SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 119 of 501

CVESummaryPriorityPublished
CVE-2015-1424Cross-site request forgery (CSRF) vulnerability in Gecko CMS 2.2 and 2.3 allows remote attackers to hijack the authentication of administrators for requests that add an administrator user via a newuser request to admin/index.php.EXPLOITMEDIUM 6.8EPSS 2.31%29 January 2015
CVE-2015-1423Multiple SQL injection vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote administrators to execute arbitrary SQL commands via the (1) jak_delete_log[] or (2) ssp parameter to admin/index.php.EXPLOITMEDIUM 6.5EPSS 1.80%29 January 2015
CVE-2015-1422Multiple cross-site scripting (XSS) vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) horder[], (2) jak_catid, (3) jak_content, (4) jak_css, (5) jak_delete_log[], (6) jak_email, (7)…EXPLOITMEDIUM 4.3EPSS 4.08%29 January 2015
CVE-2015-0235Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2…EXPLOIT ×2HIGH 10.0EPSS 94.6%28 January 2015
CVE-2015-1376pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.EXPLOITMEDIUM 4.0EPSS 33.1%28 January 2015
CVE-2015-1375pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.EXPLOITHIGH 7.5EPSS 11.9%28 January 2015
CVE-2015-1374Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to hijack the authentication of administrators for requests that conduct (1) cross-site scripting (XSS), (2) SQL injection, or (3)…EXPLOITMEDIUM 6.8EPSS 0.95%27 January 2015
CVE-2015-1373Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter in a search request, (2) username in a login request, which is not…EXPLOITMEDIUM 4.3EPSS 3.23%27 January 2015
CVE-2015-1372SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p parameter in an update action to admin.php.EXPLOITHIGH 7.5EPSS 2.36%27 January 2015
CVE-2015-1371Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in custom/uploads/.EXPLOITHIGH 7.5EPSS 8.06%27 January 2015
CVE-2015-1368Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to credentials/, (2) inventories/, (3) projects/, or (4)…EXPLOITMEDIUM 4.3EPSS 5.15%27 January 2015
CVE-2015-1366Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the image_user parameter.EXPLOITMEDIUM 4.3EPSS 6.13%27 January 2015
CVE-2015-1365Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 13.0%27 January 2015
CVE-2015-1364SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter to register/.EXPLOITHIGH 7.5EPSS 1.34%27 January 2015
CVE-2015-1362Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the maker element in an XML file.EXPLOITHIGH 7.5EPSS 8.31%27 January 2015
CVE-2015-0311Adobe Flash Player Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 85.8%23 January 2015
CVE-2014-8802The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit…EXPLOITMEDIUM 5.0EPSS 7.36%23 January 2015
CVE-2015-0925The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subprocess reached through a named pipe, as demonstrated…EXPLOITHIGH 9.0EPSS 52.2%22 January 2015
CVE-2014-8008Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authenticated users to read arbitrary files via a full pathname in an API command, aka Bug ID CSCur49414.EXPLOITMEDIUM 6.8EPSS 8.44%22 January 2015
CVE-2015-0554The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly restrict access to the web interface, which allows remote attackers to obtain sensitive information or cause a denial of service (device…EXPLOITHIGH 9.4EPSS 38.9%21 January 2015
CVE-2015-1028Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remote authenticated users to inject arbitrary web script or HTML via the (1) domainname parameter to dnsProxy.cmd (DNS Proxy…EXPLOIT ×3LOW 3.5EPSS 2.83%21 January 2015
CVE-2014-6593Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.EXPLOITMEDIUM 4.0EPSS 66.4%21 January 2015
CVE-2015-0516Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL.EXPLOITMEDIUM 4.0EPSS 7.41%21 January 2015
CVE-2015-0514EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack.EXPLOITMEDIUM 5.0EPSS 7.65%21 January 2015
CVE-2014-9598The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.EXPLOITMEDIUM 6.8EPSS 6.31%21 January 2015
CVE-2014-9597The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.EXPLOITMEDIUM 6.8EPSS 6.63%21 January 2015
CVE-2014-9226The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Policies via unspecified vectors.EXPLOITHIGH 7.2EPSS 1.54%21 January 2015
CVE-2014-9225The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server…EXPLOITMEDIUM 4.0EPSS 9.22%21 January 2015
CVE-2014-9224Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x…EXPLOITLOW 3.5EPSS 4.59%21 January 2015
CVE-2014-7289SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary…EXPLOITMEDIUM 6.5EPSS 4.55%21 January 2015
CVE-2014-8386Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file.EXPLOITHIGH 7.5EPSS 5.92%20 January 2015
CVE-2014-9195Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.EXPLOITHIGH 7.5EPSS 80.7%17 January 2015
CVE-2015-1060Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.EXPLOITMEDIUM 5.8EPSS 4.40%16 January 2015
CVE-2015-1059Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in…EXPLOITMEDIUM 6.5EPSS 5.43%16 January 2015
CVE-2015-1058Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Category][title] parameter to admin/categories/add, (2) data[Field][title] parameter to…EXPLOITMEDIUM 4.3EPSS 4.27%16 January 2015
CVE-2015-1057Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary web script or HTML via the "Real Name" value.EXPLOITMEDIUM 4.3EPSS 3.23%16 January 2015
CVE-2015-1054Cross-site scripting (XSS) vulnerability in the Games feature in Crea8Social 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the Game Content field in Add Game.EXPLOITLOW 3.5EPSS 2.93%16 January 2015
CVE-2014-8904lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.EXPLOITHIGH 7.2EPSS 0.96%15 January 2015
CVE-2014-9308Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote authenticated users to execute arbitrary code by uploading a file with an…EXPLOIT ×2MEDIUM 6.5EPSS 50.6%15 January 2015
CVE-2014-8636The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges…EXPLOITHIGH 7.5EPSS 64.8%14 January 2015
CVE-2015-0016Microsoft Windows TS WebProxy Directory Traversal VulnerabilityKEVEXPLOITHIGH 7.8EPSS 75.8%13 January 2015
CVE-2015-0004The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to…EXPLOITHIGH 7.2EPSS 3.57%13 January 2015
CVE-2015-0002The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify…EXPLOITHIGH 7.2EPSS 13.8%13 January 2015
CVE-2014-10038SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitrary SQL commands via the ids parameter.EXPLOITHIGH 7.5EPSS 2.35%13 January 2015
CVE-2014-10037Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a ..EXPLOITHIGH 7.5EPSS 18.8%13 January 2015
CVE-2014-10035Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to inject arbitrary web script or HTML via the (1) sEcho parameter to comments_paginate.php or (2) stores_paginate.php or the (3)…EXPLOITMEDIUM 4.3EPSS 3.50%13 January 2015
CVE-2014-10034Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL commands via the (1) iDisplayLength or (2) iDisplayStart parameter to (a) comments_paginate.php or (b)…EXPLOITMEDIUM 6.5EPSS 1.96%13 January 2015
CVE-2014-10033SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.EXPLOITMEDIUM 6.5EPSS 1.80%13 January 2015
CVE-2014-10032SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.EXPLOITMEDIUM 6.5EPSS 1.12%13 January 2015
CVE-2014-10031Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary code via a long string in a UID command.EXPLOITHIGH 7.5EPSS 3.74%13 January 2015

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.