Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,388 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 142 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-5672 | Multiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add a testimonial via an iNIC_testimonial_save… | EXPLOITMEDIUM 6.8EPSS 3.15% | 10 September 2013 |
| CVE-2013-3934 | Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers to execute arbitrary code via a long font name in a WPS file. | EXPLOIT ✓HIGH 9.3EPSS 9.75% | 10 September 2013 |
| CVE-2013-4984 | The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument. | EXPLOIT ×2 ✓HIGH 7.2EPSS 8.13% | 10 September 2013 |
| CVE-2013-4983 | The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to end-user/index.php. | EXPLOIT ×2 ✓HIGH 10.0EPSS 90.1% | 10 September 2013 |
| CVE-2013-5716 | Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file. | EXPLOIT ✓MEDIUM 4.3EPSS 2.07% | 9 September 2013 |
| CVE-2013-4900 | Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote attackers to read arbitrary files via a ..%5c (dot dot encoded backslash) in a GET request. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.95% | 9 September 2013 |
| CVE-2013-1651 | OXUpdater in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof update servers and install arbitrary software via a… | EXPLOITMEDIUM 5.8EPSS 0.99% | 5 September 2013 |
| CVE-2013-1650 | Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses weak permissions (group "other" readable) under opt/open-xchange/etc/, which allows local users to obtain sensitive information via standard filesystem operations. | EXPLOITLOW 2.1EPSS 0.76% | 5 September 2013 |
| CVE-2013-1649 | Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithms for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack. | EXPLOITMEDIUM 4.3EPSS 1.89% | 5 September 2013 |
| CVE-2013-1648 | The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic… | EXPLOITLOW 3.5EPSS 1.33% | 5 September 2013 |
| CVE-2013-1647 | Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter,… | EXPLOITMEDIUM 5.0EPSS 1.72% | 5 September 2013 |
| CVE-2013-1646 | Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary web script or HTML via (1) invalid JSON data in a mail-sending POST… | EXPLOITMEDIUM 4.3EPSS 1.33% | 5 September 2013 |
| CVE-2013-1645 | Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated users to read arbitrary files via a .. | EXPLOITMEDIUM 4.0EPSS 2.82% | 5 September 2013 |
| CVE-2013-3346 | Adobe Reader and Acrobat Memory Corruption Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 78.9% | 30 August 2013 |
| CVE-2013-3597 | servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords via a getList action. | EXPLOIT ✓MEDIUM 5.0EPSS 8.48% | 28 August 2013 |
| CVE-2013-3586 | Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie. | EXPLOITHIGH 7.6EPSS 11.2% | 28 August 2013 |
| CVE-2013-3585 | Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup web page. | EXPLOITMEDIUM 5.0EPSS 23.5% | 28 August 2013 |
| CVE-2013-4266 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 27 August 2013 |
| CVE-2013-5578 | Buffer overflow in the ToDot method in the WINGRAPHVIZLib.NEATO ActiveX control in WinGraphviz.dll in StarUML allows remote attackers to execute arbitrary code via a long argument. | EXPLOITHIGH 9.3EPSS 4.90% | 25 August 2013 |
| CVE-2012-6589 | Cross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbitrary web script or HTML via the look parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.32% | 25 August 2013 |
| CVE-2012-6588 | SQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 25 August 2013 |
| CVE-2012-6587 | Cross-site scripting (XSS) vulnerability in vacation/1_mobile/alert_members.php in MYRE Vacation Rental Software allows remote attackers to inject arbitrary web script or HTML via the link_idd parameter in a login action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.35% | 25 August 2013 |
| CVE-2012-6586 | Multiple SQL injection vulnerabilities in MYRE Vacation Rental Software allow remote attackers to execute arbitrary SQL commands via the (1) garage1 or (2) bathrooms1 parameter to vacation/1_mobile/search.php, or (3) unspecified input to… | EXPLOIT ✓HIGH 7.5EPSS 1.07% | 25 August 2013 |
| CVE-2012-6585 | Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.32% | 25 August 2013 |
| CVE-2012-6584 | Multiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands via the bathrooms1 parameter to (1) demo2/search.php or (2) search.php. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 25 August 2013 |
| CVE-2010-5289 | Buffer overflow in the Authenticate method in the INCREDISPOOLERLib.Pop ActiveX control in ImSpoolU.dll in IncrediMail 2.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long… | EXPLOIT ✓HIGH 7.5EPSS 2.38% | 25 August 2013 |
| CVE-2013-1662 | vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen… | EXPLOIT ×2 ✓MEDIUM 6.9EPSS 4.64% | 24 August 2013 |
| CVE-2013-2299 | Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | EXPLOITLOW 3.5EPSS 1.44% | 22 August 2013 |
| CVE-2013-0526 | ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2)… | EXPLOITHIGH 8.5EPSS 6.07% | 21 August 2013 |
| CVE-2013-5321 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2)… | EXPLOITHIGH 7.5EPSS 1.37% | 20 August 2013 |
| CVE-2013-5318 | SQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.21% | 20 August 2013 |
| CVE-2013-5317 | Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the mode parameter to cms/index.php. | EXPLOITLOW 3.5EPSS 2.64% | 20 August 2013 |
| CVE-2013-5316 | Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via an edit user action to cms/index.php. | EXPLOITMEDIUM 6.8EPSS 2.27% | 20 August 2013 |
| CVE-2013-2160 | The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes,… | EXPLOIT ✓MEDIUM 5.0EPSS 32.3% | 19 August 2013 |
| CVE-2013-5314 | Cross-site scripting (XSS) vulnerability in serendipity_admin_image_selector.php in Serendipity 1.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the serendipity[htmltarget] parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.61% | 19 August 2013 |
| CVE-2013-5312 | Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to browse_videos.php or the (2) cat parameter to groups.php. | EXPLOIT ✓MEDIUM 4.3EPSS 3.22% | 19 August 2013 |
| CVE-2013-5311 | Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL commands via the "n" parameter to (1) browse_videos.php or (2) members.php. | EXPLOIT ✓HIGH 7.5EPSS 2.22% | 19 August 2013 |
| CVE-2013-4881 | Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to hijack the authentication of administrators for requests that create an administrative user via an add… | EXPLOIT ✓MEDIUM 6.8EPSS 2.20% | 19 August 2013 |
| CVE-2013-1942 | Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.20, as used in ownCloud Server before 5.0.4 and other products, allow remote attackers to inject arbitrary web… | EXPLOIT ✓MEDIUM 4.3EPSS 5.49% | 15 August 2013 |
| CVE-2013-5121 | SQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands via the search[sort_by] parameter to user/browse/view_/. | EXPLOITHIGH 7.5EPSS 1.15% | 14 August 2013 |
| CVE-2013-5120 | SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the search[gender] parameter to user/browse/view_/. | EXPLOITHIGH 7.5EPSS 1.15% | 14 August 2013 |
| CVE-2013-4880 | Cross-site scripting (XSS) vulnerability in core/admin/modules/developer/modules/views/add.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via the module parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.29% | 14 August 2013 |
| CVE-2013-4879 | SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.28% | 14 August 2013 |
| CVE-2013-3184 | Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | EXPLOIT ✓HIGH 9.3EPSS 58.4% | 14 August 2013 |
| CVE-2013-5099 | Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. | EXPLOIT ✓LOW 2.6EPSS 1.71% | 9 August 2013 |
| CVE-2013-4789 | SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via the "c" parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 9 August 2013 |
| CVE-2013-4759 | Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 for Magnolia CMS allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) fullname, or (3) email… | EXPLOIT ✓MEDIUM 4.3EPSS 3.53% | 9 August 2013 |
| CVE-2013-4625 | Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 11.1% | 9 August 2013 |
| CVE-2013-4620 | Cross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the note parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.28% | 9 August 2013 |
| CVE-2013-4147 | Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in a request in the (1)… | EXPLOIT ✓HIGH 7.5EPSS 3.69% | 9 August 2013 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.