SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,540 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 164 of 348

CVESummaryPriorityPublished
CVE-2017-16385The vulnerability is caused by a buffer access with an incorrect length value in TIFF parsing during XPS conversion.HIGH 8.8EPSS 12.8%9 December 2017
CVE-2017-16383This vulnerability is an instance of a heap overflow vulnerability when processing a JPEG file embedded within an XPS document.HIGH 8.8EPSS 10.7%9 December 2017
CVE-2017-16381The vulnerability is caused by a buffer access with an incorrect length value when processing TIFF files embedded within an XPS document.HIGH 8.8EPSS 12.8%9 December 2017
CVE-2017-16368This vulnerability leads to a stack-based buffer overflow condition in the internal Unicode string manipulation module.HIGH 8.8EPSS 13.2%9 December 2017
CVE-2017-16921In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell…HIGH 8.8EPSS 19.9%8 December 2017
CVE-2017-11940The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft…HIGH 7.8EPSS 19.8%8 December 2017
CVE-2017-11937The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft…HIGH 7.8EPSS 28.3%7 December 2017
CVE-2017-3738There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli.MEDIUM 5.9EPSS 13.4%7 December 2017
CVE-2017-3737OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism.MEDIUM 5.9EPSS 78.7%7 December 2017
CVE-2017-13156An elevation of privilege vulnerability in the Android system (art).HIGH 7.8EPSS 20.5%6 December 2017
CVE-2017-16930The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler.CRITICAL 9.8EPSS 34.3%5 December 2017
CVE-2017-16929The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by issuing a specially crafted request, allowing a remote attacker to read/write arbitrary files.HIGH 8.1EPSS 12.9%5 December 2017
CVE-2017-15889Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.HIGH 8.8EPSS 73.7%4 December 2017
CVE-2017-17099There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16.HIGH 7.8EPSS 11.8%3 December 2017
CVE-2017-17095tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.HIGH 8.8EPSS 10.6%2 December 2017
CVE-2017-17090An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older.HIGH 7.5EPSS 81.5%2 December 2017
CVE-2017-16953connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.HIGH 7.5EPSS 11.3%1 December 2017
CVE-2017-17085In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash.HIGH 7.5EPSS 16.8%1 December 2017
CVE-2017-11284Adobe ColdFusion has an Untrusted Data Deserialization vulnerability.CRITICAL 9.8EPSS 42.7%1 December 2017
CVE-2017-11283Adobe ColdFusion has an Untrusted Data Deserialization vulnerability.CRITICAL 9.8EPSS 42.7%1 December 2017
CVE-2017-11282Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser.CRITICAL 9.8EPSS 34.8%1 December 2017
CVE-2017-11281Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function.CRITICAL 9.8EPSS 33.9%1 December 2017
CVE-2017-8817The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.CRITICAL 9.8EPSS 11.2%29 November 2017
CVE-2017-13872It allows attackers to obtain administrator access without a password via certain interactions involving entry of the root user name.HIGH 8.1EPSS 36.8%29 November 2017
CVE-2017-17058The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory.HIGH 7.5EPSS 23.7%29 November 2017
CVE-2017-15275Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.HIGH 7.5EPSS 21.4%27 November 2017
CVE-2017-16944The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character…HIGH 7.5EPSS 63.3%25 November 2017
CVE-2017-16943The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.CRITICAL 9.8EPSS 46.7%25 November 2017
CVE-2017-16934The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a…CRITICAL 9.8EPSS 13.5%24 November 2017
CVE-2017-16894In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI.HIGH 7.5EPSS 86.9%20 November 2017
CVE-2017-6168On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3) a virtual server configured with a Client SSL profile may be vulnerable to an Adaptive Chosen Ciphertext attack…HIGH 7.4EPSS 19.6%17 November 2017
CVE-2017-1000170jqueryFileTree 2.1.5 and older Directory TraversalHIGH 7.5EPSS 59.1%17 November 2017
CVE-2017-16877ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.HIGH 7.5EPSS 14.1%17 November 2017
CVE-2017-16851Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.CRITICAL 9.8EPSS 16.6%16 November 2017
CVE-2017-16850Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.CRITICAL 9.8EPSS 16.6%16 November 2017
CVE-2017-16849Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.CRITICAL 9.8EPSS 16.6%16 November 2017
CVE-2017-16848Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.CRITICAL 9.8EPSS 15.1%16 November 2017
CVE-2017-16847Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.CRITICAL 9.8EPSS 16.6%16 November 2017
CVE-2017-16846Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.CRITICAL 9.8EPSS 16.6%16 November 2017
CVE-2017-16844Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded…CRITICAL 9.8EPSS 12.5%16 November 2017
CVE-2017-15806The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted…HIGH 8.1EPSS 10.7%15 November 2017
CVE-2017-8700ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability".HIGH 7.5EPSS 10.5%15 November 2017
CVE-2017-11882Microsoft Office Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 99.9%15 November 2017
CVE-2017-11873ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka…HIGH 7.5EPSS 69.8%15 November 2017
CVE-2017-11870ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory…HIGH 7.5EPSS 59.6%15 November 2017
CVE-2017-11861Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine…HIGH 7.5EPSS 64.2%15 November 2017
CVE-2017-11855Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an…HIGH 7.5EPSS 48.6%15 November 2017
CVE-2017-11853Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a…MEDIUM 5.5EPSS 11.0%15 November 2017
CVE-2017-11841ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in…HIGH 7.5EPSS 59.6%15 November 2017
CVE-2017-11840ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in…HIGH 7.5EPSS 59.6%15 November 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.