SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 89 of 501

CVESummaryPriorityPublished
CVE-2017-6984It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 7.66%22 May 2017
CVE-2017-6982It allows attackers to cause a denial of service via a crafted app.EXPLOITMEDIUM 5.5EPSS 2.39%22 May 2017
CVE-2017-6980It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 6.57%22 May 2017
CVE-2017-6979A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.EXPLOITHIGH 7.0EPSS 3.64%22 May 2017
CVE-2017-6978It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.EXPLOITHIGH 7.8EPSS 4.30%22 May 2017
CVE-2017-2547It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 14.3%22 May 2017
CVE-2017-2536It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 10.5%22 May 2017
CVE-2017-2533A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.EXPLOITHIGH 7.0EPSS 4.39%22 May 2017
CVE-2017-2531It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 6.57%22 May 2017
CVE-2017-2528It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with cached frames.EXPLOITMEDIUM 6.1EPSS 2.02%22 May 2017
CVE-2017-2527It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via crafted data.EXPLOITCRITICAL 9.8EPSS 6.81%22 May 2017
CVE-2017-2524It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data.EXPLOITCRITICAL 9.8EPSS 6.73%22 May 2017
CVE-2017-2523It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data.EXPLOITCRITICAL 9.8EPSS 11.5%22 May 2017
CVE-2017-2522It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data.EXPLOITCRITICAL 9.8EPSS 6.59%22 May 2017
CVE-2017-2521It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 5.90%22 May 2017
CVE-2017-2516It allows attackers to bypass intended memory-read restrictions via a crafted app.EXPLOITMEDIUM 5.0EPSS 2.88%22 May 2017
CVE-2017-2515It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 4.68%22 May 2017
CVE-2017-2514It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.EXPLOITHIGH 8.8EPSS 6.07%22 May 2017
CVE-2017-2510It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with pageshow events.EXPLOITMEDIUM 6.1EPSS 3.92%22 May 2017
CVE-2017-2509It allows attackers to bypass intended memory-read restrictions via a crafted app.EXPLOITMEDIUM 5.5EPSS 2.32%22 May 2017
CVE-2017-2508It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with container nodes.EXPLOITMEDIUM 6.1EPSS 3.02%22 May 2017
CVE-2017-2504It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with WebKit Editor commands.EXPLOITMEDIUM 6.1EPSS 3.35%22 May 2017
CVE-2017-2501A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.EXPLOITHIGH 7.0EPSS 4.19%22 May 2017
CVE-2017-9101import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.EXPLOIT ×2CRITICAL 9.8EPSS 76.7%21 May 2017
CVE-2017-9024Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname.EXPLOITHIGH 7.5EPSS 12.2%21 May 2017
CVE-2017-7620MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substring as introducing either a local pathname or a remote hostname, which…EXPLOITMEDIUM 6.5EPSS 1.36%21 May 2017
CVE-2017-9080PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.EXPLOITHIGH 8.8EPSS 62.3%19 May 2017
CVE-2017-5177A Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior.EXPLOITHIGH 7.5EPSS 17.7%19 May 2017
CVE-2017-5174An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12.EXPLOITCRITICAL 9.8EPSS 52.3%19 May 2017
CVE-2017-5173An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12.EXPLOITCRITICAL 9.8EPSS 29.6%19 May 2017
CVE-2017-6622A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges.EXPLOITCRITICAL 9.8EPSS 62.2%18 May 2017
CVE-2017-8917SQL injection vulnerability in Joomla!EXPLOIT ×2CRITICAL 9.8EPSS 99.8%17 May 2017
CVE-2017-8849smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service.EXPLOITHIGH 7.8EPSS 1.95%17 May 2017
CVE-2017-8422KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.EXPLOITHIGH 7.8EPSS 1.80%17 May 2017
CVE-2017-8382admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts.EXPLOITMEDIUM 4.5EPSS 2.63%16 May 2017
CVE-2017-7953INFOR EAM V11.0 Build 201410 has XSS via comment fields.EXPLOITMEDIUM 5.4EPSS 0.95%16 May 2017
CVE-2017-7952INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.EXPLOITHIGH 8.8EPSS 1.44%16 May 2017
CVE-2017-8927Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file.EXPLOITHIGH 7.8EPSS 3.01%15 May 2017
CVE-2017-8926Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file.EXPLOITHIGH 7.8EPSS 3.13%15 May 2017
CVE-2017-7478OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.EXPLOITHIGH 7.5EPSS 13.8%15 May 2017
CVE-2017-8928mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.EXPLOITHIGH 8.8EPSS 2.05%14 May 2017
CVE-2016-10277An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader.EXPLOITHIGH 7.8EPSS 9.68%12 May 2017
CVE-2017-0263Microsoft Win32k Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 10.0%12 May 2017
CVE-2017-0259The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows…EXPLOITMEDIUM 4.7EPSS 9.66%12 May 2017
CVE-2017-0258The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain…EXPLOITMEDIUM 4.7EPSS 7.36%12 May 2017
CVE-2017-0245The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local authenticated attacker to execute a specially crafted application to obtain kernel information, aka "Win32k Information Disclosure…EXPLOITMEDIUM 4.7EPSS 7.70%12 May 2017
CVE-2017-0220The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure…EXPLOITMEDIUM 4.7EPSS 7.46%12 May 2017
CVE-2017-0214Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when…EXPLOITHIGH 7.0EPSS 3.46%12 May 2017
CVE-2017-0213Microsoft Windows Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.3EPSS 84.1%12 May 2017
CVE-2017-0175The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different…EXPLOITMEDIUM 4.7EPSS 7.05%12 May 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.