Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,554 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 172 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-8565 | Windows PowerShell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability when PSObject… | HIGH 8.1EPSS 18.5% | 11 July 2017 |
| CVE-2017-8502 | Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". | HIGH 7.8EPSS 23.1% | 11 July 2017 |
| CVE-2017-8501 | Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". | HIGH 7.8EPSS 23.3% | 11 July 2017 |
| CVE-2017-8463 | Windows Shell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it… | HIGH 7.8EPSS 20.5% | 11 July 2017 |
| CVE-2017-0243 | Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". | HIGH 7.8EPSS 21.5% | 11 July 2017 |
| CVE-2017-9791 | Apache Struts 1 Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 98.9% | 10 July 2017 |
| CVE-2017-10974 | Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. | HIGH 7.5EPSS 81.2% | 7 July 2017 |
| CVE-2017-9248 | Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability | KEVCRITICAL 9.8EPSS 75.1% | 3 July 2017 |
| CVE-2017-6026 | This may allow a current session to be compromised. | CRITICAL 9.1EPSS 31.8% | 30 June 2017 |
| CVE-2017-8558 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10… | HIGH 7.8EPSS 43.6% | 29 June 2017 |
| CVE-2017-9993 | FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data. | HIGH 7.5EPSS 16.4% | 28 June 2017 |
| CVE-2017-9445 | A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it. | HIGH 7.5EPSS 54.8% | 28 June 2017 |
| CVE-2015-7780 | Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0. | MEDIUM 6.5EPSS 10.6% | 27 June 2017 |
| CVE-2014-6354 | Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11 allows remote attackers to execute arbitrary code. | HIGH 7.5EPSS 12.8% | 27 June 2017 |
| CVE-2017-9841 | PHPUnit Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 27 June 2017 |
| CVE-2017-6326 | The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. | CRITICAL 10.0EPSS 72.8% | 26 June 2017 |
| CVE-2017-9833 | /cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. | HIGH 7.5EPSS 68.5% | 24 June 2017 |
| CVE-2017-9829 | '/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. | HIGH 7.5EPSS 68.7% | 23 June 2017 |
| CVE-2017-9828 | '/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. | CRITICAL 9.8EPSS 82.5% | 23 June 2017 |
| CVE-2015-9098 | In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in the ability to execute arbitrary SQL commands on any monitored Microsoft SQL Server machines. | CRITICAL 9.8EPSS 14.1% | 22 June 2017 |
| CVE-2017-0176 | A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a… | HIGH 8.1EPSS 45.8% | 22 June 2017 |
| CVE-2012-6706 | A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. | CRITICAL 9.8EPSS 10.0% | 22 June 2017 |
| CVE-2017-2805 | An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. | CRITICAL 9.8EPSS 26.2% | 21 June 2017 |
| CVE-2017-3083 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the Primetime SDK functionality related to the profile metadata of the media stream. | CRITICAL 9.8EPSS 14.4% | 20 June 2017 |
| CVE-2017-3082 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the LocaleID class. | CRITICAL 9.8EPSS 11.7% | 20 June 2017 |
| CVE-2017-3081 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability during internal computation caused by multiple display object mask manipulations. | CRITICAL 9.8EPSS 14.4% | 20 June 2017 |
| CVE-2017-3078 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. | CRITICAL 9.8EPSS 30.9% | 20 June 2017 |
| CVE-2017-3077 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. | CRITICAL 9.8EPSS 22.3% | 20 June 2017 |
| CVE-2017-3076 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module. | CRITICAL 9.8EPSS 24.7% | 20 June 2017 |
| CVE-2017-7679 | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header. | CRITICAL 9.8EPSS 39.3% | 20 June 2017 |
| CVE-2017-7668 | The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. | HIGH 7.5EPSS 57.5% | 20 June 2017 |
| CVE-2017-3169 | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port. | CRITICAL 9.8EPSS 20.0% | 20 June 2017 |
| CVE-2017-3167 | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed. | CRITICAL 9.8EPSS 20.2% | 20 June 2017 |
| CVE-2017-1000375 | NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. | CRITICAL 9.8EPSS 18.9% | 19 June 2017 |
| CVE-2017-1000373 | The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. | MEDIUM 6.5EPSS 13.4% | 19 June 2017 |
| CVE-2017-9757 | IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. | HIGH 8.8EPSS 37.2% | 19 June 2017 |
| CVE-2017-8487 | Windows OLE in Windows XP and Windows Server 2003 allows an attacker to execute code when a victim opens a specially crafted file or program aka "Windows olecnv32.dll Remote Code Execution Vulnerability." | HIGH 7.8EPSS 62.5% | 15 June 2017 |
| CVE-2017-8461 | Windows RPC with Routing and Remote Access enabled in Windows XP and Windows Server 2003 allows an attacker to execute code on a targeted RPC server which has Routing and Remote Access enabled via a specially crafted application, aka "Windows RPC Remote… | HIGH 7.8EPSS 20.4% | 15 June 2017 |
| CVE-2017-9675 | On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot. | HIGH 7.5EPSS 12.1% | 15 June 2017 |
| CVE-2017-8555 | Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge… | MEDIUM 4.3EPSS 12.5% | 15 June 2017 |
| CVE-2017-8550 | A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability". | MEDIUM 5.4EPSS 22.4% | 15 June 2017 |
| CVE-2017-8548 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system when Microsoft Edge improperly handles objects in memory, aka "Scripting Engine… | HIGH 7.5EPSS 67.6% | 15 June 2017 |
| CVE-2017-8543 | Microsoft Windows Search Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 74.2% | 15 June 2017 |
| CVE-2017-8529 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to detect specific files on the user's computer when affected Microsoft scripting engines do not… | MEDIUM 6.5EPSS 14.2% | 15 June 2017 |
| CVE-2017-8528 | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows a remote code… | HIGH 8.8EPSS 19.9% | 15 June 2017 |
| CVE-2017-8527 | Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it… | HIGH 8.8EPSS 19.0% | 15 June 2017 |
| CVE-2017-8513 | A remote code execution vulnerability exists in Microsoft PowerPoint when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability". | HIGH 7.8EPSS 17.1% | 15 June 2017 |
| CVE-2017-8512 | A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". | HIGH 8.8EPSS 22.1% | 15 June 2017 |
| CVE-2017-8511 | A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". | HIGH 7.8EPSS 20.6% | 15 June 2017 |
| CVE-2017-8510 | A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". | HIGH 8.8EPSS 22.1% | 15 June 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.