Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 119 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2015-1424 | Cross-site request forgery (CSRF) vulnerability in Gecko CMS 2.2 and 2.3 allows remote attackers to hijack the authentication of administrators for requests that add an administrator user via a newuser request to admin/index.php. | EXPLOITMEDIUM 6.8EPSS 2.31% | 29 January 2015 |
| CVE-2015-1423 | Multiple SQL injection vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote administrators to execute arbitrary SQL commands via the (1) jak_delete_log[] or (2) ssp parameter to admin/index.php. | EXPLOITMEDIUM 6.5EPSS 1.80% | 29 January 2015 |
| CVE-2015-1422 | Multiple cross-site scripting (XSS) vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) horder[], (2) jak_catid, (3) jak_content, (4) jak_css, (5) jak_delete_log[], (6) jak_email, (7)… | EXPLOITMEDIUM 4.3EPSS 4.08% | 29 January 2015 |
| CVE-2015-0235 | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2… | EXPLOIT ×2 ✓HIGH 10.0EPSS 94.6% | 28 January 2015 |
| CVE-2015-1376 | pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com. | EXPLOITMEDIUM 4.0EPSS 33.1% | 28 January 2015 |
| CVE-2015-1375 | pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files. | EXPLOITHIGH 7.5EPSS 11.9% | 28 January 2015 |
| CVE-2015-1374 | Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to hijack the authentication of administrators for requests that conduct (1) cross-site scripting (XSS), (2) SQL injection, or (3)… | EXPLOIT ✓MEDIUM 6.8EPSS 0.95% | 27 January 2015 |
| CVE-2015-1373 | Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter in a search request, (2) username in a login request, which is not… | EXPLOIT ✓MEDIUM 4.3EPSS 3.23% | 27 January 2015 |
| CVE-2015-1372 | SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p parameter in an update action to admin.php. | EXPLOIT ✓HIGH 7.5EPSS 2.36% | 27 January 2015 |
| CVE-2015-1371 | Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in custom/uploads/. | EXPLOIT ✓HIGH 7.5EPSS 8.06% | 27 January 2015 |
| CVE-2015-1368 | Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to credentials/, (2) inventories/, (3) projects/, or (4)… | EXPLOITMEDIUM 4.3EPSS 5.15% | 27 January 2015 |
| CVE-2015-1366 | Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the image_user parameter. | EXPLOITMEDIUM 4.3EPSS 6.13% | 27 January 2015 |
| CVE-2015-1365 | Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 13.0% | 27 January 2015 |
| CVE-2015-1364 | SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter to register/. | EXPLOITHIGH 7.5EPSS 1.34% | 27 January 2015 |
| CVE-2015-1362 | Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the maker element in an XML file. | EXPLOITHIGH 7.5EPSS 8.31% | 27 January 2015 |
| CVE-2015-0311 | Adobe Flash Player Remote Code Execution Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 85.8% | 23 January 2015 |
| CVE-2014-8802 | The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit… | EXPLOITMEDIUM 5.0EPSS 7.36% | 23 January 2015 |
| CVE-2015-0925 | The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subprocess reached through a named pipe, as demonstrated… | EXPLOIT ✓HIGH 9.0EPSS 52.2% | 22 January 2015 |
| CVE-2014-8008 | Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authenticated users to read arbitrary files via a full pathname in an API command, aka Bug ID CSCur49414. | EXPLOITMEDIUM 6.8EPSS 8.44% | 22 January 2015 |
| CVE-2015-0554 | The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly restrict access to the web interface, which allows remote attackers to obtain sensitive information or cause a denial of service (device… | EXPLOITHIGH 9.4EPSS 38.9% | 21 January 2015 |
| CVE-2015-1028 | Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remote authenticated users to inject arbitrary web script or HTML via the (1) domainname parameter to dnsProxy.cmd (DNS Proxy… | EXPLOIT ×3LOW 3.5EPSS 2.83% | 21 January 2015 |
| CVE-2014-6593 | Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. | EXPLOITMEDIUM 4.0EPSS 66.4% | 21 January 2015 |
| CVE-2015-0516 | Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL. | EXPLOITMEDIUM 4.0EPSS 7.41% | 21 January 2015 |
| CVE-2015-0514 | EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack. | EXPLOITMEDIUM 5.0EPSS 7.65% | 21 January 2015 |
| CVE-2014-9598 | The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file. | EXPLOITMEDIUM 6.8EPSS 6.31% | 21 January 2015 |
| CVE-2014-9597 | The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file. | EXPLOITMEDIUM 6.8EPSS 6.63% | 21 January 2015 |
| CVE-2014-9226 | The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Policies via unspecified vectors. | EXPLOITHIGH 7.2EPSS 1.54% | 21 January 2015 |
| CVE-2014-9225 | The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server… | EXPLOITMEDIUM 4.0EPSS 9.22% | 21 January 2015 |
| CVE-2014-9224 | Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x… | EXPLOITLOW 3.5EPSS 4.59% | 21 January 2015 |
| CVE-2014-7289 | SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary… | EXPLOITMEDIUM 6.5EPSS 4.55% | 21 January 2015 |
| CVE-2014-8386 | Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file. | EXPLOITHIGH 7.5EPSS 5.92% | 20 January 2015 |
| CVE-2014-9195 | Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic. | EXPLOIT ✓HIGH 7.5EPSS 80.7% | 17 January 2015 |
| CVE-2015-1060 | Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header. | EXPLOITMEDIUM 5.8EPSS 4.40% | 16 January 2015 |
| CVE-2015-1059 | Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in… | EXPLOITMEDIUM 6.5EPSS 5.43% | 16 January 2015 |
| CVE-2015-1058 | Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Category][title] parameter to admin/categories/add, (2) data[Field][title] parameter to… | EXPLOITMEDIUM 4.3EPSS 4.27% | 16 January 2015 |
| CVE-2015-1057 | Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary web script or HTML via the "Real Name" value. | EXPLOIT ✓MEDIUM 4.3EPSS 3.23% | 16 January 2015 |
| CVE-2015-1054 | Cross-site scripting (XSS) vulnerability in the Games feature in Crea8Social 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the Game Content field in Add Game. | EXPLOITLOW 3.5EPSS 2.93% | 16 January 2015 |
| CVE-2014-8904 | lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value. | EXPLOITHIGH 7.2EPSS 0.96% | 15 January 2015 |
| CVE-2014-9308 | Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote authenticated users to execute arbitrary code by uploading a file with an… | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 50.6% | 15 January 2015 |
| CVE-2014-8636 | The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges… | EXPLOIT ✓HIGH 7.5EPSS 64.8% | 14 January 2015 |
| CVE-2015-0016 | Microsoft Windows TS WebProxy Directory Traversal Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 75.8% | 13 January 2015 |
| CVE-2015-0004 | The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to… | EXPLOIT ✓HIGH 7.2EPSS 3.57% | 13 January 2015 |
| CVE-2015-0002 | The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify… | EXPLOIT ✓HIGH 7.2EPSS 13.8% | 13 January 2015 |
| CVE-2014-10038 | SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitrary SQL commands via the ids parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.35% | 13 January 2015 |
| CVE-2014-10037 | Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a .. | EXPLOITHIGH 7.5EPSS 18.8% | 13 January 2015 |
| CVE-2014-10035 | Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to inject arbitrary web script or HTML via the (1) sEcho parameter to comments_paginate.php or (2) stores_paginate.php or the (3)… | EXPLOIT ✓MEDIUM 4.3EPSS 3.50% | 13 January 2015 |
| CVE-2014-10034 | Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL commands via the (1) iDisplayLength or (2) iDisplayStart parameter to (a) comments_paginate.php or (b)… | EXPLOIT ✓MEDIUM 6.5EPSS 1.96% | 13 January 2015 |
| CVE-2014-10033 | SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action. | EXPLOIT ✓MEDIUM 6.5EPSS 1.80% | 13 January 2015 |
| CVE-2014-10032 | SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter. | EXPLOITMEDIUM 6.5EPSS 1.12% | 13 January 2015 |
| CVE-2014-10031 | Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary code via a long string in a UID command. | EXPLOIT ✓HIGH 7.5EPSS 3.74% | 13 January 2015 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.