Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,554 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 173 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-8509 | A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". | HIGH 8.8EPSS 18.2% | 15 June 2017 |
| CVE-2017-8507 | A remote code execution vulnerability exists in the way Microsoft Office software parses specially crafted email messages, aka "Microsoft Office Memory Corruption Vulnerability". | HIGH 7.8EPSS 19.6% | 15 June 2017 |
| CVE-2017-8506 | A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". | HIGH 7.8EPSS 24.2% | 15 June 2017 |
| CVE-2017-8496 | Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". | HIGH 7.5EPSS 51.5% | 15 June 2017 |
| CVE-2017-8464 | Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 89.9% | 15 June 2017 |
| CVE-2017-0294 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute remote code when Windows fails to… | HIGH 7.8EPSS 17.4% | 15 June 2017 |
| CVE-2017-0292 | Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows remote code execution if a user opens a specially crafted PDF file, aka "Windows PDF Remote Code Execution… | HIGH 7.8EPSS 24.2% | 15 June 2017 |
| CVE-2017-0291 | Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows remote code execution if a user opens a specially crafted PDF file, aka "Windows PDF Remote Code Execution… | HIGH 7.8EPSS 20.5% | 15 June 2017 |
| CVE-2017-0283 | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office Word… | HIGH 8.8EPSS 39.0% | 15 June 2017 |
| CVE-2017-0260 | A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". | HIGH 7.8EPSS 19.9% | 15 June 2017 |
| CVE-2017-0215 | Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code… | MEDIUM 5.3EPSS 35.8% | 15 June 2017 |
| CVE-2017-4971 | Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not… | MEDIUM 5.9EPSS 16.8% | 13 June 2017 |
| CVE-2017-9544 | There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1. | CRITICAL 9.8EPSS 24.1% | 12 June 2017 |
| CVE-2017-8871 | The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file. | MEDIUM 6.5EPSS 13.0% | 12 June 2017 |
| CVE-2016-7836 | SKYSEA Client View Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 19.2% | 9 June 2017 |
| CVE-2014-8687 | Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens. | CRITICAL 9.8EPSS 43.8% | 8 June 2017 |
| CVE-2017-6640 | A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. | CRITICAL 9.8EPSS 10.7% | 8 June 2017 |
| CVE-2017-6639 | A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an… | CRITICAL 9.8EPSS 35.4% | 8 June 2017 |
| CVE-2017-4901 | The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. | CRITICAL 9.9EPSS 19.9% | 8 June 2017 |
| CVE-2015-5175 | Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service. | HIGH 7.5EPSS 10.9% | 7 June 2017 |
| CVE-2017-9355 | XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file. | HIGH 7.4EPSS 26.9% | 7 June 2017 |
| CVE-2017-9462 | In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name. | HIGH 8.8EPSS 21.7% | 6 June 2017 |
| CVE-2017-5664 | The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwarded to the error page. | HIGH 7.5EPSS 16.6% | 6 June 2017 |
| CVE-2017-8835 | SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. | CRITICAL 9.8EPSS 61.6% | 5 June 2017 |
| CVE-2017-9430 | Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishandled in a strcpy call for argv[0]. | CRITICAL 9.8EPSS 11.3% | 5 June 2017 |
| CVE-2017-9417 | Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue. | CRITICAL 9.8EPSS 64.0% | 4 June 2017 |
| CVE-2017-9380 | OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application. | HIGH 8.8EPSS 15.2% | 2 June 2017 |
| CVE-2017-9353 | In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. | HIGH 7.5EPSS 14.0% | 2 June 2017 |
| CVE-2017-9347 | In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. | HIGH 7.5EPSS 14.2% | 2 June 2017 |
| CVE-2017-8386 | git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain… | HIGH 8.8EPSS 12.4% | 1 June 2017 |
| CVE-2015-5473 | Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary files via unspecified parameters to (1) upload/updateDriver or (2) upload/addDriver or to execute arbitrary code with SYSTEM… | CRITICAL 9.8EPSS 12.6% | 1 June 2017 |
| CVE-2015-0936 | Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key. | CRITICAL 9.8EPSS 78.1% | 1 June 2017 |
| CVE-2017-7494 | Samba Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 30 May 2017 |
| CVE-2017-9232 | Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root. | CRITICAL 9.8EPSS 48.5% | 28 May 2017 |
| CVE-2017-8541 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and… | HIGH 7.8EPSS 48.1% | 26 May 2017 |
| CVE-2017-8540 | Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability | KEVHIGH 7.8EPSS 71.9% | 26 May 2017 |
| CVE-2017-8538 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and… | HIGH 7.8EPSS 50.0% | 26 May 2017 |
| CVE-2017-8537 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and… | MEDIUM 5.5EPSS 16.8% | 26 May 2017 |
| CVE-2017-8536 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and… | MEDIUM 5.5EPSS 16.8% | 26 May 2017 |
| CVE-2017-8535 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and… | MEDIUM 5.5EPSS 16.8% | 26 May 2017 |
| CVE-2017-6862 | NETGEAR Multiple Devices Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 43.3% | 26 May 2017 |
| CVE-2016-4977 | When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution… | HIGH 8.8EPSS 79.2% | 25 May 2017 |
| CVE-2017-2824 | An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. | HIGH 8.1EPSS 25.9% | 24 May 2017 |
| CVE-2017-9217 | systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section. | HIGH 7.5EPSS 15.3% | 24 May 2017 |
| CVE-2016-10073 | The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password… | HIGH 7.5EPSS 83.6% | 23 May 2017 |
| CVE-2015-5469 | Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php. | HIGH 7.5EPSS 10.1% | 23 May 2017 |
| CVE-2015-5468 | Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. | HIGH 7.5EPSS 24.1% | 23 May 2017 |
| CVE-2015-4455 | Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then… | CRITICAL 9.8EPSS 40.6% | 23 May 2017 |
| CVE-2017-1092 | IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. | CRITICAL 9.8EPSS 75.8% | 22 May 2017 |
| CVE-2017-2547 | It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | HIGH 8.8EPSS 14.3% | 22 May 2017 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.