SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 127 of 501

CVESummaryPriorityPublished
CVE-2014-5349Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print JavaScript function.EXPLOITMEDIUM 5.0EPSS 3.78%19 August 2014
CVE-2014-5347Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks…EXPLOITMEDIUM 6.8EPSS 4.89%19 August 2014
CVE-2014-5346Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) activate or (2) deactivate the plugin via the…EXPLOITMEDIUM 6.8EPSS 2.66%19 August 2014
CVE-2014-5345Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.EXPLOITMEDIUM 4.3EPSS 6.09%19 August 2014
CVE-2014-5207fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows local users to gain privileges, interfere with backups…EXPLOITMEDIUM 6.2EPSS 0.88%18 August 2014
CVE-2014-1470Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —18 August 2014
CVE-2014-5074Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device restart and STOP transition) via crafted TCP packets.EXPLOITHIGH 7.1EPSS 9.70%17 August 2014
CVE-2014-3085systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter.EXPLOITHIGH 7.1EPSS 7.65%17 August 2014
CVE-2014-3081prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.EXPLOITMEDIUM 6.3EPSS 4.13%17 August 2014
CVE-2014-3080Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to kvm.cgi or (2) the…EXPLOITMEDIUM 4.3EPSS 3.52%17 August 2014
CVE-2012-5685SQL injection vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the inEmailAddress parameter in an UpdateClient action in the manage_clients module to the default URI.EXPLOITHIGH 7.5EPSS 2.33%14 August 2014
CVE-2012-5684Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the inFullname parameter in an UpdateAccountSettings action in the my_account module to zpanel/.EXPLOITMEDIUM 4.3EPSS 3.22%14 August 2014
CVE-2012-5683Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create new FTP users via a CreateFTP action in the ftp_management module…EXPLOITMEDIUM 6.8EPSS 1.13%14 August 2014
CVE-2014-1222Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authenticated users to read arbitrary files via a ..EXPLOIT ×3MEDIUM 4.0EPSS 8.79%12 August 2014
CVE-2014-5201SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid parameter in a go_view_object action to wp-admin/admin-ajax.php.EXPLOITHIGH 7.5EPSS 4.59%12 August 2014
CVE-2014-5200SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 4.36%12 August 2014
CVE-2011-2944SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOITHIGH 7.5EPSS 2.68%12 August 2014
CVE-2014-2630Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors.EXPLOITMEDIUM 4.4EPSS 7.08%12 August 2014
CVE-2014-5194Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/conf.php via the _word_upper_bound parameter.EXPLOITMEDIUM 6.5EPSS 4.21%7 August 2014
CVE-2014-5193Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the category parameter.EXPLOITMEDIUM 4.3EPSS 1.83%7 August 2014
CVE-2014-5192SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter parameter.EXPLOITHIGH 7.5EPSS 1.24%7 August 2014
CVE-2014-5189SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 4.59%7 August 2014
CVE-2014-3914Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to (1) create arbitrary files via a ..EXPLOITHIGH 10.0EPSS 72.6%7 August 2014
CVE-2014-3854Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the title parameter.EXPLOITMEDIUM 6.8EPSS 0.94%7 August 2014
CVE-2014-5180SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the edit action to…EXPLOITMEDIUM 6.5EPSS 2.31%6 August 2014
CVE-2014-3434Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition before SEP 12.1, allows local users to execute arbitrary code via a long argument to a 0x00222084 IOCTL…EXPLOITMEDIUM 6.9EPSS 1.63%6 August 2014
CVE-2012-6653Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors.EXPLOITHIGH 7.5EPSS 6.50%6 August 2014
CVE-2014-5090admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel.EXPLOITMEDIUM 6.5EPSS 2.80%6 August 2014
CVE-2014-5089SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter.EXPLOITHIGH 7.5EPSS 1.23%6 August 2014
CVE-2014-5088Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php.EXPLOITMEDIUM 4.3EPSS 1.50%6 August 2014
CVE-2014-5082Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execute arbitrary SQL commands via the (1) site_id or (2) url parameter.EXPLOIT ×2HIGH 7.5EPSS 2.10%6 August 2014
CVE-2013-5759Reason: This candidate is not an independent vulnerability; it is resultant from CVE-2013-5758.EXPLOIT ×2UnscoredEPSS —3 August 2014
CVE-2013-5758cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running unauthorized services, changing directory permissions,…EXPLOIT ×2HIGH 9.0EPSS 11.9%3 August 2014
CVE-2013-5757Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function in the command parameter to cgi-bin/cgiServer.exx.EXPLOITMEDIUM 4.0EPSS 2.75%3 August 2014
CVE-2013-5756Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a ..EXPLOITMEDIUM 4.0EPSS 3.06%3 August 2014
CVE-2014-5116The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a large string.EXPLOITMEDIUM 5.0EPSS 7.58%29 July 2014
CVE-2014-5115Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname in the phpfile parameter to index.php.EXPLOITMEDIUM 5.0EPSS 6.26%29 July 2014
CVE-2014-4710Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the Full Name field.EXPLOITMEDIUM 4.3EPSS 3.22%29 July 2014
CVE-2014-3544Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the…EXPLOITLOW 3.5EPSS 4.67%29 July 2014
CVE-2014-3120Elasticsearch Remote Code Execution VulnerabilityKEVEXPLOIT ×2HIGH 8.1EPSS 88.6%28 July 2014
CVE-2014-5112maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.EXPLOITHIGH 7.5EPSS 9.16%28 July 2014
CVE-2014-5111Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a ..EXPLOIT ×4MEDIUM 5.0EPSS 21.6%28 July 2014
CVE-2014-5109SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL commands via the mac parameter in a Submit action.EXPLOITHIGH 7.5EPSS 3.41%28 July 2014
CVE-2014-5104Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) a_country parameter in a process action to affiliate_signup.php, (2) affiliate_banner_id parameter to…EXPLOIT ×4HIGH 7.5EPSS 2.14%28 July 2014
CVE-2014-4725The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in…EXPLOITHIGH 7.5EPSS 59.9%27 July 2014
CVE-2014-4971Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the…EXPLOIT ×4HIGH 7.2EPSS 23.0%26 July 2014
CVE-2014-5101Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6) TPL_city, (7) TPL_prov, (8) TPL_zip,…EXPLOITMEDIUM 4.3EPSS 2.50%25 July 2014
CVE-2014-5100Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) add a new super user account via a request to admin/users/add, (2) insert…EXPLOITMEDIUM 6.8EPSS 2.47%25 July 2014
CVE-2014-2227The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin…EXPLOITMEDIUM 6.0EPSS 2.17%25 July 2014
CVE-2014-4927Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.EXPLOITHIGH 7.8EPSS 11.2%24 July 2014

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.