Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 123 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-8429 | Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts via a crafted… | EXPLOITMEDIUM 6.8EPSS 2.24% | 28 November 2014 |
| CVE-2014-8425 | The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files. | EXPLOITHIGH 7.8EPSS 3.14% | 28 November 2014 |
| CVE-2014-8424 | ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication. | EXPLOITHIGH 7.8EPSS 59.6% | 28 November 2014 |
| CVE-2014-8423 | Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors. | EXPLOITHIGH 10.0EPSS 62.5% | 28 November 2014 |
| CVE-2014-7178 | Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function. | EXPLOIT ✓HIGH 9.3EPSS 5.06% | 28 November 2014 |
| CVE-2014-9101 | Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS)… | EXPLOITMEDIUM 6.8EPSS 2.43% | 26 November 2014 |
| CVE-2014-9099 | Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the whydowork_adsense… | EXPLOIT ✓MEDIUM 6.8EPSS 2.69% | 26 November 2014 |
| CVE-2014-9098 | Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly before 2014-07-23, for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the… | EXPLOITLOW 3.5EPSS 2.88% | 26 November 2014 |
| CVE-2014-9097 | Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07-23, for WordPress allow (1) remote attackers to execute arbitrary SQL commands via the vid parameter… | EXPLOIT ×2HIGH 7.5EPSS 5.02% | 26 November 2014 |
| CVE-2014-9096 | Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) n parameter. | EXPLOITHIGH 7.5EPSS 2.40% | 26 November 2014 |
| CVE-2014-9095 | Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to license/records. | EXPLOITHIGH 7.5EPSS 2.35% | 26 November 2014 |
| CVE-2014-9094 | Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) swfloc or (2) designrand… | EXPLOIT ✓MEDIUM 4.3EPSS 7.31% | 26 November 2014 |
| CVE-2014-9034 | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a… | EXPLOIT ×2MEDIUM 5.0EPSS 82.7% | 25 November 2014 |
| CVE-2014-9016 | The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request. | EXPLOITMEDIUM 5.0EPSS 82.2% | 24 November 2014 |
| CVE-2014-8682 | Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in… | EXPLOITHIGH 7.5EPSS 33.4% | 21 November 2014 |
| CVE-2014-8681 | SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.6.x before 0.5.6.1025 Beta allows remote attackers to execute arbitrary SQL commands via the label parameter to user/repos/issues. | EXPLOITHIGH 7.5EPSS 4.44% | 21 November 2014 |
| CVE-2014-8469 | Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header. | EXPLOITMEDIUM 4.3EPSS 3.22% | 21 November 2014 |
| CVE-2014-5395 | Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote… | EXPLOITMEDIUM 6.8EPSS 0.92% | 21 November 2014 |
| CVE-2014-8768 | Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame. | EXPLOITMEDIUM 5.0EPSS 19.8% | 20 November 2014 |
| CVE-2014-8493 | ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1. | EXPLOIT ×2MEDIUM 5.0EPSS 8.07% | 20 November 2014 |
| CVE-2014-9005 | Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL commands via the (1) country, (2) gender1, or ((3) gender2 parameter in a search action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.21% | 20 November 2014 |
| CVE-2014-9004 | Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a member_profile action to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 20 November 2014 |
| CVE-2014-9001 | reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) APPTMIN, (2) APPTHR, (3) APPTDA, (4) APPTMO, (5) APPTYR, or (6) APPTPHONE parameters. | EXPLOITMEDIUM 6.5EPSS 2.80% | 20 November 2014 |
| CVE-2014-9000 | Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. | EXPLOITMEDIUM 6.5EPSS 8.87% | 20 November 2014 |
| CVE-2014-8998 | lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.php, which is processed by the preg_replace function with the eval switch. | EXPLOIT ✓MEDIUM 6.5EPSS 35.9% | 20 November 2014 |
| CVE-2014-8997 | Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct… | EXPLOIT ✓HIGH 7.5EPSS 9.13% | 20 November 2014 |
| CVE-2014-8995 | SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie. | EXPLOITMEDIUM 5.0EPSS 2.22% | 20 November 2014 |
| CVE-2014-8387 | cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi. | EXPLOIT ✓HIGH 9.0EPSS 30.9% | 20 November 2014 |
| CVE-2014-7910 | Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | EXPLOIT ×14 ✓HIGH 7.5EPSS 7.65% | 19 November 2014 |
| CVE-2014-6324 | Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 87.3% | 18 November 2014 |
| CVE-2014-8598 | The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive information via the export page. | EXPLOIT ✓MEDIUM 6.4EPSS 38.5% | 18 November 2014 |
| CVE-2014-7146 | The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an XML file, which is not properly handled when executing the preg_replace… | EXPLOIT ×2 ✓HIGH 7.5EPSS 50.6% | 18 November 2014 |
| CVE-2012-6665 | Directory traversal vulnerability in index.php in phpMoneyBooks 1.0.4 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 3.09% | 17 November 2014 |
| CVE-2012-1669 | Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 3.52% | 17 November 2014 |
| CVE-2014-8954 | Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Description fields in a playlist or the (3) filter parameter in an explore action to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 3.22% | 17 November 2014 |
| CVE-2014-8953 | Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to hijack the authentication of administrators or requests that (1) add an admin account via a request to… | EXPLOITMEDIUM 6.8EPSS 2.27% | 17 November 2014 |
| CVE-2014-8727 | Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role to enumerate and delete arbitrary files via a .. | EXPLOITMEDIUM 6.2EPSS 1.01% | 17 November 2014 |
| CVE-2014-8596 | Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id parameter in a 2 action to files/administration/submissions.php or (2) status parameter to… | EXPLOITHIGH 7.5EPSS 3.26% | 17 November 2014 |
| CVE-2014-8517 | The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP… | EXPLOIT ×2 ✓HIGH 7.5EPSS 69.1% | 17 November 2014 |
| CVE-2014-8499 | Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the… | EXPLOITMEDIUM 6.5EPSS 36.4% | 17 November 2014 |
| CVE-2014-8498 | SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands… | EXPLOITMEDIUM 6.5EPSS 12.7% | 17 November 2014 |
| CVE-2014-8949 | The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter. | EXPLOITMEDIUM 6.0EPSS 7.51% | 16 November 2014 |
| CVE-2014-8948 | Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to hijack the authentication of administrators for requests that with an unspecified impact via the i4w_trace parameter. | EXPLOITMEDIUM 6.8EPSS 3.72% | 16 November 2014 |
| CVE-2014-2268 | views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by… | EXPLOIT ✓MEDIUM 5.0EPSS 31.2% | 16 November 2014 |
| CVE-2014-8770 | Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for Magento Community Edition (CE) allows remote authenticated users to execute arbitrary code by uploading a ZIP file that… | EXPLOITHIGH 9.0EPSS 6.54% | 13 November 2014 |
| CVE-2014-8359 | Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll in the Mobile Partner directory. | EXPLOITHIGH 7.2EPSS 1.30% | 13 November 2014 |
| CVE-2014-8555 | Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 7.45% | 12 November 2014 |
| CVE-2014-1635 | Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote attackers to execute arbitrary code via a long string in the jump parameter. | EXPLOIT ✓HIGH 10.0EPSS 67.5% | 12 November 2014 |
| CVE-2014-8440 | Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers… | EXPLOIT ✓HIGH 10.0EPSS 81.9% | 11 November 2014 |
| CVE-2014-6332 | Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability | KEVEXPLOIT ×9 ✓HIGH 8.8EPSS 95.0% | 11 November 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.