Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 127 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-5349 | Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print JavaScript function. | EXPLOITMEDIUM 5.0EPSS 3.78% | 19 August 2014 |
| CVE-2014-5347 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks… | EXPLOITMEDIUM 6.8EPSS 4.89% | 19 August 2014 |
| CVE-2014-5346 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) activate or (2) deactivate the plugin via the… | EXPLOITMEDIUM 6.8EPSS 2.66% | 19 August 2014 |
| CVE-2014-5345 | Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter. | EXPLOITMEDIUM 4.3EPSS 6.09% | 19 August 2014 |
| CVE-2014-5207 | fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows local users to gain privileges, interfere with backups… | EXPLOITMEDIUM 6.2EPSS 0.88% | 18 August 2014 |
| CVE-2014-1470 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 18 August 2014 |
| CVE-2014-5074 | Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device restart and STOP transition) via crafted TCP packets. | EXPLOITHIGH 7.1EPSS 9.70% | 17 August 2014 |
| CVE-2014-3085 | systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter. | EXPLOIT ✓HIGH 7.1EPSS 7.65% | 17 August 2014 |
| CVE-2014-3081 | prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter. | EXPLOIT ✓MEDIUM 6.3EPSS 4.13% | 17 August 2014 |
| CVE-2014-3080 | Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to kvm.cgi or (2) the… | EXPLOIT ✓MEDIUM 4.3EPSS 3.52% | 17 August 2014 |
| CVE-2012-5685 | SQL injection vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the inEmailAddress parameter in an UpdateClient action in the manage_clients module to the default URI. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 14 August 2014 |
| CVE-2012-5684 | Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the inFullname parameter in an UpdateAccountSettings action in the my_account module to zpanel/. | EXPLOIT ✓MEDIUM 4.3EPSS 3.22% | 14 August 2014 |
| CVE-2012-5683 | Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create new FTP users via a CreateFTP action in the ftp_management module… | EXPLOIT ✓MEDIUM 6.8EPSS 1.13% | 14 August 2014 |
| CVE-2014-1222 | Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authenticated users to read arbitrary files via a .. | EXPLOIT ×3 ✓MEDIUM 4.0EPSS 8.79% | 12 August 2014 |
| CVE-2014-5201 | SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid parameter in a go_view_object action to wp-admin/admin-ajax.php. | EXPLOITHIGH 7.5EPSS 4.59% | 12 August 2014 |
| CVE-2014-5200 | SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.36% | 12 August 2014 |
| CVE-2011-2944 | SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOITHIGH 7.5EPSS 2.68% | 12 August 2014 |
| CVE-2014-2630 | Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors. | EXPLOITMEDIUM 4.4EPSS 7.08% | 12 August 2014 |
| CVE-2014-5194 | Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/conf.php via the _word_upper_bound parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 4.21% | 7 August 2014 |
| CVE-2014-5193 | Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the category parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.83% | 7 August 2014 |
| CVE-2014-5192 | SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 7 August 2014 |
| CVE-2014-5189 | SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.59% | 7 August 2014 |
| CVE-2014-3914 | Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to (1) create arbitrary files via a .. | EXPLOIT ✓HIGH 10.0EPSS 72.6% | 7 August 2014 |
| CVE-2014-3854 | Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the title parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 7 August 2014 |
| CVE-2014-5180 | SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the edit action to… | EXPLOIT ✓MEDIUM 6.5EPSS 2.31% | 6 August 2014 |
| CVE-2014-3434 | Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition before SEP 12.1, allows local users to execute arbitrary code via a long argument to a 0x00222084 IOCTL… | EXPLOIT ✓MEDIUM 6.9EPSS 1.63% | 6 August 2014 |
| CVE-2012-6653 | Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors. | EXPLOIT ✓HIGH 7.5EPSS 6.50% | 6 August 2014 |
| CVE-2014-5090 | admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel. | EXPLOITMEDIUM 6.5EPSS 2.80% | 6 August 2014 |
| CVE-2014-5089 | SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter. | EXPLOITHIGH 7.5EPSS 1.23% | 6 August 2014 |
| CVE-2014-5088 | Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php. | EXPLOITMEDIUM 4.3EPSS 1.50% | 6 August 2014 |
| CVE-2014-5082 | Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execute arbitrary SQL commands via the (1) site_id or (2) url parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.10% | 6 August 2014 |
| CVE-2013-5759 | Reason: This candidate is not an independent vulnerability; it is resultant from CVE-2013-5758. | EXPLOIT ×2UnscoredEPSS — | 3 August 2014 |
| CVE-2013-5758 | cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running unauthorized services, changing directory permissions,… | EXPLOIT ×2HIGH 9.0EPSS 11.9% | 3 August 2014 |
| CVE-2013-5757 | Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function in the command parameter to cgi-bin/cgiServer.exx. | EXPLOITMEDIUM 4.0EPSS 2.75% | 3 August 2014 |
| CVE-2013-5756 | Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. | EXPLOITMEDIUM 4.0EPSS 3.06% | 3 August 2014 |
| CVE-2014-5116 | The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a large string. | EXPLOIT ✓MEDIUM 5.0EPSS 7.58% | 29 July 2014 |
| CVE-2014-5115 | Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname in the phpfile parameter to index.php. | EXPLOIT ✓MEDIUM 5.0EPSS 6.26% | 29 July 2014 |
| CVE-2014-4710 | Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the Full Name field. | EXPLOITMEDIUM 4.3EPSS 3.22% | 29 July 2014 |
| CVE-2014-3544 | Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the… | EXPLOITLOW 3.5EPSS 4.67% | 29 July 2014 |
| CVE-2014-3120 | Elasticsearch Remote Code Execution Vulnerability | KEVEXPLOIT ×2 ✓HIGH 8.1EPSS 88.6% | 28 July 2014 |
| CVE-2014-5112 | maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter. | EXPLOIT ✓HIGH 7.5EPSS 9.16% | 28 July 2014 |
| CVE-2014-5111 | Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. | EXPLOIT ×4 ✓MEDIUM 5.0EPSS 21.6% | 28 July 2014 |
| CVE-2014-5109 | SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL commands via the mac parameter in a Submit action. | EXPLOIT ✓HIGH 7.5EPSS 3.41% | 28 July 2014 |
| CVE-2014-5104 | Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) a_country parameter in a process action to affiliate_signup.php, (2) affiliate_banner_id parameter to… | EXPLOIT ×4 ✓HIGH 7.5EPSS 2.14% | 28 July 2014 |
| CVE-2014-4725 | The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in… | EXPLOIT ✓HIGH 7.5EPSS 59.9% | 27 July 2014 |
| CVE-2014-4971 | Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the… | EXPLOIT ×4 ✓HIGH 7.2EPSS 23.0% | 26 July 2014 |
| CVE-2014-5101 | Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6) TPL_city, (7) TPL_prov, (8) TPL_zip,… | EXPLOIT ✓MEDIUM 4.3EPSS 2.50% | 25 July 2014 |
| CVE-2014-5100 | Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) add a new super user account via a request to admin/users/add, (2) insert… | EXPLOIT ✓MEDIUM 6.8EPSS 2.47% | 25 July 2014 |
| CVE-2014-2227 | The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin… | EXPLOIT ✓MEDIUM 6.0EPSS 2.17% | 25 July 2014 |
| CVE-2014-4927 | Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request. | EXPLOITHIGH 7.8EPSS 11.2% | 24 July 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.