Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 135 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-1636 | Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through… | EXPLOIT ✓MEDIUM 4.3EPSS 6.31% | 12 March 2014 |
| CVE-2014-0307 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a certain sequence of manipulations of a TextRange element, aka "Internet Explorer… | EXPLOIT ✓HIGH 9.3EPSS 72.2% | 12 March 2014 |
| CVE-2013-5639 | Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOITHIGH 7.5EPSS 7.15% | 11 March 2014 |
| CVE-2013-4467 | Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQL commands via the campaign variable in… | EXPLOIT ✓MEDIUM 6.5EPSS 31.6% | 11 March 2014 |
| CVE-2013-3961 | SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to execute arbitrary SQL commands via the eventid parameter. | EXPLOITMEDIUM 6.5EPSS 2.30% | 11 March 2014 |
| CVE-2013-3928 | Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file. | EXPLOIT ✓HIGH 9.3EPSS 37.3% | 11 March 2014 |
| CVE-2013-2754 | Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a request to admin/users/add/user/do/. | EXPLOITMEDIUM 6.8EPSS 2.29% | 11 March 2014 |
| CVE-2013-2289 | Cross-site scripting (XSS) vulnerability in admin/templates/default.php in Batavi 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to admin/index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.76% | 11 March 2014 |
| CVE-2012-6290 | SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to admin/admin_search/. | EXPLOITMEDIUM 6.5EPSS 4.23% | 11 March 2014 |
| CVE-2014-2299 | Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large… | EXPLOIT ✓HIGH 9.3EPSS 47.4% | 11 March 2014 |
| CVE-2014-0094 | The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 99.6% | 11 March 2014 |
| CVE-2014-2317 | SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. | EXPLOITMEDIUM 6.8EPSS 1.17% | 9 March 2014 |
| CVE-2014-2314 | Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors. | EXPLOIT ✓MEDIUM 4.3EPSS 26.2% | 9 March 2014 |
| CVE-2014-1945 | SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value parameter. | EXPLOITHIGH 7.5EPSS 1.31% | 9 March 2014 |
| CVE-2014-1944 | Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the text parameter to index.php/guestbook/index/newentry. | EXPLOITMEDIUM 4.3EPSS 3.29% | 9 March 2014 |
| CVE-2013-6233 | Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata." | EXPLOITMEDIUM 4.3EPSS 3.22% | 9 March 2014 |
| CVE-2013-6232 | Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page. | EXPLOITLOW 3.5EPSS 3.65% | 9 March 2014 |
| CVE-2014-1907 | Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. | EXPLOITMEDIUM 6.4EPSS 10.9% | 6 March 2014 |
| CVE-2014-1906 | Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg… | EXPLOITMEDIUM 4.3EPSS 4.55% | 6 March 2014 |
| CVE-2014-0683 | The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earlier, and CVR100W router with firmware 1.0.1.19 and earlier does not prevent replaying of modified authentication… | EXPLOITHIGH 10.0EPSS 10.4% | 6 March 2014 |
| CVE-2013-6720 | Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions… | EXPLOITMEDIUM 5.5EPSS 28.6% | 6 March 2014 |
| CVE-2013-6719 | delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the testconn_host… | EXPLOITMEDIUM 6.0EPSS 26.8% | 6 March 2014 |
| CVE-2014-2206 | Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long HTTP Response Header. | EXPLOIT ✓HIGH 10.0EPSS 61.4% | 5 March 2014 |
| CVE-2014-2211 | SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the rssurl parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 3 March 2014 |
| CVE-2014-2013 | Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the ContextColor value of the Fill attribute in a Path element. | EXPLOIT ✓HIGH 7.5EPSS 14.5% | 3 March 2014 |
| CVE-2014-1684 | The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Player before 2.1.3 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero minimum and maximum… | EXPLOITMEDIUM 4.3EPSS 5.21% | 3 March 2014 |
| CVE-2013-4981 | Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long… | EXPLOIT ✓HIGH 9.0EPSS 6.04% | 3 March 2014 |
| CVE-2013-4980 | Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long… | EXPLOIT ✓HIGH 9.0EPSS 6.04% | 3 March 2014 |
| CVE-2013-4977 | Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, allows remote attackers to cause a denial of service (device crash and reboot) and possibly execute… | EXPLOIT ✓HIGH 10.0EPSS 16.7% | 3 March 2014 |
| CVE-2013-1409 | Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php. | EXPLOIT ✓MEDIUM 4.3EPSS 4.55% | 3 March 2014 |
| CVE-2013-4710 | Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service… | EXPLOIT ×2 ✓HIGH 9.3EPSS 42.6% | 3 March 2014 |
| CVE-2012-6636 | The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded… | EXPLOIT ✓MEDIUM 6.8EPSS 41.4% | 3 March 2014 |
| CVE-2014-2091 | Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the title parameter in an add_forum action. | EXPLOIT ✓LOW 3.5EPSS 1.21% | 2 March 2014 |
| CVE-2014-2090 | Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tar, (2) tar_val, or (3) title parameter. | EXPLOITLOW 3.5EPSS 1.44% | 2 March 2014 |
| CVE-2014-2089 | ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain client_id pathname. | EXPLOITMEDIUM 6.8EPSS 2.52% | 2 March 2014 |
| CVE-2014-2088 | Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php filename in an upload_files action to the uploadFiles command, and then accessing the .php file via a… | EXPLOITMEDIUM 6.5EPSS 2.58% | 2 March 2014 |
| CVE-2014-0334 | Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple allow remote authenticated users to inject arbitrary web script or HTML via (1) the group parameter to admin/addgroup.php, (2) the htmlblob parameter to admin/addhtmlblob.php, the… | EXPLOITLOW 3.5EPSS 1.46% | 2 March 2014 |
| CVE-2014-1912 | Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string. | EXPLOITHIGH 7.5EPSS 28.3% | 1 March 2014 |
| CVE-2014-1695 | Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15, and 3.3.x before 3.3.5 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML email. | EXPLOITMEDIUM 4.3EPSS 4.91% | 1 March 2014 |
| CVE-2013-2498 | SQL injection vulnerability in the login page in flexycms/modules/user/user_manager.php in SimpleHRM 2.3, 2.2, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to index.php/user/setLogin. | EXPLOIT ✓HIGH 7.5EPSS 1.23% | 1 March 2014 |
| CVE-2014-1854 | SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free plugin 3.9 through 3.9.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter. | EXPLOIT ✓HIGH 7.5EPSS 5.60% | 27 February 2014 |
| CVE-2014-1597 | SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitrary SQL commands via the objID parameter to the default URI. | EXPLOIT ✓HIGH 7.5EPSS 1.37% | 27 February 2014 |
| CVE-2013-2817 | An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote attackers to execute arbitrary programs via a crafted HTML document in conjunction with a Login Client button click. | EXPLOITHIGH 9.3EPSS 5.93% | 24 February 2014 |
| CVE-2014-1903 | admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute… | EXPLOIT ×2 ✓HIGH 7.5EPSS 52.8% | 18 February 2014 |
| CVE-2013-6674 | Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message… | EXPLOITMEDIUM 4.3EPSS 7.70% | 17 February 2014 |
| CVE-2012-0270 | Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main.c or (2) PVOC file to the getnum function in util/pv_import.c. | EXPLOIT ✓HIGH 7.5EPSS 54.7% | 17 February 2014 |
| CVE-2013-6167 | Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that… | EXPLOIT ✓MEDIUM 6.8EPSS 1.57% | 15 February 2014 |
| CVE-2013-6166 | Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that… | EXPLOIT ✓MEDIUM 6.8EPSS 1.86% | 15 February 2014 |
| CVE-2014-0322 | Microsoft Internet Explorer Use-After-Free Vulnerability | KEVEXPLOIT ×2 ✓HIGH 8.8EPSS 85.1% | 14 February 2014 |
| CVE-2013-6492 | The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request. | EXPLOIT ✓MEDIUM 5.8EPSS 4.00% | 14 February 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.