Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 131 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-3082 | Cross-site scripting (XSS) vulnerability in plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter to forgot-password/. | EXPLOIT ✓MEDIUM 4.3EPSS 3.23% | 9 June 2014 |
| CVE-2013-3081 | SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header to /articles/test/. | EXPLOIT ✓HIGH 7.5EPSS 2.36% | 9 June 2014 |
| CVE-2014-3977 | libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. | EXPLOIT ✓MEDIUM 6.9EPSS 0.87% | 8 June 2014 |
| CVE-2014-3153 | Linux Kernel Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 37.2% | 7 June 2014 |
| CVE-2014-2575 | Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. | EXPLOITMEDIUM 6.5EPSS 8.92% | 6 June 2014 |
| CVE-2013-4727 | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a request to Admin/top.aspx. | EXPLOIT ✓MEDIUM 5.0EPSS 2.71% | 6 June 2014 |
| CVE-2013-3739 | Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.68% | 5 June 2014 |
| CVE-2013-2618 | Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web script or HTML via the map_title parameter. | EXPLOITMEDIUM 4.3EPSS 4.68% | 5 June 2014 |
| CVE-2014-3976 | Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long session id in the URI to… | EXPLOITMEDIUM 5.0EPSS 11.6% | 5 June 2014 |
| CVE-2014-3975 | Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 6.90% | 5 June 2014 |
| CVE-2014-3974 | Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the viewdir parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.22% | 5 June 2014 |
| CVE-2014-3878 | Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, possibly before 12.4.1.15, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in an add new contact… | EXPLOITMEDIUM 4.3EPSS 3.47% | 5 June 2014 |
| CVE-2014-3962 | Multiple SQL injection vulnerabilities in Videos Tube 1.0 allow remote attackers to execute arbitrary SQL commands via the url parameter to (1) videocat.php or (2) single.php. | EXPLOIT ✓HIGH 7.5EPSS 2.35% | 4 June 2014 |
| CVE-2014-3961 | SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/. | EXPLOITHIGH 7.5EPSS 5.64% | 4 June 2014 |
| CVE-2014-3913 | Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrary code via a request for a non-existent file. | EXPLOIT ✓HIGH 10.0EPSS 60.9% | 4 June 2014 |
| CVE-2014-2946 | Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API… | EXPLOIT ✓MEDIUM 6.8EPSS 1.08% | 2 June 2014 |
| CVE-2013-7387 | Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions via the PHPSESSID cookie. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 4.96% | 2 June 2014 |
| CVE-2013-1412 | DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier. | EXPLOIT ×2 ✓HIGH 7.5EPSS 40.5% | 2 June 2014 |
| CVE-2014-3936 | Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. | EXPLOIT ✓HIGH 10.0EPSS 76.6% | 2 June 2014 |
| CVE-2014-3935 | SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via the lettre parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.08% | 2 June 2014 |
| CVE-2014-3934 | SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topics[] parameter to modules.php. | EXPLOIT ✓HIGH 7.5EPSS 2.18% | 2 June 2014 |
| CVE-2014-3865 | Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directories via a source package with a crafted Index: pseudo-header in conjunction with (1) missing --- and +++… | EXPLOIT ✓MEDIUM 6.4EPSS 7.32% | 30 May 2014 |
| CVE-2012-5877 | Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an HTTP header without a name. | EXPLOITMEDIUM 5.0EPSS 7.48% | 30 May 2014 |
| CVE-2012-5876 | Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to cause a denial of service (crash) via a long string in the (1) request line or (2) HTTP Referer header to TCP port 54444, which… | EXPLOITMEDIUM 5.0EPSS 4.29% | 30 May 2014 |
| CVE-2014-3415 | SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL commands via the invite_users[] parameter to the /invite page for a group. | EXPLOITMEDIUM 6.5EPSS 1.95% | 29 May 2014 |
| CVE-2014-3414 | Cross-site request forgery (CSRF) vulnerability in Sharetronix before 3.4 allows remote attackers to hijack the authentication of administrators for requests that add administrative privileges to a user via the admin parameter to admin/administrators. | EXPLOITMEDIUM 6.8EPSS 1.93% | 29 May 2014 |
| CVE-2012-4915 | Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 50.0% | 29 May 2014 |
| CVE-2013-5036 | The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function or (2) sourcemap parameter to the sourcemap function in app/controllers/api/v1_controller.rb. | EXPLOIT ✓HIGH 7.5EPSS 46.2% | 27 May 2014 |
| CVE-2013-2225 | inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields parameter to front/ticket.form.php. | EXPLOITMEDIUM 6.4EPSS 7.56% | 27 May 2014 |
| CVE-2014-3871 | Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via the (1) c[password] or (2) c[username] parameter. | EXPLOITHIGH 7.5EPSS 2.56% | 27 May 2014 |
| CVE-2014-3840 | Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.13 allow remote authenticated users to inject arbitrary web script or HTML via a (1) tag or the (2) title of a source in a Staging… | EXPLOIT ✓LOW 3.5EPSS 3.50% | 27 May 2014 |
| CVE-2014-3866 | Multiple cross-site request forgery (CSRF) vulnerabilities in user_settings.php in Usercake 2.0.2 and earlier allow remote attackers to hijack the authentication of administrators for requests that change the (1) administrative password via the… | EXPLOIT ✓MEDIUM 6.8EPSS 1.06% | 26 May 2014 |
| CVE-2014-3849 | The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser… | EXPLOITMEDIUM 4.3EPSS 5.97% | 23 May 2014 |
| CVE-2014-3848 | The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter. | EXPLOITMEDIUM 5.0EPSS 9.15% | 23 May 2014 |
| CVE-2014-3442 | Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malformed .FLV file, related to f263.w5s. | EXPLOIT ✓MEDIUM 4.3EPSS 2.79% | 23 May 2014 |
| CVE-2013-2713 | Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request. | EXPLOITMEDIUM 6.8EPSS 1.44% | 23 May 2014 |
| CVE-2013-2712 | Cross-site scripting (XSS) vulnerability in services/get_article.php in KrisonAV CMS before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the content parameter. | EXPLOITMEDIUM 4.3EPSS 1.83% | 23 May 2014 |
| CVE-2013-1668 | The uploadFile function in upload/index.php in CosCMS before 1.822 allows remote administrators to execute arbitrary commands via shell metacharacters in the name of an uploaded file. | EXPLOITHIGH 8.5EPSS 6.98% | 23 May 2014 |
| CVE-2013-2107 | Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change the "List of alternative recipients" via the… | EXPLOIT ✓MEDIUM 6.8EPSS 3.21% | 23 May 2014 |
| CVE-2010-5299 | Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl file. | EXPLOIT ×3 ✓MEDIUM 6.8EPSS 33.6% | 23 May 2014 |
| CVE-2014-3789 | GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 63.4% | 22 May 2014 |
| CVE-2012-0943 | debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp. | EXPLOIT ✓LOW 2.1EPSS 0.76% | 22 May 2014 |
| CVE-2014-3842 | Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) decrypt or (2) encrypt parameter. | EXPLOITMEDIUM 4.3EPSS 4.51% | 22 May 2014 |
| CVE-2014-3210 | SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to… | EXPLOIT ✓MEDIUM 6.5EPSS 3.59% | 22 May 2014 |
| CVE-2014-1770 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the… | EXPLOITHIGH 9.3EPSS 34.7% | 22 May 2014 |
| CVE-2014-3806 | Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 7.65% | 21 May 2014 |
| CVE-2014-3792 | Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the… | EXPLOITMEDIUM 6.8EPSS 2.28% | 20 May 2014 |
| CVE-2014-3791 | Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie UserID parameter to vfolder.ghp. | EXPLOIT ✓HIGH 10.0EPSS 78.7% | 20 May 2014 |
| CVE-2014-3749 | SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the email parameter to autenticar/lembrarlogin.asp. | EXPLOIT ✓HIGH 7.5EPSS 1.31% | 20 May 2014 |
| CVE-2014-3738 | Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the title of a device. | EXPLOITMEDIUM 4.3EPSS 3.73% | 20 May 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.