Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 29 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2015-2291 | Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability | KEVHIGH 7.8EPSS 9.01% | 9 August 2017 |
| CVE-2017-12637 | SAP NetWeaver Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 95.1% | 7 August 2017 |
| CVE-2017-6663 | Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability | KEVMEDIUM 6.5EPSS 2.14% | 7 August 2017 |
| CVE-2017-9822 | DotNetNuke (DNN) Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 94.8% | 20 July 2017 |
| CVE-2017-6316 | Citrix Multiple Products Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 72.6% | 20 July 2017 |
| CVE-2017-6744 | Cisco IOS Software SNMP Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 7.16% | 17 July 2017 |
| CVE-2017-6743 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 10.7% | 17 July 2017 |
| CVE-2017-6742 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 21.4% | 17 July 2017 |
| CVE-2017-6740 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 10.9% | 17 July 2017 |
| CVE-2017-6739 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 10.7% | 17 July 2017 |
| CVE-2017-6738 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 10.7% | 17 July 2017 |
| CVE-2017-6737 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 44.3% | 17 July 2017 |
| CVE-2017-6736 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 70.6% | 17 July 2017 |
| CVE-2017-8570 | Microsoft Office Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 89.9% | 11 July 2017 |
| CVE-2017-9791 | Apache Struts 1 Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 98.9% | 10 July 2017 |
| CVE-2017-9248 | Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability | KEVCRITICAL 9.8EPSS 75.1% | 3 July 2017 |
| CVE-2017-9841 | PHPUnit Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 27 June 2017 |
| CVE-2017-8543 | Microsoft Windows Search Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 74.3% | 15 June 2017 |
| CVE-2017-8464 | Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 90.0% | 15 June 2017 |
| CVE-2016-7836 | SKYSEA Client View Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 19.4% | 9 June 2017 |
| CVE-2017-7494 | Samba Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 30 May 2017 |
| CVE-2017-8540 | Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability | KEVHIGH 7.8EPSS 72.0% | 26 May 2017 |
| CVE-2017-6862 | NETGEAR Multiple Devices Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 42.7% | 26 May 2017 |
| CVE-2017-0263 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 10.0% | 12 May 2017 |
| CVE-2017-0262 | Microsoft Office Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 81.0% | 12 May 2017 |
| CVE-2017-0261 | Microsoft Office Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 78.1% | 12 May 2017 |
| CVE-2017-0222 | Microsoft Internet Explorer Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 29.6% | 12 May 2017 |
| CVE-2017-0213 | Microsoft Windows Privilege Escalation Vulnerability | KEVHIGH 7.3EPSS 84.1% | 12 May 2017 |
| CVE-2017-7921 | Hikvision Multiple Products Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 6 May 2017 |
| CVE-2017-5689 | Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability | KEVCRITICAL 9.8EPSS 92.2% | 2 May 2017 |
| CVE-2017-3066 | Adobe ColdFusion Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 90.6% | 27 April 2017 |
| CVE-2017-8291 | Artifex Ghostscript Type Confusion Vulnerability | KEVHIGH 7.8EPSS 97.0% | 27 April 2017 |
| CVE-2017-5030 | Google Chromium V8 Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 41.7% | 24 April 2017 |
| CVE-2017-3506 | Oracle WebLogic Server OS Command Injection Vulnerability | KEVHIGH 7.4EPSS 96.3% | 24 April 2017 |
| CVE-2016-1555 | NETGEAR Multiple WAP Devices Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 21 April 2017 |
| CVE-2017-0210 | Microsoft Internet Explorer Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 22.3% | 12 April 2017 |
| CVE-2017-0199 | Microsoft Office and WordPad Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 99.9% | 12 April 2017 |
| CVE-2016-8735 | Apache Tomcat Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 90.3% | 6 April 2017 |
| CVE-2017-6884 | Zyxel EMG2926 Routers Command Injection Vulnerability | KEVHIGH 8.8EPSS 36.8% | 6 April 2017 |
| CVE-2014-3931 | Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 29.0% | 31 March 2017 |
| CVE-2017-7269 | Microsoft Windows Server Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 27 March 2017 |
| CVE-2017-3881 | Cisco IOS and IOS XE Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.0% | 17 March 2017 |
| CVE-2017-0149 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 29.2% | 17 March 2017 |
| CVE-2017-0148 | Microsoft SMBv1 Server Remote Code Execution Vulnerability | KEVHIGH 8.1EPSS 99.4% | 17 March 2017 |
| CVE-2017-0147 | Microsoft Windows SMBv1 Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 99.7% | 17 March 2017 |
| CVE-2017-0146 | Microsoft Windows SMB Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 89.9% | 17 March 2017 |
| CVE-2017-0145 | Microsoft SMBv1 Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 89.8% | 17 March 2017 |
| CVE-2017-0144 | Microsoft SMBv1 Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 99.2% | 17 March 2017 |
| CVE-2017-0143 | Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 93.3% | 17 March 2017 |
| CVE-2017-0101 | Microsoft Windows Transaction Manager Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 57.5% | 17 March 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.