Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 125 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-5865 | SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL commands via the activityid parameter in a stats action. | EXPLOIT ✓MEDIUM 6.5EPSS 1.12% | 20 October 2014 |
| CVE-2012-5701 | Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search_string or (2) where parameter in a contacts action, (3) dept_id parameter in a departments… | EXPLOIT ✓MEDIUM 6.8EPSS 0.68% | 20 October 2014 |
| CVE-2014-6308 | Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 22.3% | 20 October 2014 |
| CVE-2012-5244 | Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) return, (2) display, (3) table, or (4) search parameter to functions/suggest.php; (5) the id parameter to… | EXPLOIT ✓HIGH 7.5EPSS 1.50% | 20 October 2014 |
| CVE-2014-2647 | Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOIT ✓MEDIUM 4.3EPSS 3.40% | 19 October 2014 |
| CVE-2014-2995 | Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors, as demonstrated by the… | EXPLOITLOW 3.5EPSS 3.58% | 17 October 2014 |
| CVE-2014-2559 | Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that change unspecified plugin options via a… | EXPLOITMEDIUM 6.8EPSS 3.28% | 17 October 2014 |
| CVE-2014-8307 | Multiple cross-site scripting (XSS) vulnerabilities in skins/default/outline.tpl in C97net Cart Engine before 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter in the "drop down TOP menu (with path)" section or… | EXPLOITMEDIUM 4.3EPSS 1.49% | 16 October 2014 |
| CVE-2014-8306 | SQL injection vulnerability in the sql_query function in cart.php in C97net Cart Engine before 4.0 allows remote attackers to execute arbitrary SQL commands via the item_id variable, as demonstrated by the (1) item_id[0] or (2) item_id[] parameter. | EXPLOITHIGH 7.5EPSS 1.24% | 16 October 2014 |
| CVE-2014-8305 | Open redirect vulnerability in the redir function in includes/function.php in C97net Cart Engine before 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header to (1)… | EXPLOITMEDIUM 6.4EPSS 4.92% | 16 October 2014 |
| CVE-2014-3704 | The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys. | EXPLOIT ×5 ✓HIGH 7.5EPSS 100.0% | 16 October 2014 |
| CVE-2014-8295 | SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.35% | 15 October 2014 |
| CVE-2014-6312 | Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before 3.2.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site… | EXPLOITMEDIUM 4.3EPSS 4.15% | 15 October 2014 |
| CVE-2014-2927 | The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1 before HF11 and Enterprise Manager 3.x before 3.1.1 HF2, when configured in failover mode, does… | EXPLOITHIGH 9.3EPSS 7.92% | 15 October 2014 |
| CVE-2014-2022 | SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request. | EXPLOITHIGH 7.1EPSS 2.71% | 15 October 2014 |
| CVE-2014-4141 | Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | EXPLOITHIGH 9.3EPSS 30.5% | 15 October 2014 |
| CVE-2014-4138 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | EXPLOIT ✓HIGH 9.3EPSS 32.2% | 15 October 2014 |
| CVE-2014-4114 | Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability | KEVEXPLOIT ×6 ✓HIGH 7.8EPSS 81.6% | 15 October 2014 |
| CVE-2014-4113 | Microsoft Win32k Privilege Escalation Vulnerability | KEVEXPLOIT ×4 ✓HIGH 7.8EPSS 87.0% | 15 October 2014 |
| CVE-2014-0569 | Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before… | EXPLOIT ✓HIGH 9.3EPSS 91.3% | 15 October 2014 |
| CVE-2014-3671 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×14 ✓UnscoredEPSS — | 13 October 2014 |
| CVE-2014-7201 | Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via the (1) education,… | EXPLOITHIGH 7.5EPSS 2.35% | 10 October 2014 |
| CVE-2014-7200 | Cross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via the… | EXPLOITMEDIUM 4.3EPSS 3.24% | 10 October 2014 |
| CVE-2014-4312 | Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote attackers to inject arbitrary web script or HTML via the (1) Notes section to Order details; (2) Description section to "Order to… | EXPLOITMEDIUM 4.3EPSS 4.18% | 10 October 2014 |
| CVE-2014-4874 | 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page. | EXPLOITMEDIUM 4.0EPSS 8.88% | 10 October 2014 |
| CVE-2014-4873 | SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! | EXPLOITMEDIUM 6.5EPSS 4.19% | 10 October 2014 |
| CVE-2014-4872 | 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 79.3% | 10 October 2014 |
| CVE-2014-7226 | The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols. | EXPLOITHIGH 7.5EPSS 9.19% | 10 October 2014 |
| CVE-2014-5300 | Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execute commands via a message without a signature. | EXPLOITMEDIUM 5.0EPSS 7.36% | 8 October 2014 |
| CVE-2014-7205 | Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 78.6% | 8 October 2014 |
| CVE-2014-5308 | Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name parameter in a Search action to lib/project/projectView.php or (2) id parameter to lib/events/eventinfo.php. | EXPLOIT ✓HIGH 9.0EPSS 3.52% | 8 October 2014 |
| CVE-2014-7235 | htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP… | EXPLOITHIGH 10.0EPSS 43.3% | 7 October 2014 |
| CVE-2014-6287 | Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability | KEVEXPLOIT ×4 ✓CRITICAL 9.8EPSS 99.3% | 7 October 2014 |
| CVE-2014-6607 | M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via the fullname and password parameters, a different vulnerability than… | EXPLOITHIGH 7.5EPSS 6.65% | 6 October 2014 |
| CVE-2014-6409 | Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that change user passwords via the fullname and password parameters to /admin/users/update. | EXPLOITMEDIUM 6.8EPSS 2.27% | 6 October 2014 |
| CVE-2014-6389 | backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.56% | 6 October 2014 |
| CVE-2014-2044 | Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an… | EXPLOIT ✓HIGH 7.5EPSS 12.4% | 6 October 2014 |
| CVE-2013-1436 | The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action… | EXPLOIT ✓HIGH 7.5EPSS 8.98% | 6 October 2014 |
| CVE-2013-2645 | Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote attackers to hijack the authentication of administrators for requests that (1) enable FTP access (aka "FTP… | EXPLOIT ✓HIGH 9.3EPSS 3.01% | 6 October 2014 |
| CVE-2014-7227 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×14 ✓UnscoredEPSS — | 3 October 2014 |
| CVE-2014-6242 | Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby or (2) order parameter in the aiowpsec page to… | EXPLOITMEDIUM 6.5EPSS 4.15% | 2 October 2014 |
| CVE-2014-7190 | Multiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown or (2) reboot the server via a request to admin/system_shutdown.html. | EXPLOITMEDIUM 6.8EPSS 2.27% | 30 September 2014 |
| CVE-2014-6619 | Multiple cross-site scripting (XSS) vulnerabilities in register-exec.php in Restaurant Script (PizzaInn_Project) 1.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) fname, (2) lname, or (3) login parameter. | EXPLOITMEDIUM 4.3EPSS 3.22% | 30 September 2014 |
| CVE-2014-6278 | GNU Bash OS Command Injection Vulnerability | KEVEXPLOIT ×5 ✓HIGH 8.8EPSS 99.6% | 30 September 2014 |
| CVE-2013-3632 | The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter. | EXPLOIT ✓HIGH 8.8EPSS 57.1% | 29 September 2014 |
| CVE-2013-3083 | Cross-site request forgery (CSRF) vulnerability in cgi-bin/system_setting.exe in Belkin F5D8236-4 v2 allows remote attackers to hijack the authentication of administrators for requests that open the remote management interface on arbitrary ports via the… | EXPLOIT ✓MEDIUM 6.8EPSS 2.19% | 29 September 2014 |
| CVE-2013-2586 | XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method. | EXPLOITMEDIUM 4.3EPSS 5.21% | 29 September 2014 |
| CVE-2014-7187 | Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply… | EXPLOIT ×2 ✓HIGH 10.0EPSS 64.6% | 28 September 2014 |
| CVE-2014-7186 | The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here… | EXPLOIT ×2 ✓HIGH 10.0EPSS 66.0% | 28 September 2014 |
| CVE-2014-3631 | The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference… | EXPLOITHIGH 7.2EPSS 0.96% | 28 September 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.