Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 128 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-4736 | SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process. | EXPLOIT ✓HIGH 7.5EPSS 2.35% | 24 July 2014 |
| CVE-2014-3110 | Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via… | EXPLOITMEDIUM 4.3EPSS 5.34% | 24 July 2014 |
| CVE-2014-5023 | Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command. | EXPLOIT ✓MEDIUM 6.8EPSS 3.36% | 22 July 2014 |
| CVE-2014-4511 | Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and… | EXPLOIT ×2 ✓HIGH 7.5EPSS 82.7% | 22 July 2014 |
| CVE-2013-7392 | Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/. | EXPLOIT ×2 ✓HIGH 7.5EPSS 8.48% | 22 July 2014 |
| CVE-2014-4960 | Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid… | EXPLOIT ✓HIGH 7.5EPSS 2.35% | 21 July 2014 |
| CVE-2014-0226 | Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a… | EXPLOITMEDIUM 6.8EPSS 85.7% | 20 July 2014 |
| CVE-2014-4943 | The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket. | EXPLOIT ×2 ✓MEDIUM 6.9EPSS 2.10% | 19 July 2014 |
| CVE-2014-2364 | Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7)… | EXPLOIT ✓HIGH 7.5EPSS 61.4% | 19 July 2014 |
| CVE-2014-2623 | Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors. | EXPLOIT ×3 ✓HIGH 10.0EPSS 89.4% | 18 July 2014 |
| CVE-2014-2477 | Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 allows local users to affect integrity and availability via unknown vectors related to Core, a… | EXPLOIT ✓LOW 3.6EPSS 7.20% | 17 July 2014 |
| CVE-2014-4977 | Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) selectedUserGroup parameter in a create new user request to cgi-bin/admin.cgi or the (2) user_id… | EXPLOIT ✓MEDIUM 6.5EPSS 74.9% | 16 July 2014 |
| CVE-2014-4154 | ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the PPPoE/PPPoA password via a direct request for basic/tc2wanfun.js. | EXPLOITMEDIUM 5.0EPSS 6.57% | 16 July 2014 |
| CVE-2014-4018 | The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via unspecified vectors. | EXPLOITHIGH 7.8EPSS 6.30% | 16 July 2014 |
| CVE-2014-3427 | CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet. | EXPLOIT ✓MEDIUM 5.0EPSS 5.20% | 16 July 2014 |
| CVE-2013-5755 | config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) var (jhl3iZAe./qXM) for the var account, which makes it easier for remote… | EXPLOITHIGH 10.0EPSS 4.34% | 16 July 2014 |
| CVE-2014-4965 | Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) customername parameter to central/orders/searchcriteria.action; (2) productname, (3)… | EXPLOITMEDIUM 4.3EPSS 3.25% | 15 July 2014 |
| CVE-2014-4964 | Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication of users for requests that (1) modify customer settings or hijack the authentication of administrators for… | EXPLOITMEDIUM 6.8EPSS 2.30% | 15 July 2014 |
| CVE-2014-4963 | Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action. | EXPLOITMEDIUM 6.8EPSS 3.74% | 15 July 2014 |
| CVE-2014-4962 | Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be subtracted from the total cost. | EXPLOITMEDIUM 6.4EPSS 4.71% | 15 July 2014 |
| CVE-2014-4663 | TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the src parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 9.75% | 15 July 2014 |
| CVE-2014-3418 | config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipjackUsername parameter. | EXPLOITHIGH 10.0EPSS 7.17% | 15 July 2014 |
| CVE-2014-4944 | Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) categoryid or (2) pdfid parameter to wp-admin/admin.php. | EXPLOIT ✓MEDIUM 6.5EPSS 3.55% | 14 July 2014 |
| CVE-2014-4940 | Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 19.3% | 11 July 2014 |
| CVE-2014-4939 | SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the enl-add-new page to wp-admin/admin.php. | EXPLOIT ✓MEDIUM 6.5EPSS 2.29% | 11 July 2014 |
| CVE-2014-4938 | SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in the wrp-add-new page to wp-admin/admin.php. | EXPLOIT ✓HIGH 7.5EPSS 2.94% | 11 July 2014 |
| CVE-2014-4937 | Directory traversal vulnerability in includes/bookx_export.php BookX plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 8.86% | 11 July 2014 |
| CVE-2013-6117 | Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777. | EXPLOITHIGH 7.5EPSS 69.7% | 11 July 2014 |
| CVE-2014-3992 | Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) entity parameter in an update action to user/fiche.php or (2) sortorder parameter to user/group/index.php. | EXPLOIT ✓MEDIUM 6.5EPSS 1.99% | 11 July 2014 |
| CVE-2014-3991 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) dol_use_jmobile, (2) dol_optimize_smallscreen, (3) dol_no_mouse_hover, (4) dol_hide_topmenu, (5)… | EXPLOIT ✓MEDIUM 4.3EPSS 2.69% | 11 July 2014 |
| CVE-2014-4852 | SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.24% | 10 July 2014 |
| CVE-2014-3888 | Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when… | EXPLOITHIGH 8.3EPSS 62.3% | 10 July 2014 |
| CVE-2014-4741 | SQL injection vulnerability in demo/ads.php in Artifectx xClassified 1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.08% | 9 July 2014 |
| CVE-2014-4194 | SQL injection vulnerability in zero_transact_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter in a Submit Comment action. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 9 July 2014 |
| CVE-2012-4988 | Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file. | EXPLOITHIGH 9.3EPSS 9.85% | 9 July 2014 |
| CVE-2014-4699 | The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain… | EXPLOITMEDIUM 6.9EPSS 2.32% | 9 July 2014 |
| CVE-2014-1767 | Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server… | EXPLOIT ×2HIGH 7.2EPSS 12.7% | 8 July 2014 |
| CVE-2013-7389 | Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. | EXPLOITMEDIUM 4.3EPSS 27.8% | 7 July 2014 |
| CVE-2014-0894 | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers to discover database credentials by reading the DbUser and DbPass fields in an XML document. | EXPLOITLOW 3.5EPSS 4.00% | 7 July 2014 |
| CVE-2014-0871 | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to obtain potentially sensitive Tomcat stack-trace information via non-printing characters in a cookie to the /classes/ URI,… | EXPLOITMEDIUM 4.3EPSS 5.69% | 7 July 2014 |
| CVE-2014-0870 | Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to inject arbitrary web script or HTML via (1) the Message parameter to… | EXPLOITMEDIUM 4.3EPSS 3.65% | 7 July 2014 |
| CVE-2014-0869 | The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and… | EXPLOITMEDIUM 4.3EPSS 5.49% | 7 July 2014 |
| CVE-2014-0868 | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via a… | EXPLOITMEDIUM 4.9EPSS 4.27% | 7 July 2014 |
| CVE-2014-0867 | rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to create or modify cookies via the query string. | EXPLOITMEDIUM 5.8EPSS 5.07% | 7 July 2014 |
| CVE-2014-0866 | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network. | EXPLOITMEDIUM 4.3EPSS 5.49% | 7 July 2014 |
| CVE-2014-0865 | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via… | EXPLOITMEDIUM 4.9EPSS 4.98% | 7 July 2014 |
| CVE-2014-0864 | Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to hijack the authentication of arbitrary users for… | EXPLOITMEDIUM 6.8EPSS 2.52% | 7 July 2014 |
| CVE-2014-4718 | Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack the authentication of administrators for requests that (1) add Super users via a request to admin/user_create.php or conduct cross-site… | EXPLOIT ✓MEDIUM 6.8EPSS 2.31% | 3 July 2014 |
| CVE-2014-4717 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS)… | EXPLOITMEDIUM 6.8EPSS 2.80% | 3 July 2014 |
| CVE-2014-4716 | Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authentication of unspecified victims for requests that change passwords via the Password and PasswordReEnter parameters to goform/RgSecurity. | EXPLOITMEDIUM 6.8EPSS 2.28% | 3 July 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.