Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 120 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-100039 | mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an out-of-bounds read. | EXPLOITLOW 2.1EPSS 0.66% | 13 January 2015 |
| CVE-2014-100031 | Multiple SQL injection vulnerabilities in Ganesha Digital Library (GDL) 4.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) download.php or (2) main.php. | EXPLOITHIGH 7.5EPSS 2.35% | 13 January 2015 |
| CVE-2014-100030 | Cross-site scripting (XSS) vulnerability in module/search/function.php in Ganesha Digital Library (GDL) 4.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a ByEge action. | EXPLOITMEDIUM 4.3EPSS 3.25% | 13 January 2015 |
| CVE-2014-100029 | Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 7.04% | 13 January 2015 |
| CVE-2014-100020 | SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. | EXPLOITHIGH 7.5EPSS 1.31% | 13 January 2015 |
| CVE-2014-100017 | Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitrary web script or HTML via the message field. | EXPLOITMEDIUM 4.3EPSS 3.22% | 13 January 2015 |
| CVE-2014-100015 | Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write to arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 57.4% | 13 January 2015 |
| CVE-2014-100014 | Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to execute arbitrary code via a long string in a (1) 2001, (2) 2002, or (3) 2003 opcode to port 3000. | EXPLOITHIGH 7.5EPSS 6.06% | 13 January 2015 |
| CVE-2014-100013 | Multiple cross-site scripting (XSS) vulnerabilities in clientResponse 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Subject or (2) Message field. | EXPLOITMEDIUM 4.3EPSS 1.47% | 13 January 2015 |
| CVE-2014-100012 | SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 13 January 2015 |
| CVE-2014-100011 | SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via the c parameter. | EXPLOITHIGH 7.5EPSS 1.32% | 13 January 2015 |
| CVE-2014-62771 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×14 ✓UnscoredEPSS — | 13 January 2015 |
| CVE-2014-10029 | SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL commands via the req_new_email parameter. | EXPLOITHIGH 7.5EPSS 2.57% | 13 January 2015 |
| CVE-2014-10023 | Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) edit_block.php, (2) edit_cat.php, (3) edit_note.php, or (4) rmv_topic.php in admincp/. | EXPLOITHIGH 7.5EPSS 3.28% | 13 January 2015 |
| CVE-2014-10021 | Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the… | EXPLOIT ×2 ✓HIGH 7.5EPSS 59.0% | 13 January 2015 |
| CVE-2014-10020 | SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOITHIGH 7.5EPSS 2.35% | 13 January 2015 |
| CVE-2014-10019 | Multiple cross-site request forgery (CSRF) vulnerabilities in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allow remote attackers to hijack the authentication of administrators for requests that (1) change the SSID or (2)… | EXPLOITMEDIUM 6.8EPSS 1.26% | 13 January 2015 |
| CVE-2014-10018 | Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allows remote attackers to inject arbitrary web script or HTML via the essid parameter. | EXPLOITMEDIUM 4.3EPSS 1.82% | 13 January 2015 |
| CVE-2014-10015 | SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOITHIGH 7.5EPSS 1.23% | 13 January 2015 |
| CVE-2014-10014 | Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and password of the administrator via an… | EXPLOITMEDIUM 6.8EPSS 1.97% | 13 January 2015 |
| CVE-2014-10013 | SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action. | EXPLOITHIGH 7.5EPSS 4.59% | 13 January 2015 |
| CVE-2014-10011 | Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView camera TV-IP422WN allows remote attackers to execute arbitrary code via a long string to the (1) CGI_ParamSet, (2) OpenFileDlg, (3)… | EXPLOITHIGH 7.5EPSS 10.1% | 13 January 2015 |
| CVE-2014-10010 | Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 7.65% | 13 January 2015 |
| CVE-2014-10009 | Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) notes parameter to the client page; (4) insu_name or (5) price parameter to… | EXPLOITMEDIUM 4.3EPSS 1.81% | 13 January 2015 |
| CVE-2014-10008 | Multiple cross-site request forgery (CSRF) vulnerabilities in Stark CRM 1.0 allow remote attackers to hijack the authentication of administrators for requests that add (1) an administrator via a crafted request to the admin page, (2) an agent via a… | EXPLOITMEDIUM 6.8EPSS 1.42% | 13 January 2015 |
| CVE-2014-10001 | Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the… | EXPLOITMEDIUM 6.8EPSS 2.26% | 13 January 2015 |
| CVE-2014-100003 | SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ym_download_id parameter to the default URI. | EXPLOIT ✓HIGH 7.5EPSS 4.23% | 13 January 2015 |
| CVE-2014-100002 | Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket. | EXPLOITMEDIUM 5.0EPSS 59.9% | 13 January 2015 |
| CVE-2013-7420 | Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART XML element in an HML file. | EXPLOIT ✓HIGH 7.5EPSS 6.98% | 12 January 2015 |
| CVE-2014-1155 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 10 January 2015 |
| CVE-2014-1137 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×2UnscoredEPSS — | 10 January 2015 |
| CVE-2014-1004 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 10 January 2015 |
| CVE-2014-9583 | common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass… | EXPLOIT ×2 ✓HIGH 10.0EPSS 80.2% | 8 January 2015 |
| CVE-2014-9582 | Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary web script or HTML via the short_name parameter in a rename action. | EXPLOITMEDIUM 4.3EPSS 1.47% | 8 January 2015 |
| CVE-2014-9581 | Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 3.58% | 8 January 2015 |
| CVE-2014-9580 | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or HTML via the Description field in a file upload. | EXPLOITMEDIUM 4.3EPSS 3.22% | 8 January 2015 |
| CVE-2015-0919 | Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php. | EXPLOITHIGH 7.5EPSS 2.12% | 8 January 2015 |
| CVE-2014-9473 | Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then… | EXPLOITHIGH 7.5EPSS 13.8% | 8 January 2015 |
| CVE-2014-9567 | Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the… | EXPLOIT ×2 ✓HIGH 7.5EPSS 43.3% | 7 January 2015 |
| CVE-2014-9528 | SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the from parameter to… | EXPLOITHIGH 7.5EPSS 2.34% | 6 January 2015 |
| CVE-2014-9522 | Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web script or HTML via the (1) author field to guestbook.php or (2) username field to account.php. | EXPLOITMEDIUM 4.3EPSS 3.50% | 5 January 2015 |
| CVE-2014-9516 | Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI, related to the "Web Site" input in the Profile section. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 5 January 2015 |
| CVE-2014-2598 | Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the… | EXPLOITMEDIUM 6.8EPSS 3.47% | 5 January 2015 |
| CVE-2013-2131 | Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function. | EXPLOIT ✓MEDIUM 5.0EPSS 10.6% | 4 January 2015 |
| CVE-2014-9464 | SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable. | EXPLOITHIGH 7.5EPSS 2.08% | 3 January 2015 |
| CVE-2010-5318 | The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by specifying the administrator's e-mail address in the email parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.76% | 3 January 2015 |
| CVE-2010-5317 | Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands via (1) the file_name parameter in an attachment action, (2) the post parameter in a show_comment action, (3)… | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 3 January 2015 |
| CVE-2010-5315 | Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create categories via a data array to news/saveCategories or (2) modify… | EXPLOITMEDIUM 6.8EPSS 1.06% | 3 January 2015 |
| CVE-2014-9457 | SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the id parameter to catalog.php. | EXPLOITMEDIUM 6.5EPSS 1.05% | 2 January 2015 |
| CVE-2014-9456 | Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Event element in an XML file. | EXPLOIT ✓HIGH 10.0EPSS 10.5% | 2 January 2015 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.