Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 118 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2015-1497 | radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execute arbitrary commands via a crafted request to TCP port 3465. | EXPLOIT ×3 ✓HIGH 10.0EPSS 75.1% | 16 February 2015 |
| CVE-2014-6137 | Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOITMEDIUM 4.3EPSS 2.25% | 16 February 2015 |
| CVE-2014-7883 | HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response. | EXPLOIT ✓MEDIUM 5.0EPSS 37.0% | 15 February 2015 |
| CVE-2014-7196 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×15 ✓UnscoredEPSS — | 15 February 2015 |
| CVE-2015-1471 | SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to the default URI. | EXPLOITHIGH 7.5EPSS 3.80% | 12 February 2015 |
| CVE-2015-1579 | Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 21.5% | 11 February 2015 |
| CVE-2015-1578 | Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) pidvesa cookie to u5admin/pidvesa.php or (2) uri parameter to u5admin/meta2.php. | EXPLOITMEDIUM 5.8EPSS 7.21% | 11 February 2015 |
| CVE-2015-1577 | Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to arbitrary files via a (1) .. | EXPLOIT ×2MEDIUM 6.4EPSS 7.27% | 11 February 2015 |
| CVE-2015-1576 | Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) copy2.php, (2) localize.php, (3) metai.php, (4) nc.php, (5) new2.php, or (6) rename2.php in u5admin/; (7)… | EXPLOITHIGH 7.5EPSS 2.13% | 11 February 2015 |
| CVE-2015-1575 | Multiple cross-site scripting (XSS) vulnerabilities in u5CMS before 3.9.4 allow remote attackers to inject arbitrary web script or HTML via the (1) c, (2) i, (3) l, or (4) p parameter to index.php; the (5) a or (6) b parameter to u5admin/cookie.php; the… | EXPLOITMEDIUM 4.3EPSS 3.28% | 11 February 2015 |
| CVE-2015-1518 | SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter. | EXPLOITHIGH 7.5EPSS 2.40% | 11 February 2015 |
| CVE-2015-1172 | Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 and earlier for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then… | EXPLOIT ✓HIGH 7.5EPSS 59.3% | 11 February 2015 |
| CVE-2015-0065 | Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "OneTableDocumentStream Remote Code Execution Vulnerability." | EXPLOIT ✓HIGH 9.3EPSS 30.3% | 11 February 2015 |
| CVE-2015-0064 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applications 2010 SP2, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of… | EXPLOIT ✓HIGH 9.3EPSS 30.0% | 11 February 2015 |
| CVE-2015-0060 | The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1… | EXPLOITMEDIUM 4.7EPSS 3.81% | 11 February 2015 |
| CVE-2015-0059 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted TrueType font, aka… | EXPLOITMEDIUM 6.9EPSS 11.1% | 11 February 2015 |
| CVE-2015-0058 | Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a crafted application, aka "Windows Cursor Object Double Free Vulnerability." | EXPLOITHIGH 7.2EPSS 2.69% | 11 February 2015 |
| CVE-2015-0057 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to… | EXPLOIT ×2 ✓HIGH 7.2EPSS 12.8% | 11 February 2015 |
| CVE-2015-0050 | Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | EXPLOIT ✓HIGH 9.3EPSS 33.5% | 11 February 2015 |
| CVE-2015-0040 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | EXPLOIT ✓HIGH 9.3EPSS 30.0% | 11 February 2015 |
| CVE-2015-0010 | The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,… | EXPLOITLOW 1.9EPSS 2.65% | 11 February 2015 |
| CVE-2015-0009 | The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and… | EXPLOITLOW 3.3EPSS 8.07% | 11 February 2015 |
| CVE-2015-0008 | The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from… | EXPLOITHIGH 8.3EPSS 28.6% | 11 February 2015 |
| CVE-2015-0003 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to… | EXPLOITMEDIUM 6.9EPSS 4.54% | 11 February 2015 |
| CVE-2015-1467 | Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) type[] parameter to private/en/locale/index. | EXPLOITHIGH 7.5EPSS 2.40% | 6 February 2015 |
| CVE-2015-1305 | McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call. | EXPLOITMEDIUM 6.9EPSS 0.88% | 6 February 2015 |
| CVE-2014-9643 | K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580,… | EXPLOITHIGH 7.2EPSS 1.05% | 6 February 2015 |
| CVE-2014-9642 | bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted 0x0022405c IOCTL call. | EXPLOITHIGH 7.2EPSS 1.08% | 6 February 2015 |
| CVE-2014-9641 | The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x00222400 IOCTL call. | EXPLOITHIGH 7.2EPSS 0.96% | 6 February 2015 |
| CVE-2014-9632 | The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted… | EXPLOITHIGH 7.2EPSS 1.46% | 6 February 2015 |
| CVE-2015-0318 | Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a… | EXPLOIT ✓HIGH 10.0EPSS 75.2% | 6 February 2015 |
| CVE-2015-1482 | Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/. | EXPLOITMEDIUM 5.0EPSS 8.54% | 4 February 2015 |
| CVE-2015-1481 | Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account. | EXPLOITMEDIUM 6.5EPSS 6.14% | 4 February 2015 |
| CVE-2015-1480 | ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf/flashreport.swf, (3)… | EXPLOITMEDIUM 4.0EPSS 6.26% | 4 February 2015 |
| CVE-2015-1479 | SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to execute arbitrary SQL commands via the site parameter. | EXPLOITMEDIUM 6.5EPSS 3.93% | 4 February 2015 |
| CVE-2015-1478 | Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the view parameter to /classifieds. | EXPLOITMEDIUM 4.3EPSS 3.22% | 4 February 2015 |
| CVE-2015-1477 | SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to classifieds/offerring-ads. | EXPLOITHIGH 7.5EPSS 2.40% | 4 February 2015 |
| CVE-2015-1476 | Multiple SQL injection vulnerabilities in xlinkerz ecommerceMajor allow remote attackers to execute arbitrary SQL commands via the (1) productbycat parameter to product.php, or (2) username or (3) password parameter to __admin/index.php. | EXPLOITHIGH 7.5EPSS 2.40% | 4 February 2015 |
| CVE-2014-9331 | Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to… | EXPLOITMEDIUM 6.8EPSS 4.61% | 4 February 2015 |
| CVE-2014-7864 | Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attackers and remote authenticated users to execute arbitrary… | EXPLOITHIGH 7.5EPSS 22.7% | 4 February 2015 |
| CVE-2015-1428 | Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL commands via the sefrengo cookie in a login to backend/main.php or (2) remote authenticated users to execute arbitrary SQL commands via… | EXPLOITHIGH 7.5EPSS 2.70% | 3 February 2015 |
| CVE-2015-1400 | SQL injection vulnerability in search.php in NPDS Revolution 13 allows remote attackers to execute arbitrary SQL commands via the query parameter. | EXPLOITHIGH 7.5EPSS 2.41% | 3 February 2015 |
| CVE-2014-9633 | The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which triggers a NULL pointer dereference. | EXPLOITHIGH 7.5EPSS 8.09% | 3 February 2015 |
| CVE-2015-0313 | Adobe Flash Player Use-After-Free Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 95.3% | 2 February 2015 |
| CVE-2014-8612 | Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allow local users to (1) gain privileges via the stream id to the setsockopt function,… | EXPLOIT ✓MEDIUM 4.6EPSS 0.90% | 2 February 2015 |
| CVE-2014-0998 | Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VT_WAITACTIVE ioctl call,… | EXPLOIT ✓HIGH 7.2EPSS 0.92% | 2 February 2015 |
| CVE-2014-7288 | Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action. | EXPLOIT ✓HIGH 9.0EPSS 8.12% | 1 February 2015 |
| CVE-2014-8835 | The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type, which allows attackers to execute arbitrary code by providing a crafted dictionary to sysmond, related… | EXPLOITHIGH 9.3EPSS 8.25% | 30 January 2015 |
| CVE-2014-8826 | LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper protection mechanism via a crafted JAR archive. | EXPLOITMEDIUM 5.0EPSS 8.72% | 30 January 2015 |
| CVE-2014-4492 | libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an _networkd context via a crafted XPC… | EXPLOIT ✓HIGH 7.5EPSS 19.7% | 30 January 2015 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.