SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 133 of 501

CVESummaryPriorityPublished
CVE-2014-3008Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to recoveryconsole/bpl/snmpd.php.EXPLOITHIGH 10.0EPSS 7.02%28 April 2014
CVE-2014-2846Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot…EXPLOITHIGH 7.5EPSS 8.83%28 April 2014
CVE-2014-2383dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a…EXPLOITMEDIUM 6.8EPSS 39.2%28 April 2014
CVE-2014-1766Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at…EXPLOITHIGH 9.3EPSS 33.3%27 April 2014
CVE-2014-1764Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging "object confusion" in a broker process, as demonstrated by VUPEN during a Pwn2Own competition at…EXPLOITHIGH 10.0EPSS 37.4%27 April 2014
CVE-2014-1762Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a…EXPLOITHIGH 7.5EPSS 70.7%27 April 2014
CVE-2014-2994Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to execute arbitrary code via an HTML file containing an IMG element with a long URL (src attribute).EXPLOITHIGH 10.0EPSS 26.4%27 April 2014
CVE-2014-2996XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the dbbackup_comp parameter in a generate action to index2.php.EXPLOITHIGH 7.1EPSS 9.92%25 April 2014
CVE-2014-2579Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password via the config task to…EXPLOITHIGH 7.6EPSS 6.04%25 April 2014
CVE-2013-5660Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.EXPLOITHIGH 9.3EPSS 11.2%25 April 2014
CVE-2013-5954Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delete (1) users via admin/agency-user-unlink.php, (2) advertisers via…EXPLOITMEDIUM 6.8EPSS 3.09%25 April 2014
CVE-2014-2908Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.EXPLOITMEDIUM 4.3EPSS 20.9%25 April 2014
CVE-2014-0780InduSoft Web Studio NTWebServer Directory Traversal VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 74.4%25 April 2014
CVE-2014-2976Directory traversal vulnerability in Sixnet SixView Manager 2.4.1 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 3.74%23 April 2014
CVE-2014-1322The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user space, which makes it easier for local users to bypass the ASLR protection mechanism by reading an unspecified attribute of the object.EXPLOITMEDIUM 4.9EPSS 1.08%23 April 2014
CVE-2014-2341Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.EXPLOITMEDIUM 6.8EPSS 5.83%22 April 2014
CVE-2014-1216FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in the pageContent parameter when editing a page.EXPLOITHIGH 7.5EPSS 3.92%22 April 2014
CVE-2013-5948The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the Target field…EXPLOITHIGH 8.5EPSS 9.52%22 April 2014
CVE-2014-2922The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 does not properly handle an object obtained by unserializing a pathname, which allows remote attackers to conduct PHP object injection…EXPLOITMEDIUM 6.4EPSS 2.92%21 April 2014
CVE-2014-2921The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an object obtained by unserializing Lucene search data, which allows remote attackers to conduct PHP object…EXPLOITHIGH 7.5EPSS 7.32%21 April 2014
CVE-2014-1990Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change…EXPLOITMEDIUM 6.8EPSS 1.15%19 April 2014
CVE-2013-7196static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication.EXPLOITMEDIUM 5.5EPSS 2.44%18 April 2014
CVE-2014-2880Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the…EXPLOITMEDIUM 5.8EPSS 8.49%17 April 2014
CVE-2014-2879Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page…EXPLOITMEDIUM 4.3EPSS 4.85%17 April 2014
CVE-2014-0984The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table entry password upon encountering the first incorrect character, which allows remote attackers to obtain…EXPLOITMEDIUM 4.3EPSS 2.82%17 April 2014
CVE-2013-2143The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.EXPLOITMEDIUM 6.5EPSS 48.2%17 April 2014
CVE-2014-0644EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE)…EXPLOITHIGH 7.8EPSS 53.3%17 April 2014
CVE-2013-4694Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name.EXPLOIT ×2HIGH 7.5EPSS 17.2%16 April 2014
CVE-2011-4089The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.EXPLOITMEDIUM 4.6EPSS 1.04%16 April 2014
CVE-2014-2424Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related to CEP system.EXPLOITMEDIUM 4.0EPSS 47.4%16 April 2014
CVE-2014-2399Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different…EXPLOITMEDIUM 4.3EPSS 6.98%16 April 2014
CVE-2014-0514The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute arbitrary code via a crafted PDF document, a related issue to CVE-2012-6636.EXPLOIT ×2HIGH 9.3EPSS 72.2%15 April 2014
CVE-2013-7368Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script or HTML via the gnew_template parameter to (1) users/profile.php, (2) articles/index.php, or (3) admin/polls.php; (4) category_id…EXPLOITMEDIUM 4.3EPSS 3.24%15 April 2014
CVE-2014-0358Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a ..EXPLOIT ×3HIGH 7.8EPSS 6.16%15 April 2014
CVE-2014-2851Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that leverages…EXPLOITMEDIUM 6.9EPSS 0.96%14 April 2014
CVE-2014-0787Stack-based buffer overflow in WellinTech KingSCADA before 3.1.2.13 allows remote attackers to execute arbitrary code via a crafted packet.EXPLOITHIGH 10.0EPSS 16.0%12 April 2014
CVE-2014-2850The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.EXPLOITHIGH 8.5EPSS 57.7%11 April 2014
CVE-2014-2849The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.EXPLOITHIGH 8.5EPSS 60.3%11 April 2014
CVE-2014-2847SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands via the TroncoID parameter.EXPLOITHIGH 7.5EPSS 1.31%11 April 2014
CVE-2014-2540SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitrary SQL commands via the site_directory_sort_field parameter to guest/site_directory.EXPLOITHIGH 7.5EPSS 1.31%11 April 2014
CVE-2012-6644Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to…EXPLOIT ×8MEDIUM 4.3EPSS 3.20%8 April 2014
CVE-2012-6643Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers to execute arbitrary SQL commands via the time parameter to (1) videos.php or (2) channels.php.EXPLOIT ×2HIGH 7.5EPSS 1.56%8 April 2014
CVE-2011-5278SQL injection vulnerability in signature.php in Advanced Forum Signatures plugin (aka afsignatures) 2.0.4 for MyBB allows remote attackers to execute arbitrary SQL commands via the afs_bar_right parameter.EXPLOITHIGH 7.5EPSS 1.24%8 April 2014
CVE-2011-5277Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4 for MyBB allow remote attackers to execute arbitrary SQL commands via the (1) afs_type, (2) afs_background, (3) afs_showonline, (4)…EXPLOITHIGH 7.5EPSS 1.24%8 April 2014
CVE-2011-4958Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to template placeholders, as…EXPLOITMEDIUM 4.3EPSS 4.29%8 April 2014
CVE-2014-0346Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ×4UnscoredEPSS —7 April 2014
CVE-2014-0160OpenSSL Information Disclosure VulnerabilityKEVEXPLOIT ×4HIGH 7.5EPSS 100.0%7 April 2014
CVE-2012-2095The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configuration settings and gain privileges via a crafted property name in a dbus message.EXPLOITMEDIUM 6.9EPSS 0.80%7 April 2014
CVE-2013-5680Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of service (child hang) or execute arbitrary code via a long USER command.EXPLOITMEDIUM 6.8EPSS 7.91%6 April 2014
CVE-2013-2287Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.EXPLOITMEDIUM 4.3EPSS 9.24%4 April 2014

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.