Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 89 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-6984 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 7.66% | 22 May 2017 |
| CVE-2017-6982 | It allows attackers to cause a denial of service via a crafted app. | EXPLOIT ✓MEDIUM 5.5EPSS 2.39% | 22 May 2017 |
| CVE-2017-6980 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 6.57% | 22 May 2017 |
| CVE-2017-6979 | A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app. | EXPLOIT ✓HIGH 7.0EPSS 3.64% | 22 May 2017 |
| CVE-2017-6978 | It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | EXPLOIT ✓HIGH 7.8EPSS 4.30% | 22 May 2017 |
| CVE-2017-2547 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 14.3% | 22 May 2017 |
| CVE-2017-2536 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOITHIGH 8.8EPSS 10.5% | 22 May 2017 |
| CVE-2017-2533 | A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app. | EXPLOIT ✓HIGH 7.0EPSS 4.39% | 22 May 2017 |
| CVE-2017-2531 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 6.57% | 22 May 2017 |
| CVE-2017-2528 | It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with cached frames. | EXPLOIT ✓MEDIUM 6.1EPSS 2.02% | 22 May 2017 |
| CVE-2017-2527 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via crafted data. | EXPLOIT ✓CRITICAL 9.8EPSS 6.81% | 22 May 2017 |
| CVE-2017-2524 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data. | EXPLOIT ✓CRITICAL 9.8EPSS 6.73% | 22 May 2017 |
| CVE-2017-2523 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data. | EXPLOIT ✓CRITICAL 9.8EPSS 11.5% | 22 May 2017 |
| CVE-2017-2522 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data. | EXPLOIT ✓CRITICAL 9.8EPSS 6.59% | 22 May 2017 |
| CVE-2017-2521 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 5.90% | 22 May 2017 |
| CVE-2017-2516 | It allows attackers to bypass intended memory-read restrictions via a crafted app. | EXPLOIT ✓MEDIUM 5.0EPSS 2.88% | 22 May 2017 |
| CVE-2017-2515 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 4.68% | 22 May 2017 |
| CVE-2017-2514 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 6.07% | 22 May 2017 |
| CVE-2017-2510 | It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with pageshow events. | EXPLOIT ✓MEDIUM 6.1EPSS 3.92% | 22 May 2017 |
| CVE-2017-2509 | It allows attackers to bypass intended memory-read restrictions via a crafted app. | EXPLOIT ✓MEDIUM 5.5EPSS 2.32% | 22 May 2017 |
| CVE-2017-2508 | It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with container nodes. | EXPLOIT ✓MEDIUM 6.1EPSS 3.02% | 22 May 2017 |
| CVE-2017-2504 | It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with WebKit Editor commands. | EXPLOIT ✓MEDIUM 6.1EPSS 3.35% | 22 May 2017 |
| CVE-2017-2501 | A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app. | EXPLOIT ✓HIGH 7.0EPSS 4.19% | 22 May 2017 |
| CVE-2017-9101 | import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 76.7% | 21 May 2017 |
| CVE-2017-9024 | Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname. | EXPLOITHIGH 7.5EPSS 12.2% | 21 May 2017 |
| CVE-2017-7620 | MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substring as introducing either a local pathname or a remote hostname, which… | EXPLOITMEDIUM 6.5EPSS 1.36% | 21 May 2017 |
| CVE-2017-9080 | PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection. | EXPLOIT ✓HIGH 8.8EPSS 62.3% | 19 May 2017 |
| CVE-2017-5177 | A Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior. | EXPLOITHIGH 7.5EPSS 17.7% | 19 May 2017 |
| CVE-2017-5174 | An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. | EXPLOIT ✓CRITICAL 9.8EPSS 52.3% | 19 May 2017 |
| CVE-2017-5173 | An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. | EXPLOIT ✓CRITICAL 9.8EPSS 29.6% | 19 May 2017 |
| CVE-2017-6622 | A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. | EXPLOITCRITICAL 9.8EPSS 62.2% | 18 May 2017 |
| CVE-2017-8917 | SQL injection vulnerability in Joomla! | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 99.8% | 17 May 2017 |
| CVE-2017-8849 | smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service. | EXPLOITHIGH 7.8EPSS 1.95% | 17 May 2017 |
| CVE-2017-8422 | KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app. | EXPLOITHIGH 7.8EPSS 1.80% | 17 May 2017 |
| CVE-2017-8382 | admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts. | EXPLOIT ✓MEDIUM 4.5EPSS 2.63% | 16 May 2017 |
| CVE-2017-7953 | INFOR EAM V11.0 Build 201410 has XSS via comment fields. | EXPLOITMEDIUM 5.4EPSS 0.95% | 16 May 2017 |
| CVE-2017-7952 | INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter. | EXPLOITHIGH 8.8EPSS 1.44% | 16 May 2017 |
| CVE-2017-8927 | Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file. | EXPLOIT ✓HIGH 7.8EPSS 3.01% | 15 May 2017 |
| CVE-2017-8926 | Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file. | EXPLOIT ✓HIGH 7.8EPSS 3.13% | 15 May 2017 |
| CVE-2017-7478 | OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. | EXPLOIT ✓HIGH 7.5EPSS 13.8% | 15 May 2017 |
| CVE-2017-8928 | mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF. | EXPLOITHIGH 8.8EPSS 2.05% | 14 May 2017 |
| CVE-2016-10277 | An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. | EXPLOITHIGH 7.8EPSS 9.68% | 12 May 2017 |
| CVE-2017-0263 | Microsoft Win32k Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 10.0% | 12 May 2017 |
| CVE-2017-0259 | The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows… | EXPLOIT ✓MEDIUM 4.7EPSS 9.66% | 12 May 2017 |
| CVE-2017-0258 | The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain… | EXPLOIT ✓MEDIUM 4.7EPSS 7.36% | 12 May 2017 |
| CVE-2017-0245 | The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local authenticated attacker to execute a specially crafted application to obtain kernel information, aka "Win32k Information Disclosure… | EXPLOIT ✓MEDIUM 4.7EPSS 7.70% | 12 May 2017 |
| CVE-2017-0220 | The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure… | EXPLOIT ✓MEDIUM 4.7EPSS 7.46% | 12 May 2017 |
| CVE-2017-0214 | Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when… | EXPLOIT ✓HIGH 7.0EPSS 3.46% | 12 May 2017 |
| CVE-2017-0213 | Microsoft Windows Privilege Escalation Vulnerability | KEVEXPLOIT ✓HIGH 7.3EPSS 84.1% | 12 May 2017 |
| CVE-2017-0175 | The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different… | EXPLOIT ✓MEDIUM 4.7EPSS 7.05% | 12 May 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.