SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 126 of 501

CVESummaryPriorityPublished
CVE-2014-6277GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer…EXPLOIT ×3HIGH 10.0EPSS 69.8%27 September 2014
CVE-2014-6446The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.EXPLOITHIGH 7.5EPSS 46.2%26 September 2014
CVE-2014-3659Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ×14UnscoredEPSS —25 September 2014
CVE-2014-7169GNU Bourne-Again Shell (Bash) Arbitrary Code Execution VulnerabilityKEVEXPLOIT ×15CRITICAL 9.8EPSS 99.9%25 September 2014
CVE-2014-6271GNU Bourne-Again Shell (Bash) Arbitrary Code Execution VulnerabilityKEVEXPLOIT ×21CRITICAL 9.8EPSS 100.0%24 September 2014
CVE-2012-5700Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/index.php or the (2) username or (3) password parameter in…EXPLOITMEDIUM 4.3EPSS 1.81%22 September 2014
CVE-2014-7153SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to…EXPLOITMEDIUM 6.5EPSS 2.29%22 September 2014
CVE-2012-2588Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.EXPLOITMEDIUM 4.3EPSS 2.39%19 September 2014
CVE-2014-4404Apple OS X Heap-Based Buffer Overflow VulnerabilityKEVEXPLOITHIGH 7.8EPSS 48.9%18 September 2014
CVE-2012-6658Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName configuration in snmpd.conf.EXPLOITMEDIUM 4.3EPSS 2.02%17 September 2014
CVE-2012-2956SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json.EXPLOITMEDIUM 6.5EPSS 1.10%17 September 2014
CVE-2012-2583Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email.EXPLOITMEDIUM 4.3EPSS 3.73%17 September 2014
CVE-2012-1507Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltResumeHsp.php, (2) sortOrder1 parameter to…EXPLOIT ×3MEDIUM 4.3EPSS 2.35%17 September 2014
CVE-2012-1506SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php.EXPLOITMEDIUM 6.5EPSS 1.30%17 September 2014
CVE-2012-1417Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.EXPLOITLOW 3.5EPSS 1.73%17 September 2014
CVE-2014-2009The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.EXPLOITMEDIUM 5.0EPSS 7.41%12 September 2014
CVE-2014-2008SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to execute arbitrary SQL commands via the TID parameter.EXPLOITHIGH 7.5EPSS 2.64%12 September 2014
CVE-2012-1556Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php.EXPLOITMEDIUM 4.3EPSS 3.26%12 September 2014
CVE-2014-3740Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket request to the portal page.EXPLOITLOW 3.5EPSS 3.38%11 September 2014
CVE-2014-6043ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do.EXPLOITMEDIUM 6.5EPSS 12.8%11 September 2014
CVE-2014-5460Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in…EXPLOIT ×2MEDIUM 6.5EPSS 70.9%11 September 2014
CVE-2014-6235Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary code via unknown vectors.EXPLOITHIGH 7.5EPSS 5.57%11 September 2014
CVE-2014-6070Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML via the hostname in (1) index.php or (2) detail.php.EXPLOITMEDIUM 4.3EPSS 3.58%11 September 2014
CVE-2014-5519The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp.EXPLOITHIGH 7.5EPSS 65.0%11 September 2014
CVE-2014-2223Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file and a non-zero length PNG file, then…EXPLOITHIGH 7.5EPSS 10.0%11 September 2014
CVE-2012-4240SQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.EXPLOITMEDIUM 6.5EPSS 1.25%11 September 2014
CVE-2012-0984Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to_userid parameter to modules/pm/pmlite.php or the (2) current_file, (3) imgcat_id, or (4) target…EXPLOIT ×3MEDIUM 4.3EPSS 4.16%11 September 2014
CVE-2014-2624Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2264.EXPLOITHIGH 10.0EPSS 65.4%11 September 2014
CVE-2014-4865Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attackers to hijack the authentication of arbitrary users.EXPLOITMEDIUM 6.8EPSS 1.24%10 September 2014
CVE-2014-0556Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK…EXPLOITHIGH 10.0EPSS 84.3%10 September 2014
CVE-2014-5464Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.EXPLOITMEDIUM 4.3EPSS 4.45%8 September 2014
CVE-2014-5377ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.EXPLOITMEDIUM 5.0EPSS 57.5%4 September 2014
CVE-2012-4768Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.EXPLOITMEDIUM 4.3EPSS 10.5%4 September 2014
CVE-2012-4234Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via the group parameter.EXPLOITMEDIUM 4.3EPSS 2.29%4 September 2014
CVE-2014-5465Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 13.5%3 September 2014
CVE-2014-1564Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script…EXPLOITMEDIUM 4.3EPSS 5.46%3 September 2014
CVE-2014-5521plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.EXPLOITMEDIUM 6.5EPSS 7.07%2 September 2014
CVE-2014-5119Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment…EXPLOITHIGH 7.5EPSS 17.0%29 August 2014
CVE-2014-5073vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in the fileDate parameter in a DOWN call.EXPLOITHIGH 7.5EPSS 76.3%29 August 2014
CVE-2012-1503Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.EXPLOITMEDIUM 4.3EPSS 2.01%29 August 2014
CVE-2013-5467Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and…EXPLOITHIGH 7.2EPSS 0.84%29 August 2014
CVE-2014-5455Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.EXPLOITMEDIUM 5.3EPSS 0.96%25 August 2014
CVE-2014-5453Ubisoft Uplay PC before 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory (%PROGRAMFILES%\Ubisoft Game Launcher), which allows local users to gain privileges via a Trojan horse file.EXPLOITHIGH 7.2EPSS 1.03%25 August 2014
CVE-2014-5335Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the authentication of administrators for requests that modify configurations or user accounts, as demonstrated by (1)…EXPLOITMEDIUM 6.8EPSS 1.22%25 August 2014
CVE-2014-5368Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Source Control (wp-source-control) plugin 3.0.0 and earlier for WordPress allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 18.8%22 August 2014
CVE-2014-5246The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn.EXPLOITHIGH 10.0EPSS 12.5%22 August 2014
CVE-2014-5097Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) get or (2) set action to rate.php.EXPLOITHIGH 7.5EPSS 2.35%22 August 2014
CVE-2014-5383SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.EXPLOITMEDIUM 6.5EPSS 21.2%21 August 2014
CVE-2014-5210The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.EXPLOITHIGH 10.0EPSS 14.9%21 August 2014
CVE-2014-5350Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) ..EXPLOITMEDIUM 5.0EPSS 63.9%19 August 2014

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.