SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 116 of 501

CVESummaryPriorityPublished
CVE-2015-2843Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute arbitrary SQL commands via the (1) user_name or (2) user_pass parameter in go_login.php or the PATH_INFO to (3)…EXPLOIT ×2HIGH 7.5EPSS 37.9%12 May 2015
CVE-2015-2842Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3.3-1421902800 allows remote attackers to execute arbitrary code by uploading a file with an executable…EXPLOITHIGH 10.0EPSS 13.1%12 May 2015
CVE-2015-2219Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an…EXPLOITHIGH 7.2EPSS 4.15%12 May 2015
CVE-2015-3632Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.EXPLOITMEDIUM 4.3EPSS 6.03%1 May 2015
CVE-2015-3337Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.EXPLOITMEDIUM 4.3EPSS 32.9%1 May 2015
CVE-2015-2248Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for…EXPLOITMEDIUM 6.8EPSS 3.93%1 May 2015
CVE-2014-8361Realtek SDK Improper Input Validation VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%1 May 2015
CVE-2015-1397SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary SQL commands via the…EXPLOITMEDIUM 6.5EPSS 52.3%29 April 2015
CVE-2012-5451Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a denial of service (tvMobiliService service crash) via a long string in a (1) GET or (2) HEAD request to TCP port 30888.EXPLOITMEDIUM 5.0EPSS 3.91%24 April 2015
CVE-2011-4403Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable…EXPLOITMEDIUM 5.8EPSS 1.68%24 April 2015
CVE-2015-2825Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct…EXPLOITHIGH 7.5EPSS 14.4%21 April 2015
CVE-2014-5370Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows remote attackers to read or possibly delete arbitrary files via a ..EXPLOITHIGH 7.5EPSS 7.46%21 April 2015
CVE-2015-1701Microsoft Win32k Privilege Escalation VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 55.9%21 April 2015
CVE-2015-1318The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).EXPLOIT ×3HIGH 7.2EPSS 4.19%17 April 2015
CVE-2015-2572Unspecified vulnerability in the Oracle Hyperion Smart View for Office component in Oracle Hyperion 11.1.2.5.216 and earlier, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors related…EXPLOITMEDIUM 4.6EPSS 1.07%16 April 2015
CVE-2015-0493Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than…EXPLOITLOW 1.5EPSS 0.90%16 April 2015
CVE-2015-0474Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than…EXPLOITLOW 1.5EPSS 0.69%16 April 2015
CVE-2015-3043Adobe Flash Player Memory Corruption VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 73.9%14 April 2015
CVE-2015-3042Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a…EXPLOITHIGH 10.0EPSS 36.8%14 April 2015
CVE-2015-0359Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability…EXPLOITHIGH 10.0EPSS 92.1%14 April 2015
CVE-2015-1635Microsoft HTTP.sys Remote Code Execution VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 100.0%14 April 2015
CVE-2015-2223Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks Traps (formerly Cyvera Endpoint Protection) 3.1.2.1546 allow remote attackers to inject arbitrary web script or HTML via the (1)…EXPLOITMEDIUM 4.3EPSS 4.01%14 April 2015
CVE-2014-9311Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the location[id] parameter in a shareaholic_add_location action to…EXPLOITLOW 3.5EPSS 3.86%14 April 2015
CVE-2014-9146Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web script or HTML via the (1) view, (2) id, (3) page, or (4) app parameter to the default URI or the (5) act parameter to dapur/index.php.EXPLOITMEDIUM 4.3EPSS 2.52%14 April 2015
CVE-2014-9145Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edit action to dapur/index.php; (2) cat, (3) user, or (4) level parameter to…EXPLOITHIGH 7.5EPSS 2.07%14 April 2015
CVE-2015-2295Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the…EXPLOITMEDIUM 6.8EPSS 65.7%10 April 2015
CVE-2015-1130Apple OS X Authentication Bypass VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 9.89%10 April 2015
CVE-2015-1100The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service (out-of-bounds memory access) or obtain sensitive memory-content information via a crafted app.EXPLOITMEDIUM 5.4EPSS 1.04%10 April 2015
CVE-2015-2824Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a…EXPLOITHIGH 7.5EPSS 6.21%6 April 2015
CVE-2015-2166Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI.EXPLOITMEDIUM 5.0EPSS 26.8%6 April 2015
CVE-2015-0179Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users to obtain the System privilege via unspecified vectors, aka SPR TCHL9SST8V.EXPLOITHIGH 7.2EPSS 1.12%6 April 2015
CVE-2015-2841Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the application/octet-stream and text/xml Content-Types.EXPLOITMEDIUM 5.0EPSS 5.50%3 April 2015
CVE-2015-2838Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands as nsroot via shell…EXPLOITMEDIUM 6.8EPSS 2.86%3 April 2015
CVE-2015-0816Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the…EXPLOITMEDIUM 5.0EPSS 66.9%1 April 2015
CVE-2015-0802Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content…EXPLOITMEDIUM 5.0EPSS 67.3%1 April 2015
CVE-2015-2791The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.EXPLOITMEDIUM 6.4EPSS 13.3%30 March 2015
CVE-2015-2790Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.EXPLOIT ×2MEDIUM 4.3EPSS 24.5%30 March 2015
CVE-2015-2789Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.EXPLOITMEDIUM 4.4EPSS 3.19%30 March 2015
CVE-2015-1815The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.EXPLOITHIGH 10.0EPSS 16.5%30 March 2015
CVE-2015-0273Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier in…EXPLOITHIGH 7.5EPSS 42.9%30 March 2015
CVE-2015-2746The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell…EXPLOITMEDIUM 6.5EPSS 25.4%26 March 2015
CVE-2015-2682Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.EXPLOITMEDIUM 5.0EPSS 10.7%26 March 2015
CVE-2015-2701Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a request to profiles-update/.EXPLOITMEDIUM 6.8EPSS 2.73%25 March 2015
CVE-2015-2284userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary code via unspecified vectors, related to client session handling.EXPLOITHIGH 10.0EPSS 73.5%24 March 2015
CVE-2015-2153The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via a crafted header length in an RPKI-RTR Protocol Data Unit…EXPLOITMEDIUM 5.0EPSS 19.0%24 March 2015
CVE-2015-0252internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.EXPLOITMEDIUM 5.0EPSS 39.7%24 March 2015
CVE-2015-2680Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php.EXPLOITMEDIUM 6.8EPSS 3.91%23 March 2015
CVE-2015-2679Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php or (2) username parameter to gxadmin/login.php.EXPLOITHIGH 7.5EPSS 5.58%23 March 2015
CVE-2015-2678Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter in the categories page to gxadmin/index.php or (2) page parameter to index.php.EXPLOITMEDIUM 4.3EPSS 5.36%23 March 2015
CVE-2014-9261The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 9.04%23 March 2015

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.