SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,554 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 171 of 348

CVESummaryPriorityPublished
CVE-2017-8572Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka…MEDIUM 5.5EPSS 12.6%1 August 2017
CVE-2016-8743Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers.HIGH 7.5EPSS 13.3%27 July 2017
CVE-2016-2161In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.HIGH 7.5EPSS 21.0%27 July 2017
CVE-2016-0736This made it vulnerable to padding oracle attacks, particularly with CBC.HIGH 7.5EPSS 49.0%27 July 2017
CVE-2017-8870Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.HIGH 7.8EPSS 13.7%27 July 2017
CVE-2016-10402Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer overflow and heap-based buffer underflow.HIGH 7.8EPSS 10.2%27 July 2017
CVE-2017-8869Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.HIGH 7.8EPSS 15.9%27 July 2017
CVE-2017-7659A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the server process.HIGH 7.5EPSS 53.9%26 July 2017
CVE-2016-10401ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists within an ISP's deployment of these devices).HIGH 8.8EPSS 12.1%25 July 2017
CVE-2015-2280snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the mac parameter.HIGH 8.8EPSS 17.0%25 July 2017
CVE-2015-2279cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute arbitrary OS commands via shell metacharacters after an "&" (ampersand) in the write_mac write_pid,…CRITICAL 9.8EPSS 17.6%25 July 2017
CVE-2017-9554An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.MEDIUM 5.3EPSS 76.7%24 July 2017
CVE-2017-11517Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote attackers to execute arbitrary code via a long URI in a GET request.CRITICAL 9.8EPSS 29.1%21 July 2017
CVE-2017-9822DotNetNuke (DNN) Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 94.8%20 July 2017
CVE-2017-6316Citrix Multiple Products Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 73.0%20 July 2017
CVE-2017-9765Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and…HIGH 8.1EPSS 24.6%20 July 2017
CVE-2017-11467OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.CRITICAL 9.8EPSS 73.1%20 July 2017
CVE-2017-11444Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.CRITICAL 9.8EPSS 13.1%19 July 2017
CVE-2017-11435The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console.CRITICAL 9.8EPSS 10.1%19 July 2017
CVE-2017-6320A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1.006 (2016-08-19); fixed in 6.1.0.003 (2017-01-17)) in which an authenticated user can execute arbitrary shell…HIGH 8.8EPSS 11.1%18 July 2017
CVE-2017-11403The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.HIGH 8.8EPSS 28.3%18 July 2017
CVE-2017-9812The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges.HIGH 7.5EPSS 11.3%17 July 2017
CVE-2017-9811The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312).CRITICAL 9.8EPSS 10.5%17 July 2017
CVE-2017-6743Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 10.9%17 July 2017
CVE-2017-6742Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 21.4%17 July 2017
CVE-2017-6740Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 11.1%17 July 2017
CVE-2017-6739Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 10.9%17 July 2017
CVE-2017-6738Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 10.9%17 July 2017
CVE-2017-6737Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 45.2%17 July 2017
CVE-2017-6736Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 70.4%17 July 2017
CVE-2017-8011A remote attacker with the knowledge of the default password may potentially use these accounts to run arbitrary web service and remote procedure calls on the affected system.CRITICAL 9.8EPSS 14.0%17 July 2017
CVE-2017-11346Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.CRITICAL 9.8EPSS 43.3%17 July 2017
CVE-2017-1000028Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.HIGH 7.5EPSS 99.5%17 July 2017
CVE-2017-1000002ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution.CRITICAL 9.8EPSS 30.8%17 July 2017
CVE-2017-0196An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."MEDIUM 6.5EPSS 18.2%17 July 2017
CVE-2017-0152A remote code execution vulnerability exists in the way affected Microsoft scripting engine render when handling objects in memory in Microsoft browsers.HIGH 8.1EPSS 10.8%17 July 2017
CVE-2017-0028A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory.CRITICAL 9.8EPSS 18.9%17 July 2017
CVE-2017-9788Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.CRITICAL 9.1EPSS 56.8%13 July 2017
CVE-2017-9787When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack.HIGH 7.5EPSS 10.6%13 July 2017
CVE-2017-7529Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.HIGH 7.5EPSS 62.6%13 July 2017
CVE-2017-11165dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.CRITICAL 9.8EPSS 64.1%12 July 2017
CVE-2017-8619Microsoft Edge on Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way affected Microsoft scripting engines render when handling objects in memory, aka "Scripting Engine Memory Corruption…HIGH 7.5EPSS 15.9%11 July 2017
CVE-2017-8618Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 Internet Explorer in the way affected Microsoft…HIGH 7.5EPSS 58.1%11 July 2017
CVE-2017-8617Microsoft Edge in Windows 10 1703 Microsoft Edge allows a remote code execution vulnerability in the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsoft Edge Remote Code Execution Vulnerability."HIGH 7.5EPSS 11.0%11 July 2017
CVE-2017-8611Microsoft Edge on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows remote attackers to spoof web content via a crafted web site, aka "Microsoft Edge Spoofing Vulnerability."MEDIUM 6.5EPSS 11.5%11 July 2017
CVE-2017-8601Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in…HIGH 7.5EPSS 66.9%11 July 2017
CVE-2017-8594Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet…HIGH 7.5EPSS 50.4%11 July 2017
CVE-2017-8589Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows…CRITICAL 9.8EPSS 26.2%11 July 2017
CVE-2017-8588Microsoft WordPad in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way…HIGH 7.0EPSS 17.2%11 July 2017
CVE-2017-8570Microsoft Office Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 89.9%11 July 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.