-7241XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.EXPLOITCRITICAL 9.8EPSS 13.5%6 September 2017
CVE-2017-1130IBM Notes 8.5 and 9.0 is vulnerable to a denial of service.EXPLOITMEDIUM 6.5EPSS 29.2%5 September 2017
CVE-2017-1129IBM Notes 8.5 and 9.0 is vulnerable to a denial of service.EXPLOIT ×2MEDIUM 6.5EPSS 30.1%5 September 2017
CVE-2017-1000083backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option…EXPLOIT ×2HIGH 7.8EPSS 51.1%5 September 2017
CVE-2017-14126The Participants Database plugin before 1.7.5.10 for WordPress has XSS.EXPLOITMEDIUM 6.1EPSS 2.30%4 September 2017
CVE-2017-3898A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP…EXPLOITMEDIUM 5.9EPSS 3.18%1 September 2017
CVE-2017-3897A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file…EXPLOITCRITICAL 9.8EPSS 11.7%1 September 2017
CVE-2014-8677The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being…EXPLOITMEDIUM 5.3EPSS 3.49%31 August 2017
CVE-2014-8676Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a ..EXPLOITMEDIUM 5.3EPSS 40.8%31 August 2017
CVE-2014-8675Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password via a brute-force attack on the embedded password hash.EXPLOITHIGH 7.5EPSS 12.5%31 August 2017
CVE-2017-0901RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.EXPLOITHIGH 7.5EPSS 29.4%31 August 2017
CVE-2016-10504Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file.EXPLOITMEDIUM 6.5EPSS 8.22%30 August 2017
CVE-2017-12763An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to local files.EXPLOITHIGH 8.8EPSS 3.86%29 August 2017
CVE-2014-8393DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.EXPLOIT ×2HIGH 7.8EPSS 8.34%29 August 2017
CVE-2017-9979An attacker can leverage this issue by including arbitrary HTML or JavaScript code as a parameter, aka XSS.EXPLOITMEDIUM 6.1EPSS 2.56%28 August 2017
CVE-2017-9978An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames.EXPLOITMEDIUM 5.3EPSS 4.75%28 August 2017
CVE-2017-12954The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted gig file.EXPLOITMEDIUM 6.5EPSS 4.16%28 August 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.