Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 116 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2015-2843 | Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute arbitrary SQL commands via the (1) user_name or (2) user_pass parameter in go_login.php or the PATH_INFO to (3)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 37.9% | 12 May 2015 |
| CVE-2015-2842 | Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3.3-1421902800 allows remote attackers to execute arbitrary code by uploading a file with an executable… | EXPLOIT ✓HIGH 10.0EPSS 13.1% | 12 May 2015 |
| CVE-2015-2219 | Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an… | EXPLOIT ✓HIGH 7.2EPSS 4.15% | 12 May 2015 |
| CVE-2015-3632 | Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file. | EXPLOITMEDIUM 4.3EPSS 6.03% | 1 May 2015 |
| CVE-2015-3337 | Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors. | EXPLOITMEDIUM 4.3EPSS 32.9% | 1 May 2015 |
| CVE-2015-2248 | Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for… | EXPLOITMEDIUM 6.8EPSS 3.93% | 1 May 2015 |
| CVE-2014-8361 | Realtek SDK Improper Input Validation Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 100.0% | 1 May 2015 |
| CVE-2015-1397 | SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary SQL commands via the… | EXPLOITMEDIUM 6.5EPSS 52.3% | 29 April 2015 |
| CVE-2012-5451 | Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a denial of service (tvMobiliService service crash) via a long string in a (1) GET or (2) HEAD request to TCP port 30888. | EXPLOITMEDIUM 5.0EPSS 3.91% | 24 April 2015 |
| CVE-2011-4403 | Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable… | EXPLOIT ✓MEDIUM 5.8EPSS 1.68% | 24 April 2015 |
| CVE-2015-2825 | Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct… | EXPLOITHIGH 7.5EPSS 14.4% | 21 April 2015 |
| CVE-2014-5370 | Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows remote attackers to read or possibly delete arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 7.46% | 21 April 2015 |
| CVE-2015-1701 | Microsoft Win32k Privilege Escalation Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 55.9% | 21 April 2015 |
| CVE-2015-1318 | The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container). | EXPLOIT ×3 ✓HIGH 7.2EPSS 4.19% | 17 April 2015 |
| CVE-2015-2572 | Unspecified vulnerability in the Oracle Hyperion Smart View for Office component in Oracle Hyperion 11.1.2.5.216 and earlier, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors related… | EXPLOITMEDIUM 4.6EPSS 1.07% | 16 April 2015 |
| CVE-2015-0493 | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than… | EXPLOITLOW 1.5EPSS 0.90% | 16 April 2015 |
| CVE-2015-0474 | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than… | EXPLOITLOW 1.5EPSS 0.69% | 16 April 2015 |
| CVE-2015-3043 | Adobe Flash Player Memory Corruption Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 73.9% | 14 April 2015 |
| CVE-2015-3042 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a… | EXPLOIT ✓HIGH 10.0EPSS 36.8% | 14 April 2015 |
| CVE-2015-0359 | Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability… | EXPLOIT ✓HIGH 10.0EPSS 92.1% | 14 April 2015 |
| CVE-2015-1635 | Microsoft HTTP.sys Remote Code Execution Vulnerability | KEVEXPLOIT ×2CRITICAL 9.8EPSS 100.0% | 14 April 2015 |
| CVE-2015-2223 | Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks Traps (formerly Cyvera Endpoint Protection) 3.1.2.1546 allow remote attackers to inject arbitrary web script or HTML via the (1)… | EXPLOITMEDIUM 4.3EPSS 4.01% | 14 April 2015 |
| CVE-2014-9311 | Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the location[id] parameter in a shareaholic_add_location action to… | EXPLOITLOW 3.5EPSS 3.86% | 14 April 2015 |
| CVE-2014-9146 | Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web script or HTML via the (1) view, (2) id, (3) page, or (4) app parameter to the default URI or the (5) act parameter to dapur/index.php. | EXPLOITMEDIUM 4.3EPSS 2.52% | 14 April 2015 |
| CVE-2014-9145 | Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edit action to dapur/index.php; (2) cat, (3) user, or (4) level parameter to… | EXPLOITHIGH 7.5EPSS 2.07% | 14 April 2015 |
| CVE-2015-2295 | Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the… | EXPLOITMEDIUM 6.8EPSS 65.7% | 10 April 2015 |
| CVE-2015-1130 | Apple OS X Authentication Bypass Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 9.89% | 10 April 2015 |
| CVE-2015-1100 | The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service (out-of-bounds memory access) or obtain sensitive memory-content information via a crafted app. | EXPLOITMEDIUM 5.4EPSS 1.04% | 10 April 2015 |
| CVE-2015-2824 | Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a… | EXPLOIT ✓HIGH 7.5EPSS 6.21% | 6 April 2015 |
| CVE-2015-2166 | Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI. | EXPLOITMEDIUM 5.0EPSS 26.8% | 6 April 2015 |
| CVE-2015-0179 | Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users to obtain the System privilege via unspecified vectors, aka SPR TCHL9SST8V. | EXPLOITHIGH 7.2EPSS 1.12% | 6 April 2015 |
| CVE-2015-2841 | Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the application/octet-stream and text/xml Content-Types. | EXPLOITMEDIUM 5.0EPSS 5.50% | 3 April 2015 |
| CVE-2015-2838 | Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands as nsroot via shell… | EXPLOITMEDIUM 6.8EPSS 2.86% | 3 April 2015 |
| CVE-2015-0816 | Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the… | EXPLOIT ✓MEDIUM 5.0EPSS 66.9% | 1 April 2015 |
| CVE-2015-0802 | Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content… | EXPLOIT ✓MEDIUM 5.0EPSS 67.3% | 1 April 2015 |
| CVE-2015-2791 | The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php. | EXPLOITMEDIUM 6.4EPSS 13.3% | 30 March 2015 |
| CVE-2015-2790 | Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image. | EXPLOIT ×2MEDIUM 4.3EPSS 24.5% | 30 March 2015 |
| CVE-2015-2789 | Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder. | EXPLOITMEDIUM 4.4EPSS 3.19% | 30 March 2015 |
| CVE-2015-1815 | The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name. | EXPLOITHIGH 10.0EPSS 16.5% | 30 March 2015 |
| CVE-2015-0273 | Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier in… | EXPLOITHIGH 7.5EPSS 42.9% | 30 March 2015 |
| CVE-2015-2746 | The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell… | EXPLOITMEDIUM 6.5EPSS 25.4% | 26 March 2015 |
| CVE-2015-2682 | Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml. | EXPLOITMEDIUM 5.0EPSS 10.7% | 26 March 2015 |
| CVE-2015-2701 | Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a request to profiles-update/. | EXPLOITMEDIUM 6.8EPSS 2.73% | 25 March 2015 |
| CVE-2015-2284 | userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary code via unspecified vectors, related to client session handling. | EXPLOIT ✓HIGH 10.0EPSS 73.5% | 24 March 2015 |
| CVE-2015-2153 | The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via a crafted header length in an RPKI-RTR Protocol Data Unit… | EXPLOITMEDIUM 5.0EPSS 19.0% | 24 March 2015 |
| CVE-2015-0252 | internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data. | EXPLOITMEDIUM 5.0EPSS 39.7% | 24 March 2015 |
| CVE-2015-2680 | Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php. | EXPLOITMEDIUM 6.8EPSS 3.91% | 23 March 2015 |
| CVE-2015-2679 | Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php or (2) username parameter to gxadmin/login.php. | EXPLOITHIGH 7.5EPSS 5.58% | 23 March 2015 |
| CVE-2015-2678 | Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter in the categories page to gxadmin/index.php or (2) page parameter to index.php. | EXPLOITMEDIUM 4.3EPSS 5.36% | 23 March 2015 |
| CVE-2014-9261 | The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 9.04% | 23 March 2015 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.