Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 134 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-6429 | Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to execute arbitrary code via a long string to the password argument. | EXPLOIT ✓HIGH 10.0EPSS 15.5% | 4 April 2014 |
| CVE-2014-2340 | Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php. | EXPLOITMEDIUM 6.8EPSS 2.85% | 3 April 2014 |
| CVE-2013-2945 | SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL commands via the show_statuses[] parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 2.77% | 2 April 2014 |
| CVE-2013-4240 | Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add new testimonials via the… | EXPLOIT ✓MEDIUM 6.8EPSS 2.83% | 2 April 2014 |
| CVE-2013-3213 | Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_picklists method to soap/customerportal.php, (2) where parameter in the… | EXPLOITHIGH 7.5EPSS 3.11% | 2 April 2014 |
| CVE-2014-1691 | The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form. | EXPLOIT ✓HIGH 7.5EPSS 42.9% | 1 April 2014 |
| CVE-2014-0050 | MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that… | EXPLOIT ✓HIGH 7.5EPSS 83.2% | 1 April 2014 |
| CVE-2013-0662 | Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header. | EXPLOIT ×2HIGH 9.3EPSS 22.3% | 1 April 2014 |
| CVE-2013-7349 | Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter to news/send.php, (2) thread_id parameter to posts/edit.php, or (3) user_email parameter to users/password.php… | EXPLOIT ×2HIGH 7.5EPSS 2.60% | 1 April 2014 |
| CVE-2013-5640 | Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) answer_id or (2) question_id parameter to polls/vote.php, (3) story_id parameter to comments/add.php or (4) comments/edit.php, or… | EXPLOIT ×2HIGH 7.5EPSS 2.32% | 1 April 2014 |
| CVE-2009-5141 | Format string vulnerability in War FTP Daemon (warftpd) 1.82 RC 12 allows remote authenticated users to cause a denial of service (crash) via format string specifiers in a LIST command. | EXPLOIT ✓MEDIUM 4.0EPSS 2.70% | 1 April 2014 |
| CVE-2014-2671 | Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted WAV file. | EXPLOIT ×7 ✓MEDIUM 6.8EPSS 46.3% | 31 March 2014 |
| CVE-2014-1982 | The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary commands via a direct request to… | EXPLOITHIGH 10.0EPSS 9.51% | 31 March 2014 |
| CVE-2014-0983 | Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS… | EXPLOIT ×2 ✓MEDIUM 6.9EPSS 8.20% | 31 March 2014 |
| CVE-2014-0982 | Reason: This issue was MERGED into CVE-2014-0981 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. | EXPLOIT ✓UnscoredEPSS — | 31 March 2014 |
| CVE-2014-0981 | VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium… | EXPLOIT ✓MEDIUM 4.4EPSS 1.40% | 31 March 2014 |
| CVE-2014-2668 | Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids. | EXPLOIT ✓MEDIUM 5.0EPSS 22.3% | 28 March 2014 |
| CVE-2013-0807 | Cross-site scripting (XSS) vulnerability in the NewSectionPrompt function in include/tool/editing_page.php in gpEasy CMS 3.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the section parameter in a new_section action… | EXPLOIT ✓MEDIUM 4.3EPSS 4.03% | 28 March 2014 |
| CVE-2013-7346 | Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the sort parameter to system/authors/, related to… | EXPLOIT ✓MEDIUM 6.8EPSS 0.52% | 27 March 2014 |
| CVE-2013-2559 | SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. | EXPLOIT ✓MEDIUM 6.5EPSS 2.35% | 27 March 2014 |
| CVE-2014-1303 | Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014. | EXPLOIT ×2HIGH 10.0EPSS 34.8% | 26 March 2014 |
| CVE-2014-2016 | Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x before 4.7.11, and 4.8.x before 4.8.4, and Enterprise Edition 4.6.8 and earlier, 5.0.x before 5.0.11 and 5.1.x before 5.1.4… | EXPLOITMEDIUM 4.3EPSS 1.43% | 25 March 2014 |
| CVE-2013-1605 | Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitrary code via a long filename in a GET request. | EXPLOIT ✓HIGH 7.5EPSS 11.5% | 25 March 2014 |
| CVE-2013-1604 | Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.56% | 25 March 2014 |
| CVE-2014-1761 | Microsoft Word Memory Corruption Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 77.5% | 25 March 2014 |
| CVE-2013-1408 | Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. | EXPLOIT ✓MEDIUM 6.5EPSS 4.31% | 24 March 2014 |
| CVE-2012-6430 | Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19, 2012, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin.php. | EXPLOIT ✓MEDIUM 4.3EPSS 3.91% | 24 March 2014 |
| CVE-2012-4886 | Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code via a long BSTR string. | EXPLOIT ✓HIGH 10.0EPSS 15.3% | 24 March 2014 |
| CVE-2014-2588 | Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. | EXPLOITMEDIUM 4.0EPSS 7.32% | 24 March 2014 |
| CVE-2014-2587 | SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL commands via the username of an audit report (aka user parameter). | EXPLOITMEDIUM 6.5EPSS 3.14% | 24 March 2014 |
| CVE-2014-2586 | Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote attackers to inject arbitrary web script or HTML via a crafted password. | EXPLOITMEDIUM 4.3EPSS 3.22% | 24 March 2014 |
| CVE-2014-2339 | Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) subject or (2) content parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 1.98% | 19 March 2014 |
| CVE-2014-1511 | Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors. | EXPLOIT ✓CRITICAL 9.8EPSS 83.6% | 19 March 2014 |
| CVE-2014-1510 | The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to… | EXPLOIT ✓CRITICAL 9.8EPSS 82.3% | 19 March 2014 |
| CVE-2014-2087 | Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code… | EXPLOIT ✓HIGH 9.3EPSS 16.7% | 18 March 2014 |
| CVE-2013-2643 | Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) xss parameter in an allow action to rss.php, (2) msg parameter to end-user/errdoc.php,… | EXPLOITMEDIUM 4.3EPSS 4.53% | 18 March 2014 |
| CVE-2013-2642 | Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to the Block page, when using the user_workstation variable in a customized template, and remote… | EXPLOITHIGH 9.3EPSS 6.89% | 18 March 2014 |
| CVE-2013-2641 | Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter. | EXPLOITMEDIUM 5.0EPSS 71.0% | 18 March 2014 |
| CVE-2013-2619 | Directory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 7.65% | 18 March 2014 |
| CVE-2014-2534 | /sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow. | EXPLOIT ✓MEDIUM 4.9EPSS 0.95% | 18 March 2014 |
| CVE-2014-2533 | /sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument. | EXPLOIT ×2 ✓HIGH 7.2EPSS 2.91% | 18 March 2014 |
| CVE-2014-1287 | USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted USB messages. | EXPLOITHIGH 7.2EPSS 1.12% | 14 March 2014 |
| CVE-2014-0784 | Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet. | EXPLOIT ✓HIGH 8.3EPSS 35.9% | 14 March 2014 |
| CVE-2014-0783 | Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet. | EXPLOIT ✓HIGH 9.0EPSS 67.6% | 14 March 2014 |
| CVE-2013-6835 | TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote attackers to obtain telephone number or e-mail address information via a facetime-audio: URL. | EXPLOIT ✓MEDIUM 5.0EPSS 6.79% | 14 March 2014 |
| CVE-2014-2043 | SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows remote authenticated users to execute arbitrary SQL commands via the value parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 1.14% | 13 March 2014 |
| CVE-2013-3729 | Multiple cross-site request forgery (CSRF) vulnerabilities in Kasseler CMS before 2 r1232 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) groups[] parameter in a send… | EXPLOITMEDIUM 6.8EPSS 1.22% | 13 March 2014 |
| CVE-2013-3728 | Cross-site scripting (XSS) vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users with permissions to create categories to inject arbitrary web script or HTML via the cat parameter in an admin_new_category action to admin.php. | EXPLOITLOW 3.5EPSS 2.98% | 13 March 2014 |
| CVE-2013-3727 | SQL injection vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users to execute arbitrary SQL commands via the groups[] parameter to admin.php. | EXPLOITHIGH 7.5EPSS 2.85% | 13 March 2014 |
| CVE-2013-5117 | SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 12 March 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.