Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 126 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-6277 | GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer… | EXPLOIT ×3 ✓HIGH 10.0EPSS 69.8% | 27 September 2014 |
| CVE-2014-6446 | The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php. | EXPLOIT ✓HIGH 7.5EPSS 46.2% | 26 September 2014 |
| CVE-2014-3659 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×14 ✓UnscoredEPSS — | 25 September 2014 |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | KEVEXPLOIT ×15 ✓CRITICAL 9.8EPSS 99.9% | 25 September 2014 |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | KEVEXPLOIT ×21 ✓CRITICAL 9.8EPSS 100.0% | 24 September 2014 |
| CVE-2012-5700 | Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/index.php or the (2) username or (3) password parameter in… | EXPLOIT ✓MEDIUM 4.3EPSS 1.81% | 22 September 2014 |
| CVE-2014-7153 | SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to… | EXPLOITMEDIUM 6.5EPSS 2.29% | 22 September 2014 |
| CVE-2012-2588 | Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message. | EXPLOIT ✓MEDIUM 4.3EPSS 2.39% | 19 September 2014 |
| CVE-2014-4404 | Apple OS X Heap-Based Buffer Overflow Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 48.9% | 18 September 2014 |
| CVE-2012-6658 | Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName configuration in snmpd.conf. | EXPLOIT ✓MEDIUM 4.3EPSS 2.02% | 17 September 2014 |
| CVE-2012-2956 | SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. | EXPLOIT ✓MEDIUM 6.5EPSS 1.10% | 17 September 2014 |
| CVE-2012-2583 | Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email. | EXPLOIT ✓MEDIUM 4.3EPSS 3.73% | 17 September 2014 |
| CVE-2012-1507 | Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltResumeHsp.php, (2) sortOrder1 parameter to… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 2.35% | 17 September 2014 |
| CVE-2012-1506 | SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. | EXPLOIT ✓MEDIUM 6.5EPSS 1.30% | 17 September 2014 |
| CVE-2012-1417 | Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com. | EXPLOITLOW 3.5EPSS 1.73% | 17 September 2014 |
| CVE-2014-2009 | The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log. | EXPLOITMEDIUM 5.0EPSS 7.41% | 12 September 2014 |
| CVE-2014-2008 | SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to execute arbitrary SQL commands via the TID parameter. | EXPLOITHIGH 7.5EPSS 2.64% | 12 September 2014 |
| CVE-2012-1556 | Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php. | EXPLOIT ✓MEDIUM 4.3EPSS 3.26% | 12 September 2014 |
| CVE-2014-3740 | Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket request to the portal page. | EXPLOIT ✓LOW 3.5EPSS 3.38% | 11 September 2014 |
| CVE-2014-6043 | ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. | EXPLOITMEDIUM 6.5EPSS 12.8% | 11 September 2014 |
| CVE-2014-5460 | Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in… | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 70.9% | 11 September 2014 |
| CVE-2014-6235 | Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary code via unknown vectors. | EXPLOITHIGH 7.5EPSS 5.57% | 11 September 2014 |
| CVE-2014-6070 | Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML via the hostname in (1) index.php or (2) detail.php. | EXPLOITMEDIUM 4.3EPSS 3.58% | 11 September 2014 |
| CVE-2014-5519 | The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. | EXPLOITHIGH 7.5EPSS 65.0% | 11 September 2014 |
| CVE-2014-2223 | Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file and a non-zero length PNG file, then… | EXPLOITHIGH 7.5EPSS 10.0% | 11 September 2014 |
| CVE-2012-4240 | SQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter. | EXPLOITMEDIUM 6.5EPSS 1.25% | 11 September 2014 |
| CVE-2012-0984 | Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to_userid parameter to modules/pm/pmlite.php or the (2) current_file, (3) imgcat_id, or (4) target… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 4.16% | 11 September 2014 |
| CVE-2014-2624 | Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2264. | EXPLOIT ✓HIGH 10.0EPSS 65.4% | 11 September 2014 |
| CVE-2014-4865 | Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attackers to hijack the authentication of arbitrary users. | EXPLOITMEDIUM 6.8EPSS 1.24% | 10 September 2014 |
| CVE-2014-0556 | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK… | EXPLOIT ✓HIGH 10.0EPSS 84.3% | 10 September 2014 |
| CVE-2014-5464 | Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header. | EXPLOITMEDIUM 4.3EPSS 4.45% | 8 September 2014 |
| CVE-2014-5377 | ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request. | EXPLOITMEDIUM 5.0EPSS 57.5% | 4 September 2014 |
| CVE-2012-4768 | Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI. | EXPLOIT ✓MEDIUM 4.3EPSS 10.5% | 4 September 2014 |
| CVE-2012-4234 | Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via the group parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.29% | 4 September 2014 |
| CVE-2014-5465 | Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 13.5% | 3 September 2014 |
| CVE-2014-1564 | Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script… | EXPLOIT ✓MEDIUM 4.3EPSS 5.46% | 3 September 2014 |
| CVE-2014-5521 | plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter. | EXPLOITMEDIUM 6.5EPSS 7.07% | 2 September 2014 |
| CVE-2014-5119 | Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment… | EXPLOIT ✓HIGH 7.5EPSS 17.0% | 29 August 2014 |
| CVE-2014-5073 | vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in the fileDate parameter in a DOWN call. | EXPLOITHIGH 7.5EPSS 76.3% | 29 August 2014 |
| CVE-2012-1503 | Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section. | EXPLOITMEDIUM 4.3EPSS 2.01% | 29 August 2014 |
| CVE-2013-5467 | Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and… | EXPLOITHIGH 7.2EPSS 0.84% | 29 August 2014 |
| CVE-2014-5455 | Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder. | EXPLOITMEDIUM 5.3EPSS 0.96% | 25 August 2014 |
| CVE-2014-5453 | Ubisoft Uplay PC before 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory (%PROGRAMFILES%\Ubisoft Game Launcher), which allows local users to gain privileges via a Trojan horse file. | EXPLOIT ✓HIGH 7.2EPSS 1.03% | 25 August 2014 |
| CVE-2014-5335 | Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the authentication of administrators for requests that modify configurations or user accounts, as demonstrated by (1)… | EXPLOITMEDIUM 6.8EPSS 1.22% | 25 August 2014 |
| CVE-2014-5368 | Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Source Control (wp-source-control) plugin 3.0.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 18.8% | 22 August 2014 |
| CVE-2014-5246 | The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn. | EXPLOITHIGH 10.0EPSS 12.5% | 22 August 2014 |
| CVE-2014-5097 | Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) get or (2) set action to rate.php. | EXPLOIT ✓HIGH 7.5EPSS 2.35% | 22 August 2014 |
| CVE-2014-5383 | SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | EXPLOITMEDIUM 6.5EPSS 21.2% | 21 August 2014 |
| CVE-2014-5210 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805. | EXPLOITHIGH 10.0EPSS 14.9% | 21 August 2014 |
| CVE-2014-5350 | Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) .. | EXPLOITMEDIUM 5.0EPSS 63.9% | 19 August 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.