Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,329 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 139 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-4212 | Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL… | EXPLOIT ✓MEDIUM 6.8EPSS 81.1% | 7 December 2013 |
| CVE-2013-6787 | SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL… | EXPLOIT ✓MEDIUM 6.0EPSS 2.74% | 5 December 2013 |
| CVE-2013-6341 | SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language parameter to index.php. | EXPLOITHIGH 7.5EPSS 2.28% | 5 December 2013 |
| CVE-2013-6936 | Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.48% | 4 December 2013 |
| CVE-2013-6935 | Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the SourcePath value in a .wcf file. | EXPLOIT ✓HIGH 9.3EPSS 32.4% | 4 December 2013 |
| CVE-2013-6937 | Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the name attribute of the cols element in a .wstyle file. | EXPLOIT ✓MEDIUM 6.8EPSS 3.24% | 4 December 2013 |
| CVE-2013-5912 | VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in the fileName parameter during an importFile action. | EXPLOIT ✓HIGH 10.0EPSS 31.4% | 28 November 2013 |
| CVE-2013-5065 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVEXPLOIT ×3 ✓HIGH 7.8EPSS 34.7% | 28 November 2013 |
| CVE-2013-4624 | Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web script or HTML via (1) the site parameter to engines/manager.jsp, (2) the searchString parameter to administration/… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.40% | 27 November 2013 |
| CVE-2013-6875 | SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php. | EXPLOIT ✓HIGH 7.5EPSS 3.24% | 26 November 2013 |
| CVE-2013-6874 | Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a long URL in a .m3u file. | EXPLOIT ✓HIGH 9.3EPSS 5.53% | 26 November 2013 |
| CVE-2013-6873 | SQL injection vulnerability in Testa Online Test Management System (OTMS) 2.0.0.2 allows remote attackers to execute arbitrary SQL commands via the test_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 26 November 2013 |
| CVE-2012-6608 | Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the Page parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.55% | 25 November 2013 |
| CVE-2013-4547 | nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI. | EXPLOIT ✓HIGH 7.5EPSS 67.7% | 23 November 2013 |
| CVE-2013-0221 | The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command, when using the (1) -d or (2) -M switch, which triggers a stack-based… | EXPLOIT ✓MEDIUM 4.3EPSS 7.24% | 23 November 2013 |
| CVE-2013-4474 | Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filename. | EXPLOIT ✓MEDIUM 5.0EPSS 10.5% | 23 November 2013 |
| CVE-2013-6852 | Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack the authentication of administrators for requests that change an administrative password via the setPassword method. | EXPLOITMEDIUM 6.8EPSS 1.46% | 22 November 2013 |
| CVE-2013-6831 | PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privileges via a sudo command that leverages access to the qmailq account. | EXPLOIT ✓HIGH 7.2EPSS 1.01% | 20 November 2013 |
| CVE-2013-6830 | admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary commands via shell metacharacters in the nsserver parameter during an nslookup operation. | EXPLOIT ✓HIGH 7.5EPSS 8.93% | 20 November 2013 |
| CVE-2013-6829 | admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parameter during a ping operation. | EXPLOIT ✓HIGH 7.5EPSS 79.9% | 20 November 2013 |
| CVE-2013-6826 | cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks. | EXPLOIT ✓MEDIUM 6.8EPSS 1.93% | 20 November 2013 |
| CVE-2013-6282 | Linux Kernel Improper Input Validation Vulnerability | KEVEXPLOIT ×2 ✓HIGH 8.8EPSS 39.7% | 20 November 2013 |
| CVE-2013-5730 | Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DSL-2740B Gateway with firmware EU_1.00 allow remote attackers to hijack the authentication of administrators for requests that (1) enable or disable Wireless MAC Address Filters via a… | EXPLOITMEDIUM 6.8EPSS 1.21% | 20 November 2013 |
| CVE-2013-4579 | The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach to determine the set of MAC addresses on which a Wi-Fi device is listening, which allows remote… | EXPLOIT ✓MEDIUM 4.3EPSS 10.2% | 20 November 2013 |
| CVE-2013-3095 | Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. | EXPLOIT ✓MEDIUM 6.8EPSS 1.21% | 20 November 2013 |
| CVE-2013-6797 | Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin before 2.0.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that embed arbitrary… | EXPLOIT ✓MEDIUM 6.8EPSS 2.88% | 19 November 2013 |
| CVE-2013-6042 | Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo before 2.1.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter. | EXPLOITMEDIUM 4.3EPSS 1.71% | 19 November 2013 |
| CVE-2013-5223 | D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability | KEVEXPLOIT ×2MEDIUM 5.4EPSS 50.8% | 19 November 2013 |
| CVE-2013-2271 | The D-Link DSL-2740B Gateway with firmware EU_1.0, when an active administrator session exists, allows remote attackers to bypass authentication and gain administrator access via a request to login.cgi. | EXPLOITHIGH 7.6EPSS 4.91% | 19 November 2013 |
| CVE-2013-4034 | IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in… | EXPLOIT ✓MEDIUM 4.0EPSS 5.56% | 18 November 2013 |
| CVE-2013-6799 | Apple Mac OS X 10.9 allows local users to cause a denial of service (memory corruption or panic) by creating a hard link to a directory. | EXPLOITMEDIUM 4.7EPSS 0.77% | 18 November 2013 |
| CVE-2013-6794 | Cross-site scripting (XSS) vulnerability in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allows remote attackers to inject arbitrary web script or HTML via the Location field. | EXPLOIT ✓MEDIUM 4.3EPSS 1.38% | 14 November 2013 |
| CVE-2013-6793 | Multiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote attackers to inject arbitrary web script or HTML via the (1) event name or (2) date field. | EXPLOIT ✓MEDIUM 4.3EPSS 3.22% | 14 November 2013 |
| CVE-2013-6164 | SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrary SQL commands via the objectId parameter. | EXPLOITHIGH 7.5EPSS 3.44% | 14 November 2013 |
| CVE-2013-6058 | SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to blog-by-cat/. | EXPLOITHIGH 7.5EPSS 2.48% | 14 November 2013 |
| CVE-2013-6627 | net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1xx) status codes, which allows remote web servers to cause a denial of service (out-of-bounds read) via a crafted response. | EXPLOIT ✓MEDIUM 5.0EPSS 5.34% | 13 November 2013 |
| CVE-2013-6357 | Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST… | EXPLOITMEDIUM 6.8EPSS 2.47% | 13 November 2013 |
| CVE-2013-2653 | security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing attacks without detection by the victim. | EXPLOIT ✓MEDIUM 5.8EPSS 4.07% | 13 November 2013 |
| CVE-2013-3918 | Microsoft Windows Out-of-Bounds Write Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 73.7% | 12 November 2013 |
| CVE-2013-4987 | PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters in a "system ping" command. | EXPLOIT ✓HIGH 8.5EPSS 2.73% | 8 November 2013 |
| CVE-2013-3906 | Microsoft Graphics Component Memory Corruption Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 84.9% | 6 November 2013 |
| CVE-2013-5689 | Reason: This issue has been MERGED with CVE-2013-5688 in accordance with CVE content decisions, because it is the same type of vulnerability affecting the same versions. | EXPLOIT ✓UnscoredEPSS — | 5 November 2013 |
| CVE-2013-5688 | Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the file parameter in a (1) download or (2)… | EXPLOIT ✓MEDIUM 5.5EPSS 6.16% | 5 November 2013 |
| CVE-2013-6618 | jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allows remote authenticated users to execute arbitrary commands via the rsargs parameter in an exec action. | EXPLOITHIGH 9.0EPSS 10.6% | 5 November 2013 |
| CVE-2013-5694 | SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL commands via the service_selection parameter. | EXPLOITHIGH 7.5EPSS 2.56% | 5 November 2013 |
| CVE-2011-5267 | Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as used in WikiWig 5.01 and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1)… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.74% | 5 November 2013 |
| CVE-2013-6366 | The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().exec call. | EXPLOIT ✓MEDIUM 6.5EPSS 7.01% | 4 November 2013 |
| CVE-2013-4837 | Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832. | EXPLOIT ✓HIGH 10.0EPSS 62.6% | 4 November 2013 |
| CVE-2013-4835 | The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765. | EXPLOIT ✓HIGH 7.5EPSS 71.0% | 4 November 2013 |
| CVE-2013-6114 | Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denial of service (application crash) via a (1) large or (2) small value in the subview attribute of a viewer element in a .motn file. | EXPLOITMEDIUM 5.0EPSS 4.90% | 4 November 2013 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.