SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 129 of 501

CVESummaryPriorityPublished
CVE-2014-3857Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) x_16 or (2) x_17 parameter to print.php.EXPLOITMEDIUM 6.5EPSS 2.17%3 July 2014
CVE-2014-4688pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_dns.php in a Create Alias action, (2) the smartmonemail value to diag_smart.php, or (3) the database value to status_rrd_graph_img.php.EXPLOITMEDIUM 6.5EPSS 6.97%2 July 2014
CVE-2014-2612Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to obtain sensitive information via unknown vectors.EXPLOITMEDIUM 4.0EPSS 6.84%28 June 2014
CVE-2014-4645Cross-site scripting (XSS) vulnerability in dhcpinfo.html in D-link DSL-2760U-E1 allows remote attackers to inject arbitrary web script or HTML via a hostname.EXPLOITMEDIUM 4.3EPSS 1.50%25 June 2014
CVE-2014-4644SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2HIGH 7.5EPSS 1.32%25 June 2014
CVE-2014-4643Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in a reply to a (1) USER, (2) PASS, (3)…EXPLOITMEDIUM 5.0EPSS 8.76%25 June 2014
CVE-2014-4030Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that remove players via a delete action to wp-admin/admin.php.EXPLOITMEDIUM 6.8EPSS 2.86%25 June 2014
CVE-2014-4014The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated…EXPLOITMEDIUM 6.2EPSS 3.30%23 June 2014
CVE-2014-1739The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0…EXPLOITLOW 2.1EPSS 1.12%23 June 2014
CVE-2012-5106Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via a long string in a PUT command.EXPLOITHIGH 10.0EPSS 14.1%20 June 2014
CVE-2014-0007The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.EXPLOITHIGH 7.5EPSS 9.02%20 June 2014
CVE-2012-2591Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) From or (2) Date field in an email.EXPLOITMEDIUM 4.3EPSS 2.01%20 June 2014
CVE-2012-2580Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email.EXPLOITMEDIUM 4.3EPSS 3.73%20 June 2014
CVE-2012-2579Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) To, (2) From, (3) Date, or (4) Subject field of an email.EXPLOITMEDIUM 4.3EPSS 3.73%20 June 2014
CVE-2012-2052Stack-based buffer overflow in the U3D.8BI library plugin in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via a long Collada asset element in a DAE file, as demonstrated by the…EXPLOITHIGH 9.3EPSS 23.3%19 June 2014
CVE-2014-4334Stack-based buffer overflow in Ubisoft Rayman Legends before 1.3.140380 allows remote attackers to execute arbitrary code via a long string in the "second connection" to TCP port 1001.EXPLOITHIGH 7.5EPSS 15.2%19 June 2014
CVE-2014-4155Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to…EXPLOITMEDIUM 6.8EPSS 2.27%19 June 2014
CVE-2014-3778Multiple cross-site request forgery (CSRF) vulnerabilities in goform/RgDdns in ARRIS (formerly Motorola) SBG901 SURFboard Wireless Cable Modem allow remote attackers to hijack the authentication of administrators for requests that (1) change the dns…EXPLOITMEDIUM 6.8EPSS 1.94%19 June 2014
CVE-2012-2572Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Subject of an email.EXPLOITMEDIUM 4.3EPSS 4.10%19 June 2014
CVE-2012-2569Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote attackers to inject arbitrary web script or HTML via the body of an email.EXPLOITMEDIUM 4.3EPSS 1.82%19 June 2014
CVE-2011-4367Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 33.5%19 June 2014
CVE-2014-2962Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.EXPLOITHIGH 7.8EPSS 47.1%19 June 2014
CVE-2014-2782Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 22.3%19 June 2014
CVE-2014-4153The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.EXPLOITHIGH 7.8EPSS 7.38%18 June 2014
CVE-2012-2592Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email.EXPLOITMEDIUM 4.3EPSS 1.82%18 June 2014
CVE-2014-0910Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, and 7.0.0 through 7.0.0.2 CF28 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.EXPLOITLOW 3.5EPSS 2.66%18 June 2014
CVE-2013-6221Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled, allows remote attackers to create arbitrary files and consequently execute arbitrary code via…EXPLOITHIGH 10.0EPSS 77.9%18 June 2014
CVE-2014-4307SQL injection vulnerability in categories-x.php in WebTitan before 4.04 allows remote attackers to execute arbitrary SQL commands via the sortkey parameter.EXPLOITHIGH 7.5EPSS 2.24%18 June 2014
CVE-2014-4306Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 7.62%18 June 2014
CVE-2014-4166Cross-site scripting (XSS) vulnerability in the song history in SHOUTcast DNAS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the mp3 title field.EXPLOITMEDIUM 4.3EPSS 3.22%16 June 2014
CVE-2014-4163Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that change the (1) buried or (2) featured status of a…EXPLOITMEDIUM 6.8EPSS 2.56%16 June 2014
CVE-2014-4162Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change the (1) wifi password or (2) SSID via a request to…EXPLOITMEDIUM 6.8EPSS 2.63%16 June 2014
CVE-2014-4158Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET request.EXPLOIT ×2HIGH 7.5EPSS 14.3%13 June 2014
CVE-2014-3805The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a different vulnerability than CVE-2014-3804.EXPLOIT ×2HIGH 10.0EPSS 13.1%13 June 2014
CVE-2014-3804The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_info_debian_package, (2) ossec_task, (3) set_ossim_setup admin_ip, (4) sync_rserver, or (5)…EXPLOIT ×2HIGH 10.0EPSS 72.4%13 June 2014
CVE-2014-2303Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to execute arbitrary SQL commands via the (1) table or (2) order parameter.EXPLOITHIGH 7.5EPSS 2.57%13 June 2014
CVE-2013-2182The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as demonstrated by an encoded forward slash.EXPLOITMEDIUM 5.8EPSS 5.59%13 June 2014
CVE-2010-5301Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a HEAD request.EXPLOITHIGH 7.5EPSS 10.6%13 June 2014
CVE-2014-4035Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc.EXPLOITMEDIUM 4.3EPSS 3.28%11 June 2014
CVE-2014-4034SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter.EXPLOITHIGH 7.5EPSS 6.25%11 June 2014
CVE-2014-4033Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arbitrary web script or HTML via the surname parameter to student.php.EXPLOITMEDIUM 4.3EPSS 3.30%11 June 2014
CVE-2014-3004The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.EXPLOITMEDIUM 4.3EPSS 7.86%11 June 2014
CVE-2011-3625Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a SAMI subtitle…EXPLOITHIGH 9.3EPSS 24.1%11 June 2014
CVE-2010-5300Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name in a zip archive.EXPLOIT ×2MEDIUM 6.8EPSS 14.6%11 June 2014
CVE-2014-2777Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-1778.EXPLOITHIGH 7.5EPSS 23.0%11 June 2014
CVE-2014-2776Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 21.6%11 June 2014
CVE-2014-2775Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 20.0%11 June 2014
CVE-2014-2773Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 20.5%11 June 2014
CVE-2014-2772Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 20.5%11 June 2014
CVE-2014-2771Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 20.5%11 June 2014

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.