SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,329 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 141 of 501

CVESummaryPriorityPublished
CVE-2013-3969The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.EXPLOITMEDIUM 6.5EPSS 10.1%1 October 2013
CVE-2013-1892MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute…EXPLOIT ×2MEDIUM 6.0EPSS 44.5%1 October 2013
CVE-2013-3963Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models allows remote attackers…EXPLOITMEDIUM 6.8EPSS 0.92%1 October 2013
CVE-2013-3690Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.1.0.8 and earlier, allows remote attackers to hijack the…EXPLOITMEDIUM 6.8EPSS 12.4%1 October 2013
CVE-2013-3539Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to…EXPLOITMEDIUM 6.8EPSS 8.76%1 October 2013
CVE-2013-5745The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication,…EXPLOITHIGH 7.1EPSS 8.72%1 October 2013
CVE-2012-5627Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to…EXPLOITMEDIUM 4.0EPSS 11.4%1 October 2013
CVE-2013-5572Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.EXPLOITLOW 3.5EPSS 4.11%1 October 2013
CVE-2013-5693Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the model parameter to index.php/admin/editor.EXPLOITMEDIUM 4.3EPSS 3.23%30 September 2013
CVE-2013-5692Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a ..EXPLOITHIGH 8.5EPSS 5.79%30 September 2013
CVE-2013-4362WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) mount_davfs.c, related to the "system" function.EXPLOITHIGH 7.2EPSS 1.17%30 September 2013
CVE-2013-5962Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then…EXPLOITMEDIUM 5.1EPSS 14.8%30 September 2013
CVE-2013-5961Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.EXPLOITMEDIUM 6.8EPSS 5.45%30 September 2013
CVE-2013-5697SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header.EXPLOITHIGH 7.5EPSS 1.39%30 September 2013
CVE-2013-2218Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (libvirtd crash) via a filtering flag that causes an interface to be…EXPLOITMEDIUM 5.0EPSS 8.27%30 September 2013
CVE-2013-2068Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a ..EXPLOITHIGH 9.4EPSS 58.6%28 September 2013
CVE-2013-5093The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.EXPLOITMEDIUM 6.8EPSS 38.7%27 September 2013
CVE-2013-5575Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —26 September 2013
CVE-2013-5118Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail message.EXPLOITMEDIUM 4.3EPSS 2.42%25 September 2013
CVE-2013-5917SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the comment_post_ID parameter.EXPLOITHIGH 7.5EPSS 2.85%23 September 2013
CVE-2013-5486Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka Bug IDs CSCue77035 and CSCue77036.EXPLOITHIGH 10.0EPSS 76.0%23 September 2013
CVE-2013-5696inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection…EXPLOIT ×2MEDIUM 6.8EPSS 7.85%23 September 2013
CVE-2013-5147Passcode Lock in Apple iOS before 7 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging a race condition involving phone calls and ejection of a SIM card.EXPLOITLOW 3.7EPSS 0.66%19 September 2013
CVE-2013-3893Microsoft Internet Explorer Resource Management Errors VulnerabilityKEVEXPLOIT ×2HIGH 8.8EPSS 85.8%18 September 2013
CVE-2013-1727Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a…EXPLOITMEDIUM 4.0EPSS 5.19%18 September 2013
CVE-2013-5633Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —17 September 2013
CVE-2013-5632Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —17 September 2013
CVE-2013-5631Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —17 September 2013
CVE-2013-5630Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ×2UnscoredEPSS —17 September 2013
CVE-2013-5628Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —17 September 2013
CVE-2013-5627Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ×2UnscoredEPSS —17 September 2013
CVE-2013-5625Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ×2UnscoredEPSS —17 September 2013
CVE-2013-5624Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ×2UnscoredEPSS —17 September 2013
CVE-2013-5623Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —17 September 2013
CVE-2013-5622Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ×2UnscoredEPSS —17 September 2013
CVE-2013-5621Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ×2UnscoredEPSS —17 September 2013
CVE-2013-5620Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —17 September 2013
CVE-2013-3615Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack.EXPLOITHIGH 7.8EPSS 7.66%17 September 2013
CVE-2013-3614Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force attack.EXPLOITHIGH 9.3EPSS 7.01%17 September 2013
CVE-2013-3613Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port.EXPLOITHIGH 7.8EPSS 6.66%17 September 2013
CVE-2013-3612Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a…EXPLOITHIGH 10.0EPSS 10.3%17 September 2013
CVE-2013-4123client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header.EXPLOITMEDIUM 5.0EPSS 80.5%16 September 2013
CVE-2013-4341Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.EXPLOITMEDIUM 4.3EPSS 21.9%16 September 2013
CVE-2013-4812UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp…EXPLOITHIGH 10.0EPSS 51.9%16 September 2013
CVE-2013-4811UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload…EXPLOITHIGH 10.0EPSS 71.3%16 September 2013
CVE-2013-4810HP Multiple Products Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 79.5%16 September 2013
CVE-2013-3205Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."EXPLOITHIGH 9.3EPSS 66.3%11 September 2013
CVE-2013-3179Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."EXPLOITMEDIUM 4.3EPSS 14.2%11 September 2013
CVE-2013-0810Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, and Windows Server 2008 SP2 allow remote attackers to execute arbitrary code via a crafted screensaver in a theme file, aka "Windows Theme File Remote Code Execution…EXPLOITHIGH 8.1EPSS 59.9%11 September 2013
CVE-2013-5673SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the custom_query parameter in a testimonial_add action to wp-admin/admin-ajax.php.EXPLOITHIGH 7.5EPSS 6.54%10 September 2013

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.