SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,554 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 172 of 348

CVESummaryPriorityPublished
CVE-2017-8565Windows PowerShell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability when PSObject…HIGH 8.1EPSS 18.5%11 July 2017
CVE-2017-8502Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability".HIGH 7.8EPSS 23.1%11 July 2017
CVE-2017-8501Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability".HIGH 7.8EPSS 23.3%11 July 2017
CVE-2017-8463Windows Shell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it…HIGH 7.8EPSS 20.5%11 July 2017
CVE-2017-0243Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability".HIGH 7.8EPSS 21.5%11 July 2017
CVE-2017-9791Apache Struts 1 Improper Input Validation VulnerabilityKEVCRITICAL 9.8EPSS 98.9%10 July 2017
CVE-2017-10974Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080.HIGH 7.5EPSS 81.2%7 July 2017
CVE-2017-9248Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness VulnerabilityKEVCRITICAL 9.8EPSS 75.1%3 July 2017
CVE-2017-6026This may allow a current session to be compromised.CRITICAL 9.1EPSS 31.8%30 June 2017
CVE-2017-8558The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10…HIGH 7.8EPSS 43.6%29 June 2017
CVE-2017-9993FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.HIGH 7.5EPSS 16.4%28 June 2017
CVE-2017-9445A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.HIGH 7.5EPSS 54.8%28 June 2017
CVE-2015-7780Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.MEDIUM 6.5EPSS 10.6%27 June 2017
CVE-2014-6354Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11 allows remote attackers to execute arbitrary code.HIGH 7.5EPSS 12.8%27 June 2017
CVE-2017-9841PHPUnit Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%27 June 2017
CVE-2017-6326The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process.CRITICAL 10.0EPSS 72.8%26 June 2017
CVE-2017-9833/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges.HIGH 7.5EPSS 68.5%24 June 2017
CVE-2017-9829'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences.HIGH 7.5EPSS 68.7%23 June 2017
CVE-2017-9828'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request.CRITICAL 9.8EPSS 82.5%23 June 2017
CVE-2015-9098In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in the ability to execute arbitrary SQL commands on any monitored Microsoft SQL Server machines.CRITICAL 9.8EPSS 14.1%22 June 2017
CVE-2017-0176A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a…HIGH 8.1EPSS 45.8%22 June 2017
CVE-2012-6706A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution.CRITICAL 9.8EPSS 10.0%22 June 2017
CVE-2017-2805An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera.CRITICAL 9.8EPSS 26.2%21 June 2017
CVE-2017-3083Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the Primetime SDK functionality related to the profile metadata of the media stream.CRITICAL 9.8EPSS 14.4%20 June 2017
CVE-2017-3082Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the LocaleID class.CRITICAL 9.8EPSS 11.7%20 June 2017
CVE-2017-3081Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability during internal computation caused by multiple display object mask manipulations.CRITICAL 9.8EPSS 14.4%20 June 2017
CVE-2017-3078Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module.CRITICAL 9.8EPSS 30.9%20 June 2017
CVE-2017-3077Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser.CRITICAL 9.8EPSS 22.3%20 June 2017
CVE-2017-3076Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module.CRITICAL 9.8EPSS 24.7%20 June 2017
CVE-2017-7679In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.CRITICAL 9.8EPSS 39.3%20 June 2017
CVE-2017-7668The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string.HIGH 7.5EPSS 57.5%20 June 2017
CVE-2017-3169In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.CRITICAL 9.8EPSS 20.0%20 June 2017
CVE-2017-3167In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.CRITICAL 9.8EPSS 20.2%20 June 2017
CVE-2017-1000375NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution.CRITICAL 9.8EPSS 18.9%19 June 2017
CVE-2017-1000373The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times.MEDIUM 6.5EPSS 13.4%19 June 2017
CVE-2017-9757IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell.HIGH 8.8EPSS 37.2%19 June 2017
CVE-2017-8487Windows OLE in Windows XP and Windows Server 2003 allows an attacker to execute code when a victim opens a specially crafted file or program aka "Windows olecnv32.dll Remote Code Execution Vulnerability."HIGH 7.8EPSS 62.5%15 June 2017
CVE-2017-8461Windows RPC with Routing and Remote Access enabled in Windows XP and Windows Server 2003 allows an attacker to execute code on a targeted RPC server which has Routing and Remote Access enabled via a specially crafted application, aka "Windows RPC Remote…HIGH 7.8EPSS 20.4%15 June 2017
CVE-2017-9675On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.HIGH 7.5EPSS 12.1%15 June 2017
CVE-2017-8555Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge…MEDIUM 4.3EPSS 12.5%15 June 2017
CVE-2017-8550A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability".MEDIUM 5.4EPSS 22.4%15 June 2017
CVE-2017-8548Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system when Microsoft Edge improperly handles objects in memory, aka "Scripting Engine…HIGH 7.5EPSS 67.6%15 June 2017
CVE-2017-8543Microsoft Windows Search Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 74.2%15 June 2017
CVE-2017-8529Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to detect specific files on the user's computer when affected Microsoft scripting engines do not…MEDIUM 6.5EPSS 14.2%15 June 2017
CVE-2017-8528Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows a remote code…HIGH 8.8EPSS 19.9%15 June 2017
CVE-2017-8527Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it…HIGH 8.8EPSS 19.0%15 June 2017
CVE-2017-8513A remote code execution vulnerability exists in Microsoft PowerPoint when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability".HIGH 7.8EPSS 17.1%15 June 2017
CVE-2017-8512A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability".HIGH 8.8EPSS 22.1%15 June 2017
CVE-2017-8511A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability".HIGH 7.8EPSS 20.6%15 June 2017
CVE-2017-8510A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability".HIGH 8.8EPSS 22.1%15 June 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.