Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,329 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 137 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-2750 | Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the query string. | EXPLOIT ✓MEDIUM 4.3EPSS 3.22% | 22 January 2014 |
| CVE-2013-6343 | Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_flag parameter to APP_Installation.asp. | EXPLOITHIGH 10.0EPSS 7.82% | 22 January 2014 |
| CVE-2013-4884 | Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded sequences in a server response, which is not properly handled in the SuperScan HTML report. | EXPLOIT ✓MEDIUM 4.3EPSS 4.25% | 21 January 2014 |
| CVE-2012-2997 | XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows remote authenticated users to read arbitrary files via a crafted XML file. | EXPLOIT ✓MEDIUM 4.0EPSS 6.44% | 21 January 2014 |
| CVE-2013-7219 | SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the answer_id[] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 21 January 2014 |
| CVE-2013-6922 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts via a… | EXPLOITMEDIUM 6.8EPSS 1.36% | 21 January 2014 |
| CVE-2013-4200 | The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows remote attackers to bypass the… | EXPLOIT ✓MEDIUM 5.8EPSS 2.22% | 21 January 2014 |
| CVE-2013-2594 | SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary SQL commands via the callref parameter. | EXPLOITHIGH 7.5EPSS 2.56% | 21 January 2014 |
| CVE-2014-1619 | Multiple SQL injection vulnerabilities in Cubic CMS 5.1.1, 5.1.2, and 5.2 allow remote attackers to execute arbitrary SQL commands via the (1) resource_id or (2) version_id parameter to recursos/agent.php or (3) login or (4) pass parameter to… | EXPLOITHIGH 7.5EPSS 2.28% | 21 January 2014 |
| CVE-2014-1618 | Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) p_id parameter to products.php or id parameter to (3) page.php or (4) news.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.23% | 21 January 2014 |
| CVE-2013-6872 | SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a projectpdf action. | EXPLOITMEDIUM 6.5EPSS 2.46% | 21 January 2014 |
| CVE-2013-6040 | MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML document. | EXPLOIT ×3HIGH 8.1EPSS 7.37% | 21 January 2014 |
| CVE-2013-3482 | Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in an ERS… | EXPLOIT ✓HIGH 9.3EPSS 31.5% | 19 January 2014 |
| CVE-2013-7204 | Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users. | EXPLOITMEDIUM 6.8EPSS 10.6% | 17 January 2014 |
| CVE-2012-6626 | SQL injection vulnerability in verify-user.php in b2ePMS 1.0 allows remote attackers to execute arbitrary SQL commands via the username field. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 16 January 2014 |
| CVE-2012-6625 | SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the groupid parameter in an editgroup action. | EXPLOIT ✓HIGH 7.5EPSS 4.93% | 16 January 2014 |
| CVE-2012-6624 | Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the width parameter in a soundcloud_is_gold_player_preview action to wp-admin/admin-ajax.php. | EXPLOIT ✓MEDIUM 4.3EPSS 3.75% | 16 January 2014 |
| CVE-2012-6622 | Multiple cross-site scripting (XSS) vulnerabilities in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) groupid parameter in an editgroup… | EXPLOIT ✓MEDIUM 4.3EPSS 5.03% | 16 January 2014 |
| CVE-2013-5880 | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows remote attackers to affect confidentiality via unknown vectors related to DM Others. | EXPLOIT ✓MEDIUM 5.0EPSS 59.6% | 15 January 2014 |
| CVE-2013-5877 | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.0, and 12.2.1 allows remote attackers to affect confidentiality via unknown vectors related to DM… | EXPLOIT ✓MEDIUM 5.0EPSS 55.0% | 15 January 2014 |
| CVE-2013-5795 | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, 12.2.2, and 12.2.3 allows remote attackers to affect confidentiality via unknown vectors related… | EXPLOIT ✓MEDIUM 5.0EPSS 59.5% | 15 January 2014 |
| CVE-2014-1206 | SQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the owa_email_address parameter in a base.passwordResetRequest action to index.php. | EXPLOITHIGH 7.5EPSS 2.50% | 15 January 2014 |
| CVE-2014-1201 | Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers… | EXPLOITHIGH 10.0EPSS 29.5% | 15 January 2014 |
| CVE-2013-2827 | An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers to download arbitrary DLL code onto a client machine and execute this code via the ProjectURL property… | EXPLOIT ✓HIGH 7.5EPSS 48.3% | 15 January 2014 |
| CVE-2014-0379 | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0.x, 7.3.1.x, 12.2.0, 12.2.1, and 12.2.2 allows remote attackers to affect integrity via unknown vectors related… | EXPLOIT ✓MEDIUM 4.3EPSS 7.24% | 15 January 2014 |
| CVE-2014-0372 | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown… | EXPLOIT ✓MEDIUM 5.5EPSS 8.76% | 15 January 2014 |
| CVE-2013-7108 | Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service… | EXPLOIT ✓MEDIUM 5.5EPSS 59.5% | 15 January 2014 |
| CVE-2014-0659 | The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data,… | EXPLOIT ✓HIGH 10.0EPSS 73.8% | 12 January 2014 |
| CVE-2013-6017 | Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML via the body of an e-mail message, as demonstrated by the SRC attribute of an IFRAME element. | EXPLOIT ✓MEDIUM 4.3EPSS 4.37% | 12 January 2014 |
| CVE-2013-7282 | The management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with firmware 5.07.36_NIS01 allows remote attackers to bypass authentication via a "Cookie: :language=en" HTTP header. | EXPLOITHIGH 10.0EPSS 9.57% | 10 January 2014 |
| CVE-2013-7139 | SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote to execute arbitrary SQL commands via the category parameter. | EXPLOITHIGH 7.5EPSS 1.02% | 9 January 2014 |
| CVE-2013-6923 | Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname parameter to admin/access_control_user_edit.php… | EXPLOITMEDIUM 4.3EPSS 3.22% | 9 January 2014 |
| CVE-2013-6955 | webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to arbitrary files, and consequently execute arbitrary code, via a pathname… | EXPLOIT ✓HIGH 10.0EPSS 84.6% | 9 January 2014 |
| CVE-2014-0621 | Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to hijack the authentication of administrators for requests that (1) perform a factory reset via a request to… | EXPLOITMEDIUM 6.8EPSS 1.01% | 8 January 2014 |
| CVE-2014-0620 | Multiple cross-site scripting (XSS) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to inject arbitrary web script or HTML via the (1) ADDNewDomain parameter to parental/website-filters.asp or (2)… | EXPLOITMEDIUM 4.3EPSS 1.39% | 8 January 2014 |
| CVE-2013-7280 | Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of service (crash) via a long string in a .m3u file. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 5.77% | 8 January 2014 |
| CVE-2013-7278 | SQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to default.asp. | EXPLOIT ✓HIGH 7.5EPSS 2.60% | 8 January 2014 |
| CVE-2013-7274 | Cross-site scripting (XSS) vulnerability in Wallpaper Script 3.5.0082 allows remote authenticated users to inject arbitrary web script or HTML via the title field in a wallpaper file upload. | EXPLOITLOW 3.5EPSS 1.45% | 8 January 2014 |
| CVE-2013-7097 | Directory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.46% | 8 January 2014 |
| CVE-2013-6480 | Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM. | EXPLOIT ✓LOW 2.1EPSS 2.08% | 7 January 2014 |
| CVE-2013-6884 | The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges. | EXPLOITHIGH 10.0EPSS 10.3% | 7 January 2014 |
| CVE-2013-6881 | CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task. | EXPLOITHIGH 10.0EPSS 12.6% | 7 January 2014 |
| CVE-2013-6194 | Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1905. | EXPLOIT ✓HIGH 10.0EPSS 65.9% | 4 January 2014 |
| CVE-2013-2347 | The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary commands or cause a denial of service via a crafted EXEC_BAR packet to TCP port 5555, aka ZDI-CAN-1885. | EXPLOIT ×2 ✓HIGH 10.0EPSS 66.4% | 4 January 2014 |
| CVE-2013-7260 | Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary code via a long (1) version number or (2) encoding declaration in the XML… | EXPLOIT ✓HIGH 7.5EPSS 66.9% | 3 January 2014 |
| CVE-2009-5137 | Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long URL in the [playlist] section in a .pls file, a different vector than CVE-2009-1667. | EXPLOIT ✓HIGH 7.5EPSS 3.77% | 3 January 2014 |
| CVE-2013-7240 | Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 19.6% | 3 January 2014 |
| CVE-2013-5211 | The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013. | EXPLOITMEDIUM 5.0EPSS 97.5% | 2 January 2014 |
| CVE-2012-0262 | op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter. | EXPLOIT ✓HIGH 10.0EPSS 72.9% | 31 December 2013 |
| CVE-2012-0261 | license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the timestamp parameter for an install action. | EXPLOIT ✓HIGH 10.0EPSS 73.9% | 31 December 2013 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.