Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 117 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2015-2564 | SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to users-edit.php. | EXPLOITMEDIUM 6.5EPSS 3.10% | 20 March 2015 |
| CVE-2015-2562 | Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) search_category_id, (2) sort_order, or (3) filter_manufacturer_ids… | EXPLOITHIGH 7.5EPSS 38.7% | 20 March 2015 |
| CVE-2015-2281 | Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000. | EXPLOIT ✓HIGH 7.5EPSS 10.3% | 19 March 2015 |
| CVE-2015-2315 | Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI. | EXPLOITMEDIUM 4.3EPSS 7.03% | 17 March 2015 |
| CVE-2015-2314 | SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed. | EXPLOITHIGH 7.5EPSS 7.07% | 17 March 2015 |
| CVE-2015-2292 | Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote authenticated users to execute arbitrary SQL… | EXPLOIT ✓MEDIUM 6.5EPSS 5.79% | 17 March 2015 |
| CVE-2014-7822 | The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file, which allows local users to cause a denial of service (system crash) or possibly have… | EXPLOITHIGH 7.2EPSS 1.13% | 16 March 2015 |
| CVE-2014-7884 | Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors. | EXPLOITHIGH 9.0EPSS 11.7% | 14 March 2015 |
| CVE-2015-0336 | Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than… | EXPLOIT ✓HIGH 9.3EPSS 70.4% | 13 March 2015 |
| CVE-2015-2275 | Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or HTML via the parameters[data][7][title] parameter in a saveImageData action to index.php/AJAXProxy. | EXPLOITMEDIUM 4.3EPSS 3.69% | 12 March 2015 |
| CVE-2015-2237 | Multiple SQL injection vulnerabilities in Betster (aka PHP Betoffice) 1.0.4 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showprofile.php or (2) categoryedit.php or (3) username parameter in a login to index.php. | EXPLOITHIGH 7.5EPSS 2.40% | 12 March 2015 |
| CVE-2015-2285 | The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu Vivid 15.04, allows local users to execute arbitrary commands and gain privileges via a crafted file in /run/user/*/upstart/sessions/. | EXPLOITHIGH 7.2EPSS 1.01% | 12 March 2015 |
| CVE-2015-2208 | The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the object parameter. | EXPLOITHIGH 7.5EPSS 62.0% | 12 March 2015 |
| CVE-2015-2182 | Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1) schltr parameter in a brands action or (2) brand parameter in a viewbrands action to index.php. | EXPLOITMEDIUM 4.3EPSS 4.45% | 11 March 2015 |
| CVE-2015-1875 | SQL injection vulnerability in a2billing/customer/iridium_threed.php in Elastix 2.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the transactionID parameter. | EXPLOITHIGH 7.5EPSS 1.27% | 11 March 2015 |
| CVE-2010-5322 | Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to index.php. | EXPLOITMEDIUM 4.3EPSS 2.56% | 11 March 2015 |
| CVE-2015-0097 | Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Word Local Zone Remote Code Execution… | EXPLOITHIGH 9.3EPSS 40.9% | 11 March 2015 |
| CVE-2015-0096 | Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to… | EXPLOIT ✓HIGH 9.3EPSS 71.0% | 11 March 2015 |
| CVE-2015-0081 | Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to… | EXPLOIT ✓HIGH 9.3EPSS 23.8% | 11 March 2015 |
| CVE-2015-2184 | ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function. | EXPLOITMEDIUM 5.0EPSS 8.40% | 10 March 2015 |
| CVE-2015-2183 | Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execute arbitrary SQL commands via the id parameter in a (1) disporders detail or (2) subadminmgt edit action or (3) cid parameter in an… | EXPLOITHIGH 7.5EPSS 3.53% | 10 March 2015 |
| CVE-2014-9566 | Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1,… | EXPLOITHIGH 7.5EPSS 47.7% | 10 March 2015 |
| CVE-2015-2097 | Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3)… | EXPLOIT ×3 ✓HIGH 7.5EPSS 24.1% | 9 March 2015 |
| CVE-2015-2094 | Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to execute arbitrary code via unspecified vectors to the (1) PrintSiteImage, (2) PlaySiteAllChannel, (3) StopSiteAllChannel, or (4)… | EXPLOIT ×2HIGH 7.5EPSS 14.0% | 9 March 2015 |
| CVE-2015-2177 | Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 102 or (2) Profibus. | EXPLOITHIGH 7.5EPSS 34.7% | 7 March 2015 |
| CVE-2015-2218 | Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1)… | EXPLOITMEDIUM 4.3EPSS 4.19% | 5 March 2015 |
| CVE-2015-2216 | SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to execute arbitrary SQL commands via the prod_id parameter. | EXPLOITHIGH 7.5EPSS 4.74% | 5 March 2015 |
| CVE-2015-2199 | Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to… | EXPLOITMEDIUM 6.5EPSS 2.58% | 3 March 2015 |
| CVE-2015-2198 | Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage_url, (2) pic_url, or (3) avatar_url parameter, which are not properly handled… | EXPLOITMEDIUM 4.3EPSS 1.70% | 3 March 2015 |
| CVE-2015-2196 | SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php. | EXPLOIT ✓HIGH 7.5EPSS 11.2% | 3 March 2015 |
| CVE-2015-2102 | SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execute arbitrary SQL commands via the item parameter. | EXPLOITHIGH 7.5EPSS 2.40% | 27 February 2015 |
| CVE-2015-2090 | SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to… | EXPLOITHIGH 7.5EPSS 4.74% | 26 February 2015 |
| CVE-2015-2084 | Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the… | EXPLOITMEDIUM 6.8EPSS 2.62% | 25 February 2015 |
| CVE-2015-2071 | Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote authenticated users to read arbitrary files via a .. | EXPLOITMEDIUM 4.0EPSS 6.61% | 24 February 2015 |
| CVE-2015-2070 | SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitrary SQL commands via the catId parameter to cm/blogrss/feed. | EXPLOITHIGH 7.5EPSS 2.40% | 24 February 2015 |
| CVE-2015-2068 | Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to… | EXPLOITMEDIUM 4.3EPSS 14.0% | 24 February 2015 |
| CVE-2015-2067 | Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 39.4% | 24 February 2015 |
| CVE-2015-2065 | SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the vid parameter in a rss action to… | EXPLOITHIGH 7.5EPSS 41.1% | 24 February 2015 |
| CVE-2015-0555 | Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrary code via a long string in the first argument to the (1) ReadConfigValue or (2) WriteConfigValue… | EXPLOIT ×2MEDIUM 6.8EPSS 6.39% | 24 February 2015 |
| CVE-2015-0240 | The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute… | EXPLOITHIGH 10.0EPSS 88.0% | 24 February 2015 |
| CVE-2015-2055 | Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the oldpassword parameter. | EXPLOITHIGH 7.8EPSS 3.03% | 23 February 2015 |
| CVE-2015-2051 | D-Link DIR-645 Router Remote Code Execution Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 97.1% | 23 February 2015 |
| CVE-2015-2049 | Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension. | EXPLOIT ✓HIGH 9.0EPSS 66.7% | 23 February 2015 |
| CVE-2015-1517 | SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL commands via the filter_level parameter in a "Refresh photo set" action in the batch_manager page to admin.php. | EXPLOITMEDIUM 6.0EPSS 2.72% | 20 February 2015 |
| CVE-2015-1592 | Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attackers to include and execute arbitrary local Perl files and possibly… | EXPLOIT ✓HIGH 7.5EPSS 75.4% | 19 February 2015 |
| CVE-2015-1587 | Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a request… | EXPLOIT ✓HIGH 7.5EPSS 44.2% | 19 February 2015 |
| CVE-2015-1515 | The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted 0x00222000, 0x00222004, 0x00222008, 0x0022200c, or 0x00222010 IOCTL call. | EXPLOITHIGH 7.2EPSS 1.05% | 19 February 2015 |
| CVE-2014-8690 | Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, and 2.3.x before 2.3.1 patch 4 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, the (2) src… | EXPLOITMEDIUM 4.3EPSS 3.95% | 19 February 2015 |
| CVE-2015-1494 | The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as… | EXPLOIT ✓MEDIUM 4.3EPSS 6.41% | 17 February 2015 |
| CVE-2015-1427 | Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 99.9% | 17 February 2015 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.