SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 134 of 501

CVESummaryPriorityPublished
CVE-2012-6429Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to execute arbitrary code via a long string to the password argument.EXPLOITHIGH 10.0EPSS 15.5%4 April 2014
CVE-2014-2340Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.EXPLOITMEDIUM 6.8EPSS 2.85%3 April 2014
CVE-2013-2945SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL commands via the show_statuses[] parameter.EXPLOITMEDIUM 6.5EPSS 2.77%2 April 2014
CVE-2013-4240Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add new testimonials via the…EXPLOITMEDIUM 6.8EPSS 2.83%2 April 2014
CVE-2013-3213Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_picklists method to soap/customerportal.php, (2) where parameter in the…EXPLOITHIGH 7.5EPSS 3.11%2 April 2014
CVE-2014-1691The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.EXPLOITHIGH 7.5EPSS 42.9%1 April 2014
CVE-2014-0050MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that…EXPLOITHIGH 7.5EPSS 83.2%1 April 2014
CVE-2013-0662Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.EXPLOIT ×2HIGH 9.3EPSS 22.3%1 April 2014
CVE-2013-7349Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter to news/send.php, (2) thread_id parameter to posts/edit.php, or (3) user_email parameter to users/password.php…EXPLOIT ×2HIGH 7.5EPSS 2.60%1 April 2014
CVE-2013-5640Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) answer_id or (2) question_id parameter to polls/vote.php, (3) story_id parameter to comments/add.php or (4) comments/edit.php, or…EXPLOIT ×2HIGH 7.5EPSS 2.32%1 April 2014
CVE-2009-5141Format string vulnerability in War FTP Daemon (warftpd) 1.82 RC 12 allows remote authenticated users to cause a denial of service (crash) via format string specifiers in a LIST command.EXPLOITMEDIUM 4.0EPSS 2.70%1 April 2014
CVE-2014-2671Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted WAV file.EXPLOIT ×7MEDIUM 6.8EPSS 46.3%31 March 2014
CVE-2014-1982The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary commands via a direct request to…EXPLOITHIGH 10.0EPSS 9.51%31 March 2014
CVE-2014-0983Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS…EXPLOIT ×2MEDIUM 6.9EPSS 8.20%31 March 2014
CVE-2014-0982Reason: This issue was MERGED into CVE-2014-0981 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions.EXPLOITUnscoredEPSS —31 March 2014
CVE-2014-0981VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium…EXPLOITMEDIUM 4.4EPSS 1.40%31 March 2014
CVE-2014-2668Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.EXPLOITMEDIUM 5.0EPSS 22.3%28 March 2014
CVE-2013-0807Cross-site scripting (XSS) vulnerability in the NewSectionPrompt function in include/tool/editing_page.php in gpEasy CMS 3.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the section parameter in a new_section action…EXPLOITMEDIUM 4.3EPSS 4.03%28 March 2014
CVE-2013-7346Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the sort parameter to system/authors/, related to…EXPLOITMEDIUM 6.8EPSS 0.52%27 March 2014
CVE-2013-2559SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/.EXPLOITMEDIUM 6.5EPSS 2.35%27 March 2014
CVE-2014-1303Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014.EXPLOIT ×2HIGH 10.0EPSS 34.8%26 March 2014
CVE-2014-2016Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x before 4.7.11, and 4.8.x before 4.8.4, and Enterprise Edition 4.6.8 and earlier, 5.0.x before 5.0.11 and 5.1.x before 5.1.4…EXPLOITMEDIUM 4.3EPSS 1.43%25 March 2014
CVE-2013-1605Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitrary code via a long filename in a GET request.EXPLOITHIGH 7.5EPSS 11.5%25 March 2014
CVE-2013-1604Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 3.56%25 March 2014
CVE-2014-1761Microsoft Word Memory Corruption VulnerabilityKEVEXPLOITHIGH 7.8EPSS 77.5%25 March 2014
CVE-2013-1408Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php.EXPLOITMEDIUM 6.5EPSS 4.31%24 March 2014
CVE-2012-6430Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19, 2012, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin.php.EXPLOITMEDIUM 4.3EPSS 3.91%24 March 2014
CVE-2012-4886Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code via a long BSTR string.EXPLOITHIGH 10.0EPSS 15.3%24 March 2014
CVE-2014-2588Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a ..EXPLOITMEDIUM 4.0EPSS 7.32%24 March 2014
CVE-2014-2587SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL commands via the username of an audit report (aka user parameter).EXPLOITMEDIUM 6.5EPSS 3.14%24 March 2014
CVE-2014-2586Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote attackers to inject arbitrary web script or HTML via a crafted password.EXPLOITMEDIUM 4.3EPSS 3.22%24 March 2014
CVE-2014-2339Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) subject or (2) content parameter.EXPLOITMEDIUM 6.5EPSS 1.98%19 March 2014
CVE-2014-1511Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.EXPLOITCRITICAL 9.8EPSS 83.6%19 March 2014
CVE-2014-1510The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to…EXPLOITCRITICAL 9.8EPSS 82.3%19 March 2014
CVE-2014-2087Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code…EXPLOITHIGH 9.3EPSS 16.7%18 March 2014
CVE-2013-2643Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) xss parameter in an allow action to rss.php, (2) msg parameter to end-user/errdoc.php,…EXPLOITMEDIUM 4.3EPSS 4.53%18 March 2014
CVE-2013-2642Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to the Block page, when using the user_workstation variable in a customized template, and remote…EXPLOITHIGH 9.3EPSS 6.89%18 March 2014
CVE-2013-2641Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.EXPLOITMEDIUM 5.0EPSS 71.0%18 March 2014
CVE-2013-2619Directory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 7.65%18 March 2014
CVE-2014-2534/sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow.EXPLOITMEDIUM 4.9EPSS 0.95%18 March 2014
CVE-2014-2533/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument.EXPLOIT ×2HIGH 7.2EPSS 2.91%18 March 2014
CVE-2014-1287USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted USB messages.EXPLOITHIGH 7.2EPSS 1.12%14 March 2014
CVE-2014-0784Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.EXPLOITHIGH 8.3EPSS 35.9%14 March 2014
CVE-2014-0783Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.EXPLOITHIGH 9.0EPSS 67.6%14 March 2014
CVE-2013-6835TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote attackers to obtain telephone number or e-mail address information via a facetime-audio: URL.EXPLOITMEDIUM 5.0EPSS 6.79%14 March 2014
CVE-2014-2043SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows remote authenticated users to execute arbitrary SQL commands via the value parameter.EXPLOITMEDIUM 6.5EPSS 1.14%13 March 2014
CVE-2013-3729Multiple cross-site request forgery (CSRF) vulnerabilities in Kasseler CMS before 2 r1232 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) groups[] parameter in a send…EXPLOITMEDIUM 6.8EPSS 1.22%13 March 2014
CVE-2013-3728Cross-site scripting (XSS) vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users with permissions to create categories to inject arbitrary web script or HTML via the cat parameter in an admin_new_category action to admin.php.EXPLOITLOW 3.5EPSS 2.98%13 March 2014
CVE-2013-3727SQL injection vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users to execute arbitrary SQL commands via the groups[] parameter to admin.php.EXPLOITHIGH 7.5EPSS 2.85%13 March 2014
CVE-2013-5117SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.EXPLOITHIGH 7.5EPSS 2.34%12 March 2014

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.