Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,540 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 168 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-8748 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to… | HIGH 7.5EPSS 11.8% | 13 September 2017 |
| CVE-2017-8747 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context… | HIGH 7.5EPSS 10.8% | 13 September 2017 |
| CVE-2017-8744 | A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, and Microsoft Excel 2016 when they… | HIGH 7.8EPSS 17.9% | 13 September 2017 |
| CVE-2017-8743 | A remote code execution vulnerability exists in Microsoft PowerPoint 2016, Microsoft SharePoint Enterprise Server 2016, and Office Online Server when they fail to properly handle objects in memory, aka "PowerPoint Remote Code Execution Vulnerability". | HIGH 7.8EPSS 22.1% | 13 September 2017 |
| CVE-2017-8742 | A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft PowerPoint 2010 Service Pack 2, Microsoft PowerPoint 2013 Service Pack 1, Microsoft PowerPoint 2013 RT Service Pack 1, Microsoft PowerPoint 2016,… | HIGH 7.8EPSS 22.1% | 13 September 2017 |
| CVE-2017-8741 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an… | HIGH 7.5EPSS 11.9% | 13 September 2017 |
| CVE-2017-8740 | Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption… | HIGH 7.5EPSS 72.2% | 13 September 2017 |
| CVE-2017-8737 | Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the… | HIGH 7.5EPSS 21.5% | 13 September 2017 |
| CVE-2017-8734 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge… | HIGH 7.5EPSS 52.5% | 13 September 2017 |
| CVE-2017-8731 | Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption… | HIGH 7.5EPSS 51.6% | 13 September 2017 |
| CVE-2017-8729 | Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption… | HIGH 7.5EPSS 72.2% | 13 September 2017 |
| CVE-2017-8728 | Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the… | HIGH 7.5EPSS 21.5% | 13 September 2017 |
| CVE-2017-8725 | A remote code execution vulnerability exists in Microsoft Publisher 2007 Service Pack 3 and Microsoft Publisher 2010 Service Pack 2 when they fail to properly handle objects in memory, aka "Microsoft Office Publisher Remote Code Execution". | HIGH 7.8EPSS 20.3% | 13 September 2017 |
| CVE-2017-8710 | The Microsoft Common Console Document (.msc) in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1 allows an attacker to read arbitrary files via an XML external entity (XXE) declaration, due to the way that the Microsoft Common Console… | MEDIUM 5.5EPSS 10.4% | 13 September 2017 |
| CVE-2017-8699 | Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to run arbitrary code in the context of… | HIGH 7.0EPSS 21.3% | 13 September 2017 |
| CVE-2017-8696 | Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007… | HIGH 7.5EPSS 14.3% | 13 September 2017 |
| CVE-2017-8692 | The Windows Uniscribe component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows remote code execution vulnerability when it fails to properly handle objects… | HIGH 7.5EPSS 16.9% | 13 September 2017 |
| CVE-2017-8686 | The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption… | CRITICAL 9.8EPSS 27.5% | 13 September 2017 |
| CVE-2017-8683 | Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an attacker to execute remote code by… | MEDIUM 5.5EPSS 22.6% | 13 September 2017 |
| CVE-2017-8682 | Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office… | HIGH 8.8EPSS 49.8% | 13 September 2017 |
| CVE-2017-8676 | The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010… | LOW 3.3EPSS 14.0% | 13 September 2017 |
| CVE-2017-8660 | Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft browser JavaScript engines render content when handling… | HIGH 8.8EPSS 10.1% | 13 September 2017 |
| CVE-2017-8632 | A remote code execution vulnerability exists in Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Excel for Mac 2011,… | HIGH 7.8EPSS 17.7% | 13 September 2017 |
| CVE-2017-8631 | A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office… | HIGH 7.8EPSS 17.0% | 13 September 2017 |
| CVE-2017-8630 | Microsoft Office 2016 allows a remote code execution vulnerability when it fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". | HIGH 7.8EPSS 21.0% | 13 September 2017 |
| CVE-2017-8567 | A remote code execution vulnerability exists in Microsoft Excel for Mac 2011 when it fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution". | HIGH 7.8EPSS 20.3% | 13 September 2017 |
| CVE-2017-11764 | Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting… | HIGH 7.5EPSS 64.4% | 13 September 2017 |
| CVE-2017-0161 | The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code… | HIGH 8.1EPSS 11.2% | 13 September 2017 |
| CVE-2017-1000251 | The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote… | HIGH 8.0EPSS 16.2% | 12 September 2017 |
| CVE-2017-14335 | On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change. | HIGH 7.5EPSS 27.8% | 12 September 2017 |
| CVE-2017-3133 | A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN. | MEDIUM 6.1EPSS 10.7% | 12 September 2017 |
| CVE-2015-8351 | PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to… | CRITICAL 9.0EPSS 37.0% | 11 September 2017 |
| CVE-2017-14147 | An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply browsing to the link http://[Default-Router-IP]/restoreinfo.cgi & execute it. | CRITICAL 9.8EPSS 65.6% | 7 September 2017 |
| CVE-2017-12794 | Given the right circumstances, this allowed a cross-site scripting attack. | MEDIUM 6.1EPSS 23.6% | 7 September 2017 |
| CVE-2015-7241 | XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01. | CRITICAL 9.8EPSS 13.5% | 6 September 2017 |
| CVE-2017-1130 | IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. | MEDIUM 6.5EPSS 29.2% | 5 September 2017 |
| CVE-2017-1129 | IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. | MEDIUM 6.5EPSS 30.1% | 5 September 2017 |
| CVE-2017-1000083 | backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option… | HIGH 7.8EPSS 51.1% | 5 September 2017 |
| CVE-2017-14135 | enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the command parameter to the /script URI. | CRITICAL 9.8EPSS 21.8% | 4 September 2017 |
| CVE-2017-14100 | In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. | CRITICAL 9.8EPSS 14.9% | 2 September 2017 |
| CVE-2017-14098 | In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash. | HIGH 7.5EPSS 50.1% | 2 September 2017 |
| CVE-2017-3897 | A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file… | CRITICAL 9.8EPSS 11.7% | 1 September 2017 |
| CVE-2017-14103 | The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers after certain error conditions, which allows remote attackers to conduct use-after-free attacks via a crafted file, related to… | HIGH 8.8EPSS 30.2% | 1 September 2017 |
| CVE-2015-5958 | phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL. | HIGH 8.8EPSS 27.4% | 31 August 2017 |
| CVE-2014-8676 | Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. | MEDIUM 5.3EPSS 40.8% | 31 August 2017 |
| CVE-2014-8675 | Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password via a brute-force attack on the embedded password hash. | HIGH 7.5EPSS 12.5% | 31 August 2017 |
| CVE-2017-0901 | RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem. | HIGH 7.5EPSS 29.4% | 31 August 2017 |
| CVE-2017-0899 | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. | CRITICAL 9.8EPSS 10.8% | 31 August 2017 |
| CVE-2017-13708 | Buffer overflow in the web server service in VX Search Enterprise 10.0.14 allows remote attackers to execute arbitrary code via a crafted GET request. | CRITICAL 9.8EPSS 11.7% | 31 August 2017 |
| CVE-2017-3735 | While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. | MEDIUM 5.3EPSS 21.0% | 28 August 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.