Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,329 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 141 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-3969 | The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object. | EXPLOIT ✓MEDIUM 6.5EPSS 10.1% | 1 October 2013 |
| CVE-2013-1892 | MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute… | EXPLOIT ×2 ✓MEDIUM 6.0EPSS 44.5% | 1 October 2013 |
| CVE-2013-3963 | Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models allows remote attackers… | EXPLOIT ✓MEDIUM 6.8EPSS 0.92% | 1 October 2013 |
| CVE-2013-3690 | Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.1.0.8 and earlier, allows remote attackers to hijack the… | EXPLOIT ✓MEDIUM 6.8EPSS 12.4% | 1 October 2013 |
| CVE-2013-3539 | Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to… | EXPLOIT ✓MEDIUM 6.8EPSS 8.76% | 1 October 2013 |
| CVE-2013-5745 | The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication,… | EXPLOIT ✓HIGH 7.1EPSS 8.72% | 1 October 2013 |
| CVE-2012-5627 | Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to… | EXPLOIT ✓MEDIUM 4.0EPSS 11.4% | 1 October 2013 |
| CVE-2013-5572 | Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code. | EXPLOITLOW 3.5EPSS 4.11% | 1 October 2013 |
| CVE-2013-5693 | Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the model parameter to index.php/admin/editor. | EXPLOITMEDIUM 4.3EPSS 3.23% | 30 September 2013 |
| CVE-2013-5692 | Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. | EXPLOITHIGH 8.5EPSS 5.79% | 30 September 2013 |
| CVE-2013-4362 | WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) mount_davfs.c, related to the "system" function. | EXPLOIT ✓HIGH 7.2EPSS 1.17% | 30 September 2013 |
| CVE-2013-5962 | Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then… | EXPLOITMEDIUM 5.1EPSS 14.8% | 30 September 2013 |
| CVE-2013-5961 | Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/. | EXPLOIT ✓MEDIUM 6.8EPSS 5.45% | 30 September 2013 |
| CVE-2013-5697 | SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header. | EXPLOITHIGH 7.5EPSS 1.39% | 30 September 2013 |
| CVE-2013-2218 | Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (libvirtd crash) via a filtering flag that causes an interface to be… | EXPLOIT ✓MEDIUM 5.0EPSS 8.27% | 30 September 2013 |
| CVE-2013-2068 | Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a .. | EXPLOIT ✓HIGH 9.4EPSS 58.6% | 28 September 2013 |
| CVE-2013-5093 | The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object. | EXPLOIT ✓MEDIUM 6.8EPSS 38.7% | 27 September 2013 |
| CVE-2013-5575 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 26 September 2013 |
| CVE-2013-5118 | Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail message. | EXPLOITMEDIUM 4.3EPSS 2.42% | 25 September 2013 |
| CVE-2013-5917 | SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the comment_post_ID parameter. | EXPLOITHIGH 7.5EPSS 2.85% | 23 September 2013 |
| CVE-2013-5486 | Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka Bug IDs CSCue77035 and CSCue77036. | EXPLOIT ✓HIGH 10.0EPSS 76.0% | 23 September 2013 |
| CVE-2013-5696 | inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 7.85% | 23 September 2013 |
| CVE-2013-5147 | Passcode Lock in Apple iOS before 7 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging a race condition involving phone calls and ejection of a SIM card. | EXPLOITLOW 3.7EPSS 0.66% | 19 September 2013 |
| CVE-2013-3893 | Microsoft Internet Explorer Resource Management Errors Vulnerability | KEVEXPLOIT ×2 ✓HIGH 8.8EPSS 85.8% | 18 September 2013 |
| CVE-2013-1727 | Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a… | EXPLOIT ✓MEDIUM 4.0EPSS 5.19% | 18 September 2013 |
| CVE-2013-5633 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 17 September 2013 |
| CVE-2013-5632 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 17 September 2013 |
| CVE-2013-5631 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 17 September 2013 |
| CVE-2013-5630 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×2UnscoredEPSS — | 17 September 2013 |
| CVE-2013-5628 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 17 September 2013 |
| CVE-2013-5627 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×2UnscoredEPSS — | 17 September 2013 |
| CVE-2013-5625 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×2UnscoredEPSS — | 17 September 2013 |
| CVE-2013-5624 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×2UnscoredEPSS — | 17 September 2013 |
| CVE-2013-5623 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 17 September 2013 |
| CVE-2013-5622 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×2UnscoredEPSS — | 17 September 2013 |
| CVE-2013-5621 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×2UnscoredEPSS — | 17 September 2013 |
| CVE-2013-5620 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 17 September 2013 |
| CVE-2013-3615 | Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack. | EXPLOITHIGH 7.8EPSS 7.66% | 17 September 2013 |
| CVE-2013-3614 | Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force attack. | EXPLOITHIGH 9.3EPSS 7.01% | 17 September 2013 |
| CVE-2013-3613 | Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port. | EXPLOITHIGH 7.8EPSS 6.66% | 17 September 2013 |
| CVE-2013-3612 | Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a… | EXPLOITHIGH 10.0EPSS 10.3% | 17 September 2013 |
| CVE-2013-4123 | client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header. | EXPLOIT ✓MEDIUM 5.0EPSS 80.5% | 16 September 2013 |
| CVE-2013-4341 | Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed. | EXPLOITMEDIUM 4.3EPSS 21.9% | 16 September 2013 |
| CVE-2013-4812 | UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp… | EXPLOIT ✓HIGH 10.0EPSS 51.9% | 16 September 2013 |
| CVE-2013-4811 | UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload… | EXPLOIT ✓HIGH 10.0EPSS 71.3% | 16 September 2013 |
| CVE-2013-4810 | HP Multiple Products Remote Code Execution Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 79.5% | 16 September 2013 |
| CVE-2013-3205 | Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | EXPLOIT ✓HIGH 9.3EPSS 66.3% | 11 September 2013 |
| CVE-2013-3179 | Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability." | EXPLOITMEDIUM 4.3EPSS 14.2% | 11 September 2013 |
| CVE-2013-0810 | Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, and Windows Server 2008 SP2 allow remote attackers to execute arbitrary code via a crafted screensaver in a theme file, aka "Windows Theme File Remote Code Execution… | EXPLOIT ✓HIGH 8.1EPSS 59.9% | 11 September 2013 |
| CVE-2013-5673 | SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the custom_query parameter in a testimonial_add action to wp-admin/admin-ajax.php. | EXPLOITHIGH 7.5EPSS 6.54% | 10 September 2013 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.