SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 120 of 501

CVESummaryPriorityPublished
CVE-2014-100039mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an out-of-bounds read.EXPLOITLOW 2.1EPSS 0.66%13 January 2015
CVE-2014-100031Multiple SQL injection vulnerabilities in Ganesha Digital Library (GDL) 4.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) download.php or (2) main.php.EXPLOITHIGH 7.5EPSS 2.35%13 January 2015
CVE-2014-100030Cross-site scripting (XSS) vulnerability in module/search/function.php in Ganesha Digital Library (GDL) 4.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a ByEge action.EXPLOITMEDIUM 4.3EPSS 3.25%13 January 2015
CVE-2014-100029Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 7.04%13 January 2015
CVE-2014-100020SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter.EXPLOITHIGH 7.5EPSS 1.31%13 January 2015
CVE-2014-100017Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitrary web script or HTML via the message field.EXPLOITMEDIUM 4.3EPSS 3.22%13 January 2015
CVE-2014-100015Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write to arbitrary files via a ..EXPLOIT ×2MEDIUM 6.4EPSS 57.4%13 January 2015
CVE-2014-100014Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to execute arbitrary code via a long string in a (1) 2001, (2) 2002, or (3) 2003 opcode to port 3000.EXPLOITHIGH 7.5EPSS 6.06%13 January 2015
CVE-2014-100013Multiple cross-site scripting (XSS) vulnerabilities in clientResponse 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Subject or (2) Message field.EXPLOITMEDIUM 4.3EPSS 1.47%13 January 2015
CVE-2014-100012SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i parameter.EXPLOITHIGH 7.5EPSS 1.20%13 January 2015
CVE-2014-100011SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via the c parameter.EXPLOITHIGH 7.5EPSS 1.32%13 January 2015
CVE-2014-62771Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ×14UnscoredEPSS —13 January 2015
CVE-2014-10029SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL commands via the req_new_email parameter.EXPLOITHIGH 7.5EPSS 2.57%13 January 2015
CVE-2014-10023Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) edit_block.php, (2) edit_cat.php, (3) edit_note.php, or (4) rmv_topic.php in admincp/.EXPLOITHIGH 7.5EPSS 3.28%13 January 2015
CVE-2014-10021Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the…EXPLOIT ×2HIGH 7.5EPSS 59.0%13 January 2015
CVE-2014-10020SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOITHIGH 7.5EPSS 2.35%13 January 2015
CVE-2014-10019Multiple cross-site request forgery (CSRF) vulnerabilities in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allow remote attackers to hijack the authentication of administrators for requests that (1) change the SSID or (2)…EXPLOITMEDIUM 6.8EPSS 1.26%13 January 2015
CVE-2014-10018Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allows remote attackers to inject arbitrary web script or HTML via the essid parameter.EXPLOITMEDIUM 4.3EPSS 1.82%13 January 2015
CVE-2014-10015SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOITHIGH 7.5EPSS 1.23%13 January 2015
CVE-2014-10014Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and password of the administrator via an…EXPLOITMEDIUM 6.8EPSS 1.97%13 January 2015
CVE-2014-10013SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.EXPLOITHIGH 7.5EPSS 4.59%13 January 2015
CVE-2014-10011Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView camera TV-IP422WN allows remote attackers to execute arbitrary code via a long string to the (1) CGI_ParamSet, (2) OpenFileDlg, (3)…EXPLOITHIGH 7.5EPSS 10.1%13 January 2015
CVE-2014-10010Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 7.65%13 January 2015
CVE-2014-10009Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) notes parameter to the client page; (4) insu_name or (5) price parameter to…EXPLOITMEDIUM 4.3EPSS 1.81%13 January 2015
CVE-2014-10008Multiple cross-site request forgery (CSRF) vulnerabilities in Stark CRM 1.0 allow remote attackers to hijack the authentication of administrators for requests that add (1) an administrator via a crafted request to the admin page, (2) an agent via a…EXPLOITMEDIUM 6.8EPSS 1.42%13 January 2015
CVE-2014-10001Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the…EXPLOITMEDIUM 6.8EPSS 2.26%13 January 2015
CVE-2014-100003SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ym_download_id parameter to the default URI.EXPLOITHIGH 7.5EPSS 4.23%13 January 2015
CVE-2014-100002Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.EXPLOITMEDIUM 5.0EPSS 59.9%13 January 2015
CVE-2013-7420Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART XML element in an HML file.EXPLOITHIGH 7.5EPSS 6.98%12 January 2015
CVE-2014-1155Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —10 January 2015
CVE-2014-1137Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ×2UnscoredEPSS —10 January 2015
CVE-2014-1004Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —10 January 2015
CVE-2014-9583common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass…EXPLOIT ×2HIGH 10.0EPSS 80.2%8 January 2015
CVE-2014-9582Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary web script or HTML via the short_name parameter in a rename action.EXPLOITMEDIUM 4.3EPSS 1.47%8 January 2015
CVE-2014-9581Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 3.58%8 January 2015
CVE-2014-9580Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or HTML via the Description field in a file upload.EXPLOITMEDIUM 4.3EPSS 3.22%8 January 2015
CVE-2015-0919Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php.EXPLOITHIGH 7.5EPSS 2.12%8 January 2015
CVE-2014-9473Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then…EXPLOITHIGH 7.5EPSS 13.8%8 January 2015
CVE-2014-9567Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the…EXPLOIT ×2HIGH 7.5EPSS 43.3%7 January 2015
CVE-2014-9528SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the from parameter to…EXPLOITHIGH 7.5EPSS 2.34%6 January 2015
CVE-2014-9522Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web script or HTML via the (1) author field to guestbook.php or (2) username field to account.php.EXPLOITMEDIUM 4.3EPSS 3.50%5 January 2015
CVE-2014-9516Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI, related to the "Web Site" input in the Profile section.EXPLOITMEDIUM 4.3EPSS 1.47%5 January 2015
CVE-2014-2598Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the…EXPLOITMEDIUM 6.8EPSS 3.47%5 January 2015
CVE-2013-2131Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function.EXPLOITMEDIUM 5.0EPSS 10.6%4 January 2015
CVE-2014-9464SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable.EXPLOITHIGH 7.5EPSS 2.08%3 January 2015
CVE-2010-5318The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by specifying the administrator's e-mail address in the email parameter.EXPLOITMEDIUM 4.3EPSS 1.76%3 January 2015
CVE-2010-5317Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands via (1) the file_name parameter in an attachment action, (2) the post parameter in a show_comment action, (3)…EXPLOITHIGH 7.5EPSS 1.20%3 January 2015
CVE-2010-5315Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create categories via a data array to news/saveCategories or (2) modify…EXPLOITMEDIUM 6.8EPSS 1.06%3 January 2015
CVE-2014-9457SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the id parameter to catalog.php.EXPLOITMEDIUM 6.5EPSS 1.05%2 January 2015
CVE-2014-9456Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Event element in an XML file.EXPLOITHIGH 10.0EPSS 10.5%2 January 2015

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.