SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 131 of 501

CVESummaryPriorityPublished
CVE-2013-3082Cross-site scripting (XSS) vulnerability in plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter to forgot-password/.EXPLOITMEDIUM 4.3EPSS 3.23%9 June 2014
CVE-2013-3081SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header to /articles/test/.EXPLOITHIGH 7.5EPSS 2.36%9 June 2014
CVE-2014-3977libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.EXPLOITMEDIUM 6.9EPSS 0.87%8 June 2014
CVE-2014-3153Linux Kernel Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 37.2%7 June 2014
CVE-2014-2575Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a ..EXPLOITMEDIUM 6.5EPSS 8.92%6 June 2014
CVE-2013-4727DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a request to Admin/top.aspx.EXPLOITMEDIUM 5.0EPSS 2.71%6 June 2014
CVE-2013-3739Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 3.68%5 June 2014
CVE-2013-2618Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web script or HTML via the map_title parameter.EXPLOITMEDIUM 4.3EPSS 4.68%5 June 2014
CVE-2014-3976Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long session id in the URI to…EXPLOITMEDIUM 5.0EPSS 11.6%5 June 2014
CVE-2014-3975Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir parameter.EXPLOITMEDIUM 5.0EPSS 6.90%5 June 2014
CVE-2014-3974Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the viewdir parameter.EXPLOITMEDIUM 4.3EPSS 3.22%5 June 2014
CVE-2014-3878Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, possibly before 12.4.1.15, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in an add new contact…EXPLOITMEDIUM 4.3EPSS 3.47%5 June 2014
CVE-2014-3962Multiple SQL injection vulnerabilities in Videos Tube 1.0 allow remote attackers to execute arbitrary SQL commands via the url parameter to (1) videocat.php or (2) single.php.EXPLOITHIGH 7.5EPSS 2.35%4 June 2014
CVE-2014-3961SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.EXPLOITHIGH 7.5EPSS 5.64%4 June 2014
CVE-2014-3913Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrary code via a request for a non-existent file.EXPLOITHIGH 10.0EPSS 60.9%4 June 2014
CVE-2014-2946Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API…EXPLOITMEDIUM 6.8EPSS 1.08%2 June 2014
CVE-2013-7387Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions via the PHPSESSID cookie.EXPLOIT ×2MEDIUM 6.8EPSS 4.96%2 June 2014
CVE-2013-1412DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier.EXPLOIT ×2HIGH 7.5EPSS 40.5%2 June 2014
CVE-2014-3936Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev.EXPLOITHIGH 10.0EPSS 76.6%2 June 2014
CVE-2014-3935SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via the lettre parameter.EXPLOITHIGH 7.5EPSS 2.08%2 June 2014
CVE-2014-3934SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topics[] parameter to modules.php.EXPLOITHIGH 7.5EPSS 2.18%2 June 2014
CVE-2014-3865Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directories via a source package with a crafted Index: pseudo-header in conjunction with (1) missing --- and +++…EXPLOITMEDIUM 6.4EPSS 7.32%30 May 2014
CVE-2012-5877Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an HTTP header without a name.EXPLOITMEDIUM 5.0EPSS 7.48%30 May 2014
CVE-2012-5876Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to cause a denial of service (crash) via a long string in the (1) request line or (2) HTTP Referer header to TCP port 54444, which…EXPLOITMEDIUM 5.0EPSS 4.29%30 May 2014
CVE-2014-3415SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL commands via the invite_users[] parameter to the /invite page for a group.EXPLOITMEDIUM 6.5EPSS 1.95%29 May 2014
CVE-2014-3414Cross-site request forgery (CSRF) vulnerability in Sharetronix before 3.4 allows remote attackers to hijack the authentication of administrators for requests that add administrative privileges to a user via the admin parameter to admin/administrators.EXPLOITMEDIUM 6.8EPSS 1.93%29 May 2014
CVE-2012-4915Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 50.0%29 May 2014
CVE-2013-5036The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function or (2) sourcemap parameter to the sourcemap function in app/controllers/api/v1_controller.rb.EXPLOITHIGH 7.5EPSS 46.2%27 May 2014
CVE-2013-2225inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields parameter to front/ticket.form.php.EXPLOITMEDIUM 6.4EPSS 7.56%27 May 2014
CVE-2014-3871Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via the (1) c[password] or (2) c[username] parameter.EXPLOITHIGH 7.5EPSS 2.56%27 May 2014
CVE-2014-3840Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.13 allow remote authenticated users to inject arbitrary web script or HTML via a (1) tag or the (2) title of a source in a Staging…EXPLOITLOW 3.5EPSS 3.50%27 May 2014
CVE-2014-3866Multiple cross-site request forgery (CSRF) vulnerabilities in user_settings.php in Usercake 2.0.2 and earlier allow remote attackers to hijack the authentication of administrators for requests that change the (1) administrative password via the…EXPLOITMEDIUM 6.8EPSS 1.06%26 May 2014
CVE-2014-3849The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser…EXPLOITMEDIUM 4.3EPSS 5.97%23 May 2014
CVE-2014-3848The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter.EXPLOITMEDIUM 5.0EPSS 9.15%23 May 2014
CVE-2014-3442Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malformed .FLV file, related to f263.w5s.EXPLOITMEDIUM 4.3EPSS 2.79%23 May 2014
CVE-2013-2713Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request.EXPLOITMEDIUM 6.8EPSS 1.44%23 May 2014
CVE-2013-2712Cross-site scripting (XSS) vulnerability in services/get_article.php in KrisonAV CMS before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the content parameter.EXPLOITMEDIUM 4.3EPSS 1.83%23 May 2014
CVE-2013-1668The uploadFile function in upload/index.php in CosCMS before 1.822 allows remote administrators to execute arbitrary commands via shell metacharacters in the name of an uploaded file.EXPLOITHIGH 8.5EPSS 6.98%23 May 2014
CVE-2013-2107Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change the "List of alternative recipients" via the…EXPLOITMEDIUM 6.8EPSS 3.21%23 May 2014
CVE-2010-5299Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl file.EXPLOIT ×3MEDIUM 6.8EPSS 33.6%23 May 2014
CVE-2014-3789GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspecified vectors.EXPLOITHIGH 7.5EPSS 63.4%22 May 2014
CVE-2012-0943debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp.EXPLOITLOW 2.1EPSS 0.76%22 May 2014
CVE-2014-3842Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) decrypt or (2) encrypt parameter.EXPLOITMEDIUM 4.3EPSS 4.51%22 May 2014
CVE-2014-3210SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to…EXPLOITMEDIUM 6.5EPSS 3.59%22 May 2014
CVE-2014-1770Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the…EXPLOITHIGH 9.3EPSS 34.7%22 May 2014
CVE-2014-3806Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 7.65%21 May 2014
CVE-2014-3792Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the…EXPLOITMEDIUM 6.8EPSS 2.28%20 May 2014
CVE-2014-3791Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie UserID parameter to vfolder.ghp.EXPLOITHIGH 10.0EPSS 78.7%20 May 2014
CVE-2014-3749SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the email parameter to autenticar/lembrarlogin.asp.EXPLOITHIGH 7.5EPSS 1.31%20 May 2014
CVE-2014-3738Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the title of a device.EXPLOITMEDIUM 4.3EPSS 3.73%20 May 2014

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.