SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 94 of 501

CVESummaryPriorityPublished
CVE-2017-6880Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long MLST command.EXPLOITCRITICAL 9.8EPSS 14.3%17 March 2017
CVE-2014-8722GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>.xml.bak, (3) data/other/authorization.xml, or (4) data/other/appid.xml.EXPLOITHIGH 7.5EPSS 14.4%17 March 2017
CVE-2017-0148Microsoft SMBv1 Server Remote Code Execution VulnerabilityKEVEXPLOIT ×3HIGH 8.1EPSS 99.4%17 March 2017
CVE-2017-0147Microsoft Windows SMBv1 Information Disclosure VulnerabilityKEVEXPLOIT ×4HIGH 7.5EPSS 99.7%17 March 2017
CVE-2017-0146Microsoft Windows SMB Remote Code Execution VulnerabilityKEVEXPLOIT ×4HIGH 8.8EPSS 89.9%17 March 2017
CVE-2017-0145Microsoft SMBv1 Remote Code Execution VulnerabilityKEVEXPLOIT ×3HIGH 8.8EPSS 89.8%17 March 2017
CVE-2017-0144Microsoft SMBv1 Remote Code Execution VulnerabilityKEVEXPLOIT ×6HIGH 8.8EPSS 99.2%17 March 2017
CVE-2017-0143Microsoft Windows Server Message Block (SMBv1) Remote Code Execution VulnerabilityKEVEXPLOIT ×4HIGH 8.8EPSS 93.3%17 March 2017
CVE-2017-0128Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0127Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0126Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0125Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0124Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0123Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0122Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0121Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain…EXPLOITMEDIUM 4.3EPSS 42.1%17 March 2017
CVE-2017-0120Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows Uniscribe Information Disclosure…EXPLOITMEDIUM 4.3EPSS 22.0%17 March 2017
CVE-2017-0119Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0118Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain…EXPLOITMEDIUM 4.3EPSS 23.0%17 March 2017
CVE-2017-0117Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0116Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0115Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0114Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0113Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0112Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0111Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0108The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows…EXPLOITHIGH 7.8EPSS 50.5%17 March 2017
CVE-2017-0103The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 mishandles registry objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Registry…EXPLOITHIGH 7.0EPSS 2.94%17 March 2017
CVE-2017-0101Microsoft Windows Transaction Manager Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 57.5%17 March 2017
CVE-2017-0100A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows local users to gain privileges via a crafted…EXPLOITHIGH 7.8EPSS 4.96%17 March 2017
CVE-2017-0092Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0091Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0090Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is…EXPLOITHIGH 8.8EPSS 42.5%17 March 2017
CVE-2017-0089Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is…EXPLOITHIGH 8.8EPSS 57.3%17 March 2017
CVE-2017-0088Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Uniscribe Remote Code Execution Vulnerability."EXPLOITHIGH 8.8EPSS 41.9%17 March 2017
CVE-2017-0087Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is…EXPLOITHIGH 8.8EPSS 42.5%17 March 2017
CVE-2017-0086Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is…EXPLOITHIGH 8.8EPSS 42.5%17 March 2017
CVE-2017-0085Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability."…EXPLOITMEDIUM 4.3EPSS 22.5%17 March 2017
CVE-2017-0084Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute…EXPLOITHIGH 8.8EPSS 36.5%17 March 2017
CVE-2017-0083Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is…EXPLOITHIGH 8.8EPSS 42.5%17 March 2017
CVE-2017-0072Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is…EXPLOITHIGH 8.8EPSS 42.5%17 March 2017
CVE-2017-0070A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.EXPLOITHIGH 7.5EPSS 78.5%17 March 2017
CVE-2017-0063The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and R2; and Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows…EXPLOITMEDIUM 6.5EPSS 35.3%17 March 2017
CVE-2017-0062The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain…EXPLOITMEDIUM 4.7EPSS 17.8%17 March 2017
CVE-2017-0061The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2, Windows Server 2008 SP2 and R2, and Windows 7 SP1 allows remote attackers to bypass ASLR and execute code in combination with another vulnerability through a…EXPLOITMEDIUM 5.3EPSS 43.1%17 March 2017
CVE-2017-0060The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain…EXPLOITMEDIUM 5.5EPSS 15.9%17 March 2017
CVE-2017-0059Microsoft Internet Explorer Information Disclosure VulnerabilityKEVEXPLOIT ×3MEDIUM 4.3EPSS 62.0%17 March 2017
CVE-2017-0045Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site…EXPLOITMEDIUM 5.5EPSS 6.58%17 March 2017
CVE-2017-6443Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 parameter to Forms/oadmin_1.EXPLOITMEDIUM 6.1EPSS 3.33%15 March 2017
CVE-2017-5496Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.EXPLOITCRITICAL 9.8EPSS 5.77%15 March 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.