Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 87 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-9602 | Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code. | EXPLOITCRITICAL 9.8EPSS 4.29% | 16 June 2017 |
| CVE-2017-8487 | Windows OLE in Windows XP and Windows Server 2003 allows an attacker to execute code when a victim opens a specially crafted file or program aka "Windows olecnv32.dll Remote Code Execution Vulnerability." | EXPLOIT ✓HIGH 7.8EPSS 62.5% | 15 June 2017 |
| CVE-2017-9675 | On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot. | EXPLOIT ✓HIGH 7.5EPSS 12.1% | 15 June 2017 |
| CVE-2017-8550 | A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability". | EXPLOITMEDIUM 5.4EPSS 22.4% | 15 June 2017 |
| CVE-2017-8548 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system when Microsoft Edge improperly handles objects in memory, aka "Scripting Engine… | EXPLOIT ✓HIGH 7.5EPSS 67.6% | 15 June 2017 |
| CVE-2017-8496 | Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". | EXPLOIT ✓HIGH 7.5EPSS 51.5% | 15 June 2017 |
| CVE-2017-8492 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.71% | 15 June 2017 |
| CVE-2017-8491 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.90% | 15 June 2017 |
| CVE-2017-8490 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 4.87% | 15 June 2017 |
| CVE-2017-8489 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.90% | 15 June 2017 |
| CVE-2017-8488 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.71% | 15 June 2017 |
| CVE-2017-8485 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.59% | 15 June 2017 |
| CVE-2017-8484 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted… | EXPLOIT ✓MEDIUM 5.0EPSS 3.71% | 15 June 2017 |
| CVE-2017-8483 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 5.11% | 15 June 2017 |
| CVE-2017-8482 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.71% | 15 June 2017 |
| CVE-2017-8481 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.90% | 15 June 2017 |
| CVE-2017-8480 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.42% | 15 June 2017 |
| CVE-2017-8479 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.90% | 15 June 2017 |
| CVE-2017-8478 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.71% | 15 June 2017 |
| CVE-2017-8477 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted… | EXPLOIT ✓MEDIUM 5.0EPSS 5.11% | 15 June 2017 |
| CVE-2017-8476 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.42% | 15 June 2017 |
| CVE-2017-8473 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly… | EXPLOIT ✓MEDIUM 5.0EPSS 3.59% | 15 June 2017 |
| CVE-2017-8472 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.42% | 15 June 2017 |
| CVE-2017-8471 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted… | EXPLOIT ✓MEDIUM 5.0EPSS 3.59% | 15 June 2017 |
| CVE-2017-8470 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted… | EXPLOIT ✓MEDIUM 5.0EPSS 3.42% | 15 June 2017 |
| CVE-2017-8469 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows an authenticated attacker to obtain information via a… | EXPLOIT ✓MEDIUM 5.5EPSS 3.72% | 15 June 2017 |
| CVE-2017-8464 | Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability | KEVEXPLOIT ×2HIGH 8.8EPSS 89.9% | 15 June 2017 |
| CVE-2017-8462 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 3.71% | 15 June 2017 |
| CVE-2017-0300 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 4.96% | 15 June 2017 |
| CVE-2017-0299 | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information… | EXPLOIT ✓MEDIUM 5.0EPSS 4.79% | 15 June 2017 |
| CVE-2017-0289 | Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Windows Graphics… | EXPLOIT ✓MEDIUM 5.0EPSS 3.12% | 15 June 2017 |
| CVE-2017-0288 | Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Windows Graphics… | EXPLOIT ✓MEDIUM 5.0EPSS 2.97% | 15 June 2017 |
| CVE-2017-0287 | Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Graphics… | EXPLOIT ✓MEDIUM 5.0EPSS 3.12% | 15 June 2017 |
| CVE-2017-0286 | Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Windows Graphics… | EXPLOIT ✓MEDIUM 5.0EPSS 2.97% | 15 June 2017 |
| CVE-2017-0285 | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, and Microsoft… | EXPLOIT ✓MEDIUM 5.0EPSS 2.97% | 15 June 2017 |
| CVE-2017-0284 | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows… | EXPLOIT ✓MEDIUM 5.0EPSS 2.97% | 15 June 2017 |
| CVE-2017-0283 | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office Word… | EXPLOIT ✓HIGH 8.8EPSS 39.0% | 15 June 2017 |
| CVE-2017-0282 | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows… | EXPLOIT ✓MEDIUM 5.0EPSS 2.97% | 15 June 2017 |
| CVE-2017-9603 | SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php. | EXPLOITHIGH 8.8EPSS 4.93% | 13 June 2017 |
| CVE-2017-9429 | SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php. | EXPLOITHIGH 8.8EPSS 2.73% | 13 June 2017 |
| CVE-2017-9418 | SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/admin.php. | EXPLOITHIGH 8.8EPSS 2.39% | 12 June 2017 |
| CVE-2017-9128 | The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file. | EXPLOITMEDIUM 6.5EPSS 3.83% | 12 June 2017 |
| CVE-2017-9127 | The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file. | EXPLOITMEDIUM 6.5EPSS 5.10% | 12 June 2017 |
| CVE-2017-9126 | The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file. | EXPLOITMEDIUM 6.5EPSS 3.97% | 12 June 2017 |
| CVE-2017-9125 | The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file. | EXPLOITMEDIUM 6.5EPSS 4.91% | 12 June 2017 |
| CVE-2017-9124 | The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file. | EXPLOITMEDIUM 6.5EPSS 3.83% | 12 June 2017 |
| CVE-2017-9123 | The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file. | EXPLOITMEDIUM 6.5EPSS 3.83% | 12 June 2017 |
| CVE-2017-9122 | The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file. | EXPLOITMEDIUM 6.5EPSS 6.54% | 12 June 2017 |
| CVE-2017-8871 | The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file. | EXPLOITMEDIUM 6.5EPSS 13.0% | 12 June 2017 |
| CVE-2014-8687 | Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 43.8% | 8 June 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.