Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 124 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-4076 | Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2) tcpip6.sys, aka "TCP/IP Elevation of Privilege Vulnerability." | EXPLOIT ×2HIGH 7.2EPSS 22.7% | 11 November 2014 |
| CVE-2014-8652 | Elipse E3 3.x and earlier allows remote attackers to cause a denial of service (application crash and plant outage) via a rapid series of HTTP requests to index.html on TCP port 1681. | EXPLOITMEDIUM 5.0EPSS 2.73% | 10 November 2014 |
| CVE-2014-3439 | ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vectors. | EXPLOITMEDIUM 6.1EPSS 5.84% | 7 November 2014 |
| CVE-2014-3438 | Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOITMEDIUM 4.3EPSS 3.92% | 7 November 2014 |
| CVE-2014-3437 | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an… | EXPLOITHIGH 7.5EPSS 8.54% | 7 November 2014 |
| CVE-2014-6030 | Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to execute arbitrary SQL commands via the SurveyID parameter to survey/ReviewReadOnlySurvey.aspx or (2) remote authenticated users to… | EXPLOITMEDIUM 6.5EPSS 1.73% | 6 November 2014 |
| CVE-2014-5258 | Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files via a .. | EXPLOITMEDIUM 4.0EPSS 20.3% | 6 November 2014 |
| CVE-2014-8657 | The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to cause a denial of service (disconnect all wifi clients) via a request to wirelessChannelStatus.html. | EXPLOITMEDIUM 5.0EPSS 6.76% | 6 November 2014 |
| CVE-2014-8656 | The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of (1) admin for the admin account and (2) compalbn for the root account, which makes it easier for remote attackers… | EXPLOITHIGH 10.0EPSS 10.9% | 6 November 2014 |
| CVE-2014-8655 | The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to bypass authentication and obtain sensitive information via an (a) admin or a (b) root value in the userData cookie… | EXPLOITMEDIUM 5.0EPSS 7.38% | 6 November 2014 |
| CVE-2014-8654 | Multiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway hardware 1.0 with firmware CH6640-3.5.11.7-NOSH allow remote attackers to hijack the authentication of administrators for… | EXPLOITMEDIUM 6.8EPSS 2.87% | 6 November 2014 |
| CVE-2014-8653 | Cross-site scripting (XSS) vulnerability in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to inject arbitrary web script or HTML via the userData cookie. | EXPLOITMEDIUM 4.3EPSS 3.50% | 6 November 2014 |
| CVE-2014-0995 | The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled recursion and crash) via a trace level with a wildcard in the Trace Pattern. | EXPLOIT ✓MEDIUM 5.0EPSS 10.5% | 6 November 2014 |
| CVE-2014-2937 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 6 November 2014 |
| CVE-2014-8586 | SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter. | EXPLOITHIGH 7.5EPSS 40.1% | 4 November 2014 |
| CVE-2014-7176 | SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman. | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 2.20% | 4 November 2014 |
| CVE-2013-7057 | Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that upload arbitrary files via a crafted request to api/v1.0/files/. | EXPLOITMEDIUM 6.8EPSS 1.43% | 4 November 2014 |
| CVE-2014-4311 | Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mail Connection passwords by reading HTML source code of the database connection and email settings page. | EXPLOITMEDIUM 5.0EPSS 5.78% | 4 November 2014 |
| CVE-2014-7228 | Professional 3.0.0 through 4.0.2; Backup Professional for WordPress 1.0.b1 through 1.1.3; Solo 1.0.b1 through 1.1.2; Admin Tools Core and Professional 2.0.0 through 2.4.4; and CMS Update 1.0.a1 through 1.0.1, when performing a backup or update for an… | EXPLOIT ✓HIGH 7.5EPSS 55.4% | 3 November 2014 |
| CVE-2014-5507 | iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local users to gain privileges via a Trojan horse file. | EXPLOITHIGH 7.2EPSS 0.95% | 3 November 2014 |
| CVE-2014-8577 | Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Contact][title] parameter to admin/contacts/contacts/add page; (2) data[Block][title] or (3)… | EXPLOITMEDIUM 4.3EPSS 4.25% | 31 October 2014 |
| CVE-2014-7177 | XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/. | EXPLOIT ✓MEDIUM 4.0EPSS 3.32% | 31 October 2014 |
| CVE-2013-7409 | Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .m3u (playlist) file. | EXPLOIT ×5 ✓HIGH 7.5EPSS 67.9% | 30 October 2014 |
| CVE-2013-3304 | Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 3.79% | 30 October 2014 |
| CVE-2011-2702 | Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows context-dependent attackers to execute arbitrary code via a negative length parameter to (1)… | EXPLOIT ✓MEDIUM 6.8EPSS 8.46% | 27 October 2014 |
| CVE-2014-5520 | SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, which is not properly handled by plugins/useradmin/fingeruser.php. | EXPLOITHIGH 7.5EPSS 2.56% | 26 October 2014 |
| CVE-2013-6796 | The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, which triggers an LDAP anonymous bind. | EXPLOIT ✓MEDIUM 5.0EPSS 6.30% | 26 October 2014 |
| CVE-2014-6037 | Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary code by uploading a ZIP file which contains an executable file with .. | EXPLOIT ×2 ✓HIGH 7.5EPSS 84.2% | 26 October 2014 |
| CVE-2014-2987 | Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allow remote attackers to hijack the authentication… | EXPLOITMEDIUM 6.8EPSS 1.36% | 26 October 2014 |
| CVE-2014-0476 | The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. | EXPLOIT ×2 ✓LOW 3.7EPSS 3.83% | 25 October 2014 |
| CVE-2014-2021 | Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the… | EXPLOITLOW 3.5EPSS 3.39% | 25 October 2014 |
| CVE-2014-7281 | Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to… | EXPLOITMEDIUM 6.8EPSS 2.63% | 23 October 2014 |
| CVE-2014-3829 | displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the… | EXPLOIT ✓HIGH 10.0EPSS 80.2% | 23 October 2014 |
| CVE-2014-3828 | Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to… | EXPLOIT ×2 ✓HIGH 10.0EPSS 72.7% | 23 October 2014 |
| CVE-2014-6352 | Microsoft Windows Code Injection Vulnerability | KEVEXPLOIT ×6 ✓HIGH 7.8EPSS 77.5% | 22 October 2014 |
| CVE-2014-2531 | SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search… | EXPLOIT ✓MEDIUM 6.5EPSS 1.12% | 21 October 2014 |
| CVE-2014-8380 | Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer Header in a "404 Not Found" response. | EXPLOITMEDIUM 4.3EPSS 3.28% | 21 October 2014 |
| CVE-2014-7280 | Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header. | EXPLOIT ✓MEDIUM 4.3EPSS 3.27% | 21 October 2014 |
| CVE-2014-5006 | Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. | EXPLOIT ×2 ✓HIGH 7.5EPSS 25.1% | 21 October 2014 |
| CVE-2014-5005 | Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. | EXPLOIT ×2 ✓HIGH 7.5EPSS 77.8% | 21 October 2014 |
| CVE-2014-8375 | SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQL commands via the selected_group parameter in a gb_ajax_get_group action to wp-admin/admin-ajax.php. | EXPLOIT ✓MEDIUM 6.5EPSS 3.23% | 21 October 2014 |
| CVE-2014-7140 | Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.x before 10.1-129.11 and 10.5 before 10.5-50.10 allows remote attackers to execute arbitrary code via unknown vectors. | EXPLOIT ✓HIGH 7.5EPSS 16.2% | 21 October 2014 |
| CVE-2012-5702 | Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3)… | EXPLOIT ✓MEDIUM 4.3EPSS 2.08% | 21 October 2014 |
| CVE-2012-5243 | functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request. | EXPLOIT ✓MEDIUM 5.0EPSS 2.76% | 21 October 2014 |
| CVE-2012-5242 | Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.54% | 21 October 2014 |
| CVE-2014-5276 | Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject arbitrary web script or HTML via (1) an uploaded profile picture or (2) the edit parameter to profiles/index.php. | EXPLOITLOW 3.5EPSS 2.64% | 20 October 2014 |
| CVE-2014-5275 | Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) password, (2) email, or (3) id parameter. | EXPLOITMEDIUM 6.5EPSS 1.95% | 20 October 2014 |
| CVE-2014-3978 | SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands via the First Name and Last Name fields in a new address book contact. | EXPLOITMEDIUM 6.5EPSS 1.73% | 20 October 2014 |
| CVE-2014-5094 | Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo function. | EXPLOITMEDIUM 5.0EPSS 5.54% | 20 October 2014 |
| CVE-2014-2081 | Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 2014.x before 2014.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password… | EXPLOIT ✓HIGH 7.5EPSS 2.08% | 20 October 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.