Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,914 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 86 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-8594 | Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet… | EXPLOIT ✓HIGH 7.5EPSS 50.4% | 11 July 2017 |
| CVE-2017-8570 | Microsoft Office Remote Code Execution Vulnerability | KEVEXPLOITHIGH 7.8EPSS 89.9% | 11 July 2017 |
| CVE-2017-8564 | Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability… | EXPLOIT ✓MEDIUM 5.5EPSS 3.02% | 11 July 2017 |
| CVE-2017-7175 | NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field). | EXPLOIT ✓CRITICAL 9.9EPSS 6.55% | 10 July 2017 |
| CVE-2017-9791 | Apache Struts 1 Improper Input Validation Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 98.9% | 10 July 2017 |
| CVE-2017-7950 | Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file. | EXPLOITMEDIUM 5.5EPSS 2.49% | 7 July 2017 |
| CVE-2017-10974 | Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. | EXPLOITHIGH 7.5EPSS 81.2% | 7 July 2017 |
| CVE-2017-10803 | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code,… | EXPLOITMEDIUM 6.5EPSS 3.59% | 4 July 2017 |
| CVE-2017-9248 | Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 75.1% | 3 July 2017 |
| CVE-2017-6026 | This may allow a current session to be compromised. | EXPLOITCRITICAL 9.1EPSS 31.8% | 30 June 2017 |
| CVE-2017-10688 | A crafted input will lead to a remote denial of service attack. | EXPLOIT ✓HIGH 7.5EPSS 6.72% | 29 June 2017 |
| CVE-2017-10682 | SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php. | EXPLOITCRITICAL 9.8EPSS 8.31% | 29 June 2017 |
| CVE-2017-8558 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10… | EXPLOIT ✓HIGH 7.8EPSS 43.6% | 29 June 2017 |
| CVE-2017-6086 | Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.15 allow remote attackers to hijack the authentication of logged administrators to (1) add an administrator user via a crafted POST… | EXPLOITHIGH 8.8EPSS 2.00% | 27 June 2017 |
| CVE-2017-2491 | Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remote attackers to execute arbitrary code via a crafted web page, or a crafted file. | EXPLOIT ✓HIGH 8.8EPSS 8.04% | 27 June 2017 |
| CVE-2015-7898 | Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). | EXPLOIT ✓MEDIUM 5.5EPSS 0.84% | 27 June 2017 |
| CVE-2015-7895 | Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). | EXPLOIT ✓MEDIUM 5.5EPSS 1.07% | 27 June 2017 |
| CVE-2017-9841 | PHPUnit Command Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 100.0% | 27 June 2017 |
| CVE-2017-1297 | IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. | EXPLOITHIGH 7.3EPSS 1.49% | 27 June 2017 |
| CVE-2017-6326 | The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. | EXPLOIT ✓CRITICAL 10.0EPSS 72.8% | 26 June 2017 |
| CVE-2015-3315 | Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/abrt/*/maps, (2) /tmp/jvm-*/hs_error.log, (3) /proc/*/exe, (4)… | EXPLOIT ×2 ✓HIGH 7.8EPSS 4.78% | 26 June 2017 |
| CVE-2017-9936 | In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. | EXPLOIT ✓MEDIUM 6.5EPSS 7.48% | 26 June 2017 |
| CVE-2017-9872 | The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified… | EXPLOIT ✓HIGH 7.8EPSS 9.79% | 25 June 2017 |
| CVE-2017-9869 | The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file. | EXPLOIT ✓MEDIUM 5.5EPSS 4.06% | 25 June 2017 |
| CVE-2017-9833 | /cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. | EXPLOITHIGH 7.5EPSS 68.5% | 24 June 2017 |
| CVE-2015-9098 | In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in the ability to execute arbitrary SQL commands on any monitored Microsoft SQL Server machines. | EXPLOITCRITICAL 9.8EPSS 14.1% | 22 June 2017 |
| CVE-2017-3631 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). | EXPLOIT ×2 ✓MEDIUM 5.3EPSS 5.99% | 22 June 2017 |
| CVE-2017-3630 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). | EXPLOIT ×2 ✓MEDIUM 5.3EPSS 4.53% | 22 June 2017 |
| CVE-2017-3629 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). | EXPLOIT ×2 ✓HIGH 7.8EPSS 5.08% | 22 June 2017 |
| CVE-2016-7508 | Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding. | EXPLOIT ✓HIGH 7.5EPSS 1.60% | 21 June 2017 |
| CVE-2017-9130 | The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file. | EXPLOITMEDIUM 5.5EPSS 2.93% | 21 June 2017 |
| CVE-2017-9129 | The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file. | EXPLOITMEDIUM 5.5EPSS 2.51% | 21 June 2017 |
| CVE-2017-3078 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. | EXPLOIT ✓CRITICAL 9.8EPSS 30.9% | 20 June 2017 |
| CVE-2017-3077 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. | EXPLOIT ✓CRITICAL 9.8EPSS 22.3% | 20 June 2017 |
| CVE-2017-3076 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module. | EXPLOIT ✓CRITICAL 9.8EPSS 24.7% | 20 June 2017 |
| CVE-2017-1000379 | The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing attackers to more easily manipulate the stack. | EXPLOIT ✓HIGH 7.8EPSS 1.83% | 19 June 2017 |
| CVE-2017-1000375 | NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. | EXPLOIT ✓CRITICAL 9.8EPSS 18.9% | 19 June 2017 |
| CVE-2017-1000373 | The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. | EXPLOIT ✓MEDIUM 6.5EPSS 13.4% | 19 June 2017 |
| CVE-2017-1000371 | The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the… | EXPLOIT ×2 ✓HIGH 7.8EPSS 2.73% | 19 June 2017 |
| CVE-2017-1000370 | The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above… | EXPLOIT ×2 ✓HIGH 7.8EPSS 2.25% | 19 June 2017 |
| CVE-2017-1000366 | glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. | EXPLOIT ×3 ✓HIGH 7.8EPSS 2.73% | 19 June 2017 |
| CVE-2017-1000364 | An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the… | EXPLOIT ✓HIGH 7.4EPSS 5.19% | 19 June 2017 |
| CVE-2017-9730 | SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the "r" parameter. | EXPLOITCRITICAL 9.8EPSS 1.96% | 19 June 2017 |
| CVE-2017-9756 | The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as… | EXPLOIT ✓HIGH 7.8EPSS 8.08% | 19 June 2017 |
| CVE-2017-9750 | opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary… | EXPLOIT ✓HIGH 7.8EPSS 8.11% | 19 June 2017 |
| CVE-2017-9749 | The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling… | EXPLOIT ✓HIGH 7.8EPSS 8.51% | 19 June 2017 |
| CVE-2017-9748 | The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have… | EXPLOIT ✓HIGH 7.8EPSS 7.86% | 19 June 2017 |
| CVE-2017-9747 | The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have… | EXPLOIT ✓HIGH 7.8EPSS 7.86% | 19 June 2017 |
| CVE-2017-9746 | The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by… | EXPLOIT ✓HIGH 7.8EPSS 8.54% | 19 June 2017 |
| CVE-2017-9742 | The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by… | EXPLOIT ✓HIGH 7.8EPSS 8.08% | 19 June 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.