SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 117 of 501

CVESummaryPriorityPublished
CVE-2015-2564SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to users-edit.php.EXPLOITMEDIUM 6.5EPSS 3.10%20 March 2015
CVE-2015-2562Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) search_category_id, (2) sort_order, or (3) filter_manufacturer_ids…EXPLOITHIGH 7.5EPSS 38.7%20 March 2015
CVE-2015-2281Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000.EXPLOITHIGH 7.5EPSS 10.3%19 March 2015
CVE-2015-2315Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI.EXPLOITMEDIUM 4.3EPSS 7.03%17 March 2015
CVE-2015-2314SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.EXPLOITHIGH 7.5EPSS 7.07%17 March 2015
CVE-2015-2292Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote authenticated users to execute arbitrary SQL…EXPLOITMEDIUM 6.5EPSS 5.79%17 March 2015
CVE-2014-7822The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file, which allows local users to cause a denial of service (system crash) or possibly have…EXPLOITHIGH 7.2EPSS 1.13%16 March 2015
CVE-2014-7884Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors.EXPLOITHIGH 9.0EPSS 11.7%14 March 2015
CVE-2015-0336Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than…EXPLOITHIGH 9.3EPSS 70.4%13 March 2015
CVE-2015-2275Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or HTML via the parameters[data][7][title] parameter in a saveImageData action to index.php/AJAXProxy.EXPLOITMEDIUM 4.3EPSS 3.69%12 March 2015
CVE-2015-2237Multiple SQL injection vulnerabilities in Betster (aka PHP Betoffice) 1.0.4 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showprofile.php or (2) categoryedit.php or (3) username parameter in a login to index.php.EXPLOITHIGH 7.5EPSS 2.40%12 March 2015
CVE-2015-2285The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu Vivid 15.04, allows local users to execute arbitrary commands and gain privileges via a crafted file in /run/user/*/upstart/sessions/.EXPLOITHIGH 7.2EPSS 1.01%12 March 2015
CVE-2015-2208The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the object parameter.EXPLOITHIGH 7.5EPSS 62.0%12 March 2015
CVE-2015-2182Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1) schltr parameter in a brands action or (2) brand parameter in a viewbrands action to index.php.EXPLOITMEDIUM 4.3EPSS 4.45%11 March 2015
CVE-2015-1875SQL injection vulnerability in a2billing/customer/iridium_threed.php in Elastix 2.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the transactionID parameter.EXPLOITHIGH 7.5EPSS 1.27%11 March 2015
CVE-2010-5322Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to index.php.EXPLOITMEDIUM 4.3EPSS 2.56%11 March 2015
CVE-2015-0097Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Word Local Zone Remote Code Execution…EXPLOITHIGH 9.3EPSS 40.9%11 March 2015
CVE-2015-0096Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to…EXPLOITHIGH 9.3EPSS 71.0%11 March 2015
CVE-2015-0081Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to…EXPLOITHIGH 9.3EPSS 23.8%11 March 2015
CVE-2015-2184ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function.EXPLOITMEDIUM 5.0EPSS 8.40%10 March 2015
CVE-2015-2183Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execute arbitrary SQL commands via the id parameter in a (1) disporders detail or (2) subadminmgt edit action or (3) cid parameter in an…EXPLOITHIGH 7.5EPSS 3.53%10 March 2015
CVE-2014-9566Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1,…EXPLOITHIGH 7.5EPSS 47.7%10 March 2015
CVE-2015-2097Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3)…EXPLOIT ×3HIGH 7.5EPSS 24.1%9 March 2015
CVE-2015-2094Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to execute arbitrary code via unspecified vectors to the (1) PrintSiteImage, (2) PlaySiteAllChannel, (3) StopSiteAllChannel, or (4)…EXPLOIT ×2HIGH 7.5EPSS 14.0%9 March 2015
CVE-2015-2177Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 102 or (2) Profibus.EXPLOITHIGH 7.5EPSS 34.7%7 March 2015
CVE-2015-2218Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1)…EXPLOITMEDIUM 4.3EPSS 4.19%5 March 2015
CVE-2015-2216SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to execute arbitrary SQL commands via the prod_id parameter.EXPLOITHIGH 7.5EPSS 4.74%5 March 2015
CVE-2015-2199Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to…EXPLOITMEDIUM 6.5EPSS 2.58%3 March 2015
CVE-2015-2198Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage_url, (2) pic_url, or (3) avatar_url parameter, which are not properly handled…EXPLOITMEDIUM 4.3EPSS 1.70%3 March 2015
CVE-2015-2196SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.EXPLOITHIGH 7.5EPSS 11.2%3 March 2015
CVE-2015-2102SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execute arbitrary SQL commands via the item parameter.EXPLOITHIGH 7.5EPSS 2.40%27 February 2015
CVE-2015-2090SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to…EXPLOITHIGH 7.5EPSS 4.74%26 February 2015
CVE-2015-2084Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the…EXPLOITMEDIUM 6.8EPSS 2.62%25 February 2015
CVE-2015-2071Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote authenticated users to read arbitrary files via a ..EXPLOITMEDIUM 4.0EPSS 6.61%24 February 2015
CVE-2015-2070SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitrary SQL commands via the catId parameter to cm/blogrss/feed.EXPLOITHIGH 7.5EPSS 2.40%24 February 2015
CVE-2015-2068Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to…EXPLOITMEDIUM 4.3EPSS 14.0%24 February 2015
CVE-2015-2067Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 39.4%24 February 2015
CVE-2015-2065SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the vid parameter in a rss action to…EXPLOITHIGH 7.5EPSS 41.1%24 February 2015
CVE-2015-0555Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrary code via a long string in the first argument to the (1) ReadConfigValue or (2) WriteConfigValue…EXPLOIT ×2MEDIUM 6.8EPSS 6.39%24 February 2015
CVE-2015-0240The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute…EXPLOITHIGH 10.0EPSS 88.0%24 February 2015
CVE-2015-2055Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the oldpassword parameter.EXPLOITHIGH 7.8EPSS 3.03%23 February 2015
CVE-2015-2051D-Link DIR-645 Router Remote Code Execution VulnerabilityKEVEXPLOITHIGH 8.8EPSS 97.1%23 February 2015
CVE-2015-2049Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.EXPLOITHIGH 9.0EPSS 66.7%23 February 2015
CVE-2015-1517SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL commands via the filter_level parameter in a "Refresh photo set" action in the batch_manager page to admin.php.EXPLOITMEDIUM 6.0EPSS 2.72%20 February 2015
CVE-2015-1592Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attackers to include and execute arbitrary local Perl files and possibly…EXPLOITHIGH 7.5EPSS 75.4%19 February 2015
CVE-2015-1587Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a request…EXPLOITHIGH 7.5EPSS 44.2%19 February 2015
CVE-2015-1515The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted 0x00222000, 0x00222004, 0x00222008, 0x0022200c, or 0x00222010 IOCTL call.EXPLOITHIGH 7.2EPSS 1.05%19 February 2015
CVE-2014-8690Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, and 2.3.x before 2.3.1 patch 4 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, the (2) src…EXPLOITMEDIUM 4.3EPSS 3.95%19 February 2015
CVE-2015-1494The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as…EXPLOITMEDIUM 4.3EPSS 6.41%17 February 2015
CVE-2015-1427Elasticsearch Groovy Scripting Engine Remote Code Execution VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 99.9%17 February 2015

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.