SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,554 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 174 of 348

CVESummaryPriorityPublished
CVE-2017-2536It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.HIGH 8.8EPSS 10.5%22 May 2017
CVE-2017-2523It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data.CRITICAL 9.8EPSS 11.5%22 May 2017
CVE-2017-9101import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.CRITICAL 9.8EPSS 76.7%21 May 2017
CVE-2017-9024Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname.HIGH 7.5EPSS 12.2%21 May 2017
CVE-2017-9100login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password field during an admin login attempt.HIGH 8.8EPSS 85.5%21 May 2017
CVE-2017-7504HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows…CRITICAL 9.8EPSS 41.0%19 May 2017
CVE-2017-9080PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.HIGH 8.8EPSS 62.3%19 May 2017
CVE-2017-6048A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior.HIGH 8.8EPSS 15.5%19 May 2017
CVE-2017-5177A Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior.HIGH 7.5EPSS 17.7%19 May 2017
CVE-2017-5174An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12.CRITICAL 9.8EPSS 52.3%19 May 2017
CVE-2017-5173An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12.CRITICAL 9.8EPSS 29.6%19 May 2017
CVE-2017-6622A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges.CRITICAL 9.8EPSS 62.2%18 May 2017
CVE-2017-8917SQL injection vulnerability in Joomla!CRITICAL 9.8EPSS 99.8%17 May 2017
CVE-2017-6079The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set.CRITICAL 9.8EPSS 46.8%16 May 2017
CVE-2016-10372The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the…CRITICAL 9.8EPSS 81.8%16 May 2017
CVE-2017-7478OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.HIGH 7.5EPSS 13.9%15 May 2017
CVE-2017-0252A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scripting Engine Memory Corruption Vulnerability".CRITICAL 9.8EPSS 13.4%15 May 2017
CVE-2017-0223A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scripting Engine Memory Corruption Vulnerability".CRITICAL 9.8EPSS 14.7%15 May 2017
CVE-2016-10329Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.CRITICAL 9.8EPSS 40.8%12 May 2017
CVE-2017-0281Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, SharePoint Enterprise Server 2013 SP1, SharePoint Enterprise Server 2016,…HIGH 7.8EPSS 15.8%12 May 2017
CVE-2017-0279The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an…HIGH 7.0EPSS 10.8%12 May 2017
CVE-2017-0278The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an…HIGH 7.0EPSS 10.8%12 May 2017
CVE-2017-0277The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an…HIGH 7.0EPSS 10.8%12 May 2017
CVE-2017-0272The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an…HIGH 8.1EPSS 17.1%12 May 2017
CVE-2017-0271Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511,…MEDIUM 5.9EPSS 13.3%12 May 2017
CVE-2017-0267Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511,…MEDIUM 5.9EPSS 12.7%12 May 2017
CVE-2017-0266A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsoft Edge Remote Code Execution Vulnerability."HIGH 7.5EPSS 35.8%12 May 2017
CVE-2017-0265Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability".HIGH 7.8EPSS 18.6%12 May 2017
CVE-2017-0264Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability".HIGH 7.8EPSS 13.9%12 May 2017
CVE-2017-0263Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 10.0%12 May 2017
CVE-2017-0262Microsoft Office Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 81.0%12 May 2017
CVE-2017-0261Microsoft Office Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 78.1%12 May 2017
CVE-2017-0254Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Office for Mac 2011, Office for Mac 2016, Microsoft Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, Word 2013 RT SP1, Word 2013 SP1, Word Automation Services…HIGH 7.8EPSS 19.8%12 May 2017
CVE-2017-0247A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests.HIGH 7.5EPSS 16.9%12 May 2017
CVE-2017-0240A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0221 and…HIGH 7.5EPSS 14.7%12 May 2017
CVE-2017-0238A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript scripting engines handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228,…HIGH 7.5EPSS 18.1%12 May 2017
CVE-2017-0236A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224,…HIGH 7.5EPSS 31.6%12 May 2017
CVE-2017-0235A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224,…HIGH 7.5EPSS 11.1%12 May 2017
CVE-2017-0234A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224,…HIGH 7.5EPSS 38.1%12 May 2017
CVE-2017-0230A remote code execution vulnerability exists in Microsoft Edge in the way JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228,…HIGH 7.5EPSS 10.7%12 May 2017
CVE-2017-0229A remote code execution vulnerability exists in Microsoft Edge in the way JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228,…HIGH 7.5EPSS 10.7%12 May 2017
CVE-2017-0228A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0229,…HIGH 7.5EPSS 17.0%12 May 2017
CVE-2017-0227A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0221 and…HIGH 7.5EPSS 13.8%12 May 2017
CVE-2017-0224A remote code execution vulnerability exists in the way JavaScript engines render when handling objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0228, CVE-2017-0229,…HIGH 7.5EPSS 11.4%12 May 2017
CVE-2017-0222Microsoft Internet Explorer Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 29.6%12 May 2017
CVE-2017-0213Microsoft Windows Privilege Escalation VulnerabilityKEVHIGH 7.3EPSS 84.1%12 May 2017
CVE-2017-0190The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information…MEDIUM 4.4EPSS 43.5%12 May 2017
CVE-2017-8798Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.CRITICAL 9.8EPSS 24.0%11 May 2017
CVE-2017-8895In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution.CRITICAL 9.8EPSS 71.0%10 May 2017
CVE-2017-3068Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine.HIGH 8.8EPSS 20.4%9 May 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.