SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,554 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 20 September 2026

17,386 results · page 179 of 348

CVESummaryPriorityPublished
CVE-2017-0063The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and R2; and Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows…MEDIUM 6.5EPSS 35.3%17 March 2017
CVE-2017-0062The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain…MEDIUM 4.7EPSS 17.8%17 March 2017
CVE-2017-0061The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2, Windows Server 2008 SP2 and R2, and Windows 7 SP1 allows remote attackers to bypass ASLR and execute code in combination with another vulnerability through a…MEDIUM 5.3EPSS 43.1%17 March 2017
CVE-2017-0060The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain…MEDIUM 5.5EPSS 15.9%17 March 2017
CVE-2017-0059Microsoft Internet Explorer Information Disclosure VulnerabilityKEVMEDIUM 4.3EPSS 62.0%17 March 2017
CVE-2017-0057DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensitive information via (1) convincing…MEDIUM 4.3EPSS 14.0%17 March 2017
CVE-2017-0055Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote…MEDIUM 6.1EPSS 16.4%17 March 2017
CVE-2017-0053Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, Word 2010 SP2, Word 2013 SP1, Word 2013 R2 SP1, Word 2016, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a…HIGH 7.8EPSS 16.7%17 March 2017
CVE-2017-0052Microsoft Office Compatibility Pack SP3, Excel 2007 SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka…HIGH 7.8EPSS 16.6%17 March 2017
CVE-2017-0049The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability." This vulnerability is different from…MEDIUM 4.3EPSS 38.9%17 March 2017
CVE-2017-0042Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive…LOW 3.1EPSS 29.5%17 March 2017
CVE-2017-0040The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." This…HIGH 7.5EPSS 13.5%17 March 2017
CVE-2017-0039Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle dynamic link library (DLL) loading, which allows local users to gain privileges via a crafted application, aka "Library Loading Input Validation Remote Code Execution Vulnerability."HIGH 7.8EPSS 37.4%17 March 2017
CVE-2017-0035A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.HIGH 7.5EPSS 15.2%17 March 2017
CVE-2017-0034A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory.HIGH 7.5EPSS 12.7%17 March 2017
CVE-2017-0032A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.HIGH 7.5EPSS 15.2%17 March 2017
CVE-2017-0031Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, and Word 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption…HIGH 7.8EPSS 26.3%17 March 2017
CVE-2017-0030Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Office Web Apps Server 2010 SP2, Word 2007 SP3, Word 2010 SP2, and Word Automation Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of…HIGH 7.8EPSS 26.0%17 March 2017
CVE-2017-0029Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 RT SP1, and Word 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."MEDIUM 5.5EPSS 15.6%17 March 2017
CVE-2017-0027Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office…MEDIUM 4.7EPSS 22.6%17 March 2017
CVE-2017-0023The PDF library in Microsoft Edge; Windows 8.1; Windows Server 2012 and R2; Windows RT 8.1; and Windows 10, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted PDF file, aka "Microsoft PDF Remote Code Execution Vulnerability."HIGH 7.5EPSS 34.0%17 March 2017
CVE-2017-0022Microsoft XML Core Services Information Disclosure VulnerabilityKEVMEDIUM 6.5EPSS 18.1%17 March 2017
CVE-2017-0020Microsoft Excel 2016, Excel 2010 SP2, Excel 2013 RT SP1, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory…HIGH 7.8EPSS 16.4%17 March 2017
CVE-2017-0019Microsoft Word 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described…HIGH 7.8EPSS 16.6%17 March 2017
CVE-2017-0018Microsoft Internet Explorer 10 and 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from…HIGH 7.5EPSS 13.5%17 March 2017
CVE-2017-0017The RegEx class in the XSS filter in Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability." This…MEDIUM 6.1EPSS 42.0%17 March 2017
CVE-2017-0016Microsoft Windows 10 Gold, 1511, and 1607; Windows 8.1; Windows RT 8.1; Windows Server 2012 R2, and Windows Server 2016 do not properly handle certain requests in SMBv2 and SMBv3 packets, which allows remote attackers to execute arbitrary code via a…MEDIUM 5.9EPSS 25.7%17 March 2017
CVE-2017-0015A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.HIGH 7.5EPSS 26.4%17 March 2017
CVE-2017-0014The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to…HIGH 7.5EPSS 17.6%17 March 2017
CVE-2017-0011Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0017,…MEDIUM 4.3EPSS 42.4%17 March 2017
CVE-2017-0010A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.HIGH 7.5EPSS 27.1%17 March 2017
CVE-2017-0009Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." This vulnerability is different from those described in…MEDIUM 4.3EPSS 39.6%17 March 2017
CVE-2017-0008Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those…MEDIUM 4.3EPSS 37.0%17 March 2017
CVE-2017-0007Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidating associated signatures, aka "PowerShell Security Feature Bypass Vulnerability."MEDIUM 5.5EPSS 11.3%17 March 2017
CVE-2017-0006Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka…HIGH 7.8EPSS 16.6%17 March 2017
CVE-2017-0005Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 11.0%17 March 2017
CVE-2017-6510Easy File Sharing FTP Server version 3.6 is vulnerable to a directory traversal vulnerability which allows an attacker to list and download any file from any folder outside the FTP root Directory.HIGH 7.5EPSS 15.3%16 March 2017
CVE-2016-7103Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.MEDIUM 6.1EPSS 22.6%15 March 2017
CVE-2017-5358Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect API function.CRITICAL 9.8EPSS 12.1%15 March 2017
CVE-2016-10166Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable.CRITICAL 9.8EPSS 10.7%15 March 2017
CVE-2016-8022Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to execute arbitrary code or cause a denial of service via a crafted authentication cookie.HIGH 7.5EPSS 13.3%14 March 2017
CVE-2016-8020Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to execute arbitrary code via a crafted HTTP request parameter.HIGH 8.0EPSS 11.1%14 March 2017
CVE-2017-6398An authenticated user can execute a terminal command in the context of the web server user (which is root).HIGH 8.8EPSS 54.1%14 March 2017
CVE-2013-4659Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916.CRITICAL 9.8EPSS 13.9%14 March 2017
CVE-2017-5674A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.ini HTTP/1.1\n\n" - note the lack of "/" in the path field of the request)…CRITICAL 9.8EPSS 21.6%13 March 2017
CVE-2017-6444The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets.HIGH 7.5EPSS 13.5%12 March 2017
CVE-2017-5638Apache Struts Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%11 March 2017
CVE-2017-6506In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution.CRITICAL 9.8EPSS 11.7%10 March 2017
CVE-2017-6465Remote Code Execution was discovered in FTPShell Client 6.53.CRITICAL 9.8EPSS 50.3%10 March 2017
CVE-2017-6527An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID…HIGH 7.5EPSS 56.6%9 March 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.