Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 121 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-9448 | Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long string in a WAX file. | EXPLOIT ×3 ✓HIGH 7.5EPSS 6.30% | 2 January 2015 |
| CVE-2014-9445 | SQL injection vulnerability in incl/create.inc.php in Installatron GQ File Manager 0.2.5 allows remote attackers to execute arbitrary SQL commands via the create parameter to index.php. | EXPLOITHIGH 7.5EPSS 1.28% | 2 January 2015 |
| CVE-2014-9440 | SQL injection vulnerability in browse.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the category parameter. | EXPLOITHIGH 7.5EPSS 2.35% | 2 January 2015 |
| CVE-2014-9439 | Cross-site scripting (XSS) vulnerability in Easy File Sharing Web Server 6.8 allows remote attackers to inject arbitrary web script or HTML via the username field during registration, which is not properly handled by forum.ghp. | EXPLOITMEDIUM 4.3EPSS 1.50% | 2 January 2015 |
| CVE-2014-9436 | Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes) in the fileName parameter to getRdsLogFile. | EXPLOITMEDIUM 5.0EPSS 6.90% | 2 January 2015 |
| CVE-2014-9435 | Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to execute arbitrary SQL commands via the (1) sectionID parameter to admin/managersection.php, (2) userID parameter to admin/edituser.php, (3) username… | EXPLOITMEDIUM 6.5EPSS 1.12% | 2 January 2015 |
| CVE-2014-9434 | Cross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend in Absolut Engine 1.73 allows remote authenticated users to inject arbitrary web script or HTML via the title parameter. | EXPLOITLOW 3.5EPSS 1.56% | 2 January 2015 |
| CVE-2011-5318 | Multiple cross-site request forgery (CSRF) vulnerabilities in diafan.CMS before 5.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify articles via a save_post action to admin/news/saveNEWS_ID/, (2) modify… | EXPLOITMEDIUM 6.8EPSS 1.06% | 1 January 2015 |
| CVE-2011-5313 | Multiple SQL injection vulnerabilities in includes/password.php in Redaxscript 0.3.2 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) password parameter to the password_reset program. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 1 January 2015 |
| CVE-2011-5289 | The SaveDecrypted method in the ChilkatCrypt2.ChilkatOmaDrm.1 ActiveX control in ChilkatCrypt2.dll in aTube Catcher 2.3.570 allows remote attackers to write to arbitrary files via a pathname in the argument. | EXPLOIT ✓MEDIUM 6.4EPSS 2.25% | 1 January 2015 |
| CVE-2011-5286 | SQL injection vulnerability in social-slider-2/ajax.php in the Social Slider plugin before 7.4.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the rA array parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.94% | 1 January 2015 |
| CVE-2014-9119 | Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 15.7% | 31 December 2014 |
| CVE-2011-5284 | Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to hijack the authentication of administrators for requests that… | EXPLOITMEDIUM 6.8EPSS 2.27% | 31 December 2014 |
| CVE-2011-5283 | Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to inject arbitrary web script or HTML via the IP parameter in a Run action. | EXPLOITMEDIUM 4.3EPSS 3.22% | 31 December 2014 |
| CVE-2014-9254 | bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injection attacks via the code parameter in an unsubscribe action to index.php. | EXPLOITHIGH 7.5EPSS 1.31% | 31 December 2014 |
| CVE-2014-1908 | The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct… | EXPLOITMEDIUM 5.0EPSS 6.79% | 29 December 2014 |
| CVE-2014-1905 | Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, and then… | EXPLOITHIGH 10.0EPSS 9.79% | 29 December 2014 |
| CVE-2012-1415 | Cross-site request forgery (CSRF) vulnerability in lib/logout.php in DFLabs PTK 1.0.5 and earlier allows remote attackers to hijack the authentication of administrators or investigators for requests that trigger a logout. | EXPLOITMEDIUM 6.8EPSS 1.06% | 28 December 2014 |
| CVE-2011-4722 | Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 58.2% | 28 December 2014 |
| CVE-2010-5075 | Integer overflow in aswFW.sys 5.0.594.0 in Avast! | EXPLOITLOW 2.1EPSS 0.91% | 28 December 2014 |
| CVE-2012-1203 | Cross-site request forgery (CSRF) vulnerability in starnet/index.php in SyndeoCMS 3.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts via a save_user action. | EXPLOITMEDIUM 6.8EPSS 1.06% | 28 December 2014 |
| CVE-2011-4720 | Hillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2) WRQ operation. | EXPLOIT ✓MEDIUM 5.0EPSS 2.68% | 28 December 2014 |
| CVE-2013-6227 | Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to execute arbitrary code by uploading an executable file, and then accessing this… | EXPLOITHIGH 7.5EPSS 7.96% | 27 December 2014 |
| CVE-2013-6043 | The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of requests. | EXPLOITMEDIUM 5.0EPSS 2.89% | 27 December 2014 |
| CVE-2013-6041 | index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action. | EXPLOITHIGH 7.5EPSS 3.56% | 27 December 2014 |
| CVE-2014-9418 | The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users to cause a denial of service (memory overflow) via unspecified vectors. | EXPLOITLOW 2.1EPSS 0.67% | 24 December 2014 |
| CVE-2014-9417 | The Meeting component in Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted image. | EXPLOITLOW 2.1EPSS 0.64% | 24 December 2014 |
| CVE-2014-9416 | Multiple untrusted search path vulnerabilities in Huawei eSpace Desktop before V200R003C00 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) mfc71enu.dll, (2) mfc71loc.dll, (3) tcapi.dll, or (4)… | EXPLOITMEDIUM 4.4EPSS 0.83% | 24 December 2014 |
| CVE-2014-9415 | Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QES file. | EXPLOITLOW 1.9EPSS 0.57% | 24 December 2014 |
| CVE-2014-8810 | SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action. | EXPLOITMEDIUM 6.5EPSS 3.61% | 24 December 2014 |
| CVE-2014-4322 | drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain offset, length, and base values within an ioctl call,… | EXPLOITHIGH 7.2EPSS 2.04% | 24 December 2014 |
| CVE-2014-9412 | Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter to roma/jsp/debug/debug.jsp or (2) an arbitrary parameter in a… | EXPLOITMEDIUM 4.3EPSS 3.24% | 23 December 2014 |
| CVE-2014-9115 | SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to… | EXPLOITHIGH 7.5EPSS 2.66% | 23 December 2014 |
| CVE-2014-5216 | Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allow remote attackers to inject arbitrary web script or HTML via (1) the location parameter in a dev.Empty action to nps/servlet/webacc, (2) the… | EXPLOITMEDIUM 4.3EPSS 3.24% | 23 December 2014 |
| CVE-2014-7286 | Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain privileges via unspecified vectors. | EXPLOITHIGH 7.2EPSS 1.19% | 22 December 2014 |
| CVE-2014-9258 | SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter. | EXPLOITMEDIUM 6.5EPSS 3.07% | 19 December 2014 |
| CVE-2014-7208 | GParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in a crafted filesystem label. | EXPLOITHIGH 7.2EPSS 1.11% | 19 December 2014 |
| CVE-2014-6395 | Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted password length value that is… | EXPLOITHIGH 7.5EPSS 12.7% | 19 December 2014 |
| CVE-2014-8272 | The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a… | EXPLOITMEDIUM 5.0EPSS 19.0% | 19 December 2014 |
| CVE-2014-7285 | The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts. | EXPLOIT ✓MEDIUM 6.5EPSS 50.3% | 17 December 2014 |
| CVE-2014-9322 | arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a… | EXPLOIT ×2HIGH 7.8EPSS 1.54% | 17 December 2014 |
| CVE-2014-4936 | The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earlier allow man-in-the-middle attackers to execute arbitrary code by spoofing the update server and… | EXPLOIT ✓HIGH 9.3EPSS 16.8% | 16 December 2014 |
| CVE-2014-8507 | Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPushManager module in Android before 5.0.0 allow remote attackers to execute arbitrary SQL commands, and… | EXPLOITHIGH 7.5EPSS 1.55% | 15 December 2014 |
| CVE-2014-2973 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×4 ✓UnscoredEPSS — | 15 December 2014 |
| CVE-2014-7192 | Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file. | EXPLOITHIGH 10.0EPSS 13.0% | 11 December 2014 |
| CVE-2014-6363 | vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript… | EXPLOIT ✓HIGH 9.3EPSS 28.4% | 11 December 2014 |
| CVE-2014-7866 | Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to write and execute arbitrary files via a .. | EXPLOIT ×2HIGH 7.5EPSS 79.8% | 10 December 2014 |
| CVE-2014-9350 | TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of service (httpd crash) via vectors involving a "new" value in the isNew parameter to PingIframeRpm.htm. | EXPLOITMEDIUM 5.0EPSS 7.17% | 8 December 2014 |
| CVE-2014-9349 | Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) nom or (2) user_agent parameter to admin/robots.php. | EXPLOITMEDIUM 4.3EPSS 3.22% | 8 December 2014 |
| CVE-2014-9348 | SQL injection vulnerability in the formulaireRobot function in admin/robots.lib.php in RobotStats 1.0 allows remote attackers to execute arbitrary SQL commands via the robot parameter to admin/robots.php. | EXPLOITHIGH 7.5EPSS 2.35% | 8 December 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.