Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,914 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 84 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-8646 | Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in… | EXPLOIT ✓HIGH 7.5EPSS 69.3% | 8 August 2017 |
| CVE-2017-8645 | Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in… | EXPLOIT ✓HIGH 7.5EPSS 69.3% | 8 August 2017 |
| CVE-2017-8644 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". | EXPLOIT ✓MEDIUM 4.3EPSS 15.1% | 8 August 2017 |
| CVE-2017-8641 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context… | EXPLOITHIGH 7.5EPSS 71.6% | 8 August 2017 |
| CVE-2017-8640 | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in… | EXPLOIT ✓HIGH 7.5EPSS 69.3% | 8 August 2017 |
| CVE-2017-8636 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context… | EXPLOIT ×4 ✓HIGH 7.5EPSS 72.1% | 8 August 2017 |
| CVE-2017-8635 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context… | EXPLOIT ✓HIGH 7.5EPSS 55.9% | 8 August 2017 |
| CVE-2017-8634 | Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine… | EXPLOIT ✓HIGH 7.5EPSS 70.3% | 8 August 2017 |
| CVE-2017-11741 | HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts. | EXPLOIT ✓HIGH 8.8EPSS 1.11% | 8 August 2017 |
| CVE-2017-11155 | An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 47.4% | 8 August 2017 |
| CVE-2017-11154 | Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type parameter. | EXPLOIT ✓HIGH 7.2EPSS 8.63% | 8 August 2017 |
| CVE-2017-11153 | Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload. | EXPLOIT ✓CRITICAL 9.8EPSS 12.2% | 8 August 2017 |
| CVE-2017-11152 | Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter. | EXPLOIT ✓HIGH 7.5EPSS 14.6% | 8 August 2017 |
| CVE-2017-11151 | A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action. | EXPLOIT ✓CRITICAL 9.8EPSS 16.3% | 8 August 2017 |
| CVE-2017-10246 | Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: iHelp). | EXPLOITHIGH 8.2EPSS 13.9% | 8 August 2017 |
| CVE-2017-10204 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). | EXPLOIT ✓HIGH 8.8EPSS 1.62% | 8 August 2017 |
| CVE-2017-10129 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). | EXPLOIT ✓HIGH 8.8EPSS 1.64% | 8 August 2017 |
| CVE-2017-10046 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). | EXPLOIT ✓MEDIUM 5.4EPSS 3.92% | 8 August 2017 |
| CVE-2015-7855 | The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value. | EXPLOIT ✓MEDIUM 6.5EPSS 31.1% | 7 August 2017 |
| CVE-2015-7571 | Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. | EXPLOITHIGH 7.8EPSS 8.44% | 7 August 2017 |
| CVE-2017-12653 | 360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory. | EXPLOITHIGH 7.8EPSS 1.98% | 7 August 2017 |
| CVE-2014-9262 | The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files. | EXPLOITHIGH 8.2EPSS 7.49% | 7 August 2017 |
| CVE-2014-9260 | The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option. | EXPLOITHIGH 8.8EPSS 11.1% | 7 August 2017 |
| CVE-2017-12479 | It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. | EXPLOIT ✓HIGH 8.8EPSS 11.8% | 7 August 2017 |
| CVE-2017-12478 | A remote attacker could use this flaw to bypass authentication and execute arbitrary commands with root privilege on the target system. | EXPLOIT ×3 ✓CRITICAL 9.8EPSS 78.3% | 7 August 2017 |
| CVE-2017-12477 | It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypassed. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 68.2% | 7 August 2017 |
| CVE-2017-7533 | Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that leverages simultaneous execution of the… | EXPLOITHIGH 7.0EPSS 1.22% | 5 August 2017 |
| CVE-2017-11657 | Dashlane might allow local users to gain privileges by placing a Trojan horse WINHTTP.dll in the %APPDATA%\Dashlane directory. | EXPLOITHIGH 7.3EPSS 0.67% | 4 August 2017 |
| CVE-2017-11394 | Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. | EXPLOITCRITICAL 9.8EPSS 66.8% | 3 August 2017 |
| CVE-2017-7442 | Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences. | EXPLOIT ✓HIGH 8.8EPSS 40.7% | 3 August 2017 |
| CVE-2017-11320 | Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker to cause DNS Poisoning and steal credentials from the router. | EXPLOITMEDIUM 6.1EPSS 1.81% | 3 August 2017 |
| CVE-2017-9769 | A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary process. | EXPLOIT ✓CRITICAL 9.8EPSS 85.5% | 2 August 2017 |
| CVE-2017-7642 | The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable. | EXPLOITHIGH 7.8EPSS 1.23% | 2 August 2017 |
| CVE-2017-11356 | The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control. | EXPLOITMEDIUM 6.5EPSS 3.50% | 2 August 2017 |
| CVE-2017-11355 | Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page;… | EXPLOITMEDIUM 6.1EPSS 2.90% | 2 August 2017 |
| CVE-2015-7891 | Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows local users to trigger memory errors by leveraging definition of g2d_lock and g2d_unlock lock macros as… | EXPLOIT ✓HIGH 7.0EPSS 0.67% | 2 August 2017 |
| CVE-2017-11494 | SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a login action. | EXPLOITCRITICAL 9.8EPSS 3.75% | 2 August 2017 |
| CVE-2017-11552 | mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (memory corruption seen in a crash in the mad_decoder_run function in decoder.c in libmad) via a crafted… | EXPLOITMEDIUM 6.5EPSS 6.56% | 1 August 2017 |
| CVE-2017-11735 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 31 July 2017 |
| CVE-2017-11548 | The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file. | EXPLOITMEDIUM 5.5EPSS 3.85% | 31 July 2017 |
| CVE-2017-11359 | The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file. | EXPLOITMEDIUM 5.5EPSS 6.60% | 31 July 2017 |
| CVE-2017-11358 | The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted hcom file. | EXPLOITMEDIUM 5.5EPSS 7.40% | 31 July 2017 |
| CVE-2017-11333 | The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file. | EXPLOITMEDIUM 5.5EPSS 4.84% | 31 July 2017 |
| CVE-2017-11332 | The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file. | EXPLOITMEDIUM 5.5EPSS 6.60% | 31 July 2017 |
| CVE-2017-11331 | The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file. | EXPLOITMEDIUM 5.5EPSS 3.79% | 31 July 2017 |
| CVE-2017-11330 | The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted avi file. | EXPLOITMEDIUM 5.5EPSS 3.06% | 31 July 2017 |
| CVE-2016-0736 | This made it vulnerable to padding oracle attacks, particularly with CBC. | EXPLOITHIGH 7.5EPSS 49.0% | 27 July 2017 |
| CVE-2017-8870 | Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file. | EXPLOIT ✓HIGH 7.8EPSS 13.7% | 27 July 2017 |
| CVE-2017-8869 | Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file. | EXPLOIT ✓HIGH 7.8EPSS 15.9% | 27 July 2017 |
| CVE-2017-9614 | The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file. | EXPLOITHIGH 8.8EPSS 8.15% | 27 July 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.