Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,388 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 143 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-2577 | Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file. | EXPLOIT ✓HIGH 9.3EPSS 11.8% | 9 August 2013 |
| CVE-2013-2576 | Buffer overflow in Artweaver before 3.1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AWD file. | EXPLOIT ✓MEDIUM 6.8EPSS 9.56% | 9 August 2013 |
| CVE-2013-1710 | The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to execute arbitrary JavaScript code… | EXPLOIT ✓HIGH 10.0EPSS 40.1% | 7 August 2013 |
| CVE-2013-4124 | Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet. | EXPLOITMEDIUM 5.0EPSS 69.0% | 6 August 2013 |
| CVE-2013-4679 | Symantec Workspace Virtualization before 6.x before 6.4.1953.0, when a virtual application layer is configured, allows local users to gain privileges via an application that performs crafted interaction with the operating system. | EXPLOITMEDIUM 6.6EPSS 1.00% | 5 August 2013 |
| CVE-2013-3724 | The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service outage) via a '\0' character in an HTTP request. | EXPLOITMEDIUM 5.0EPSS 13.7% | 1 August 2013 |
| CVE-2013-1616 | The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbitrary commands by injecting a command into an application script. | EXPLOIT ✓HIGH 8.3EPSS 10.7% | 1 August 2013 |
| CVE-2013-5020 | Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_name, (2) forum_group, (3) forum_icon, or (4) forum_desc parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.86% | 31 July 2013 |
| CVE-2013-5019 | Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resource name in an HTTP request. | EXPLOIT ×5 ✓HIGH 10.0EPSS 63.6% | 31 July 2013 |
| CVE-2013-3956 | The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows Server 2008; and Novell Client 2 SP3 on Windows Server 2008 R2, Windows 7, Windows 8, and Windows… | EXPLOIT ×2 ✓HIGH 7.2EPSS 7.80% | 31 July 2013 |
| CVE-2013-2121 | Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute. | EXPLOIT ✓MEDIUM 6.0EPSS 24.8% | 31 July 2013 |
| CVE-2013-2113 | The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role. | EXPLOIT ✓MEDIUM 6.0EPSS 20.9% | 31 July 2013 |
| CVE-2013-2088 | contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename. | EXPLOITHIGH 7.1EPSS 31.5% | 31 July 2013 |
| CVE-2013-5006 | main_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C with firmware 1.05.12, 1.06.18, and 1.06.28, allows remote attackers to discover the cleartext administrative password by reading the… | EXPLOITMEDIUM 4.3EPSS 4.55% | 31 July 2013 |
| CVE-2013-2367 | Multiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1678. | EXPLOIT ✓HIGH 10.0EPSS 68.9% | 31 July 2013 |
| CVE-2013-4954 | Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary… | EXPLOIT ✓LOW 2.6EPSS 6.15% | 29 July 2013 |
| CVE-2013-4953 | SQL injection vulnerability in play.php in Top Games Script 1.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 29 July 2013 |
| CVE-2013-4952 | SQL injection vulnerability in functions/global.php in Elemata CMS RC 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOITHIGH 7.5EPSS 1.04% | 29 July 2013 |
| CVE-2013-4951 | Multiple cross-site scripting (XSS) vulnerabilities in Mintboard 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) pass parameter in views/login.php or (3) name or (4) pass parameter in views/signup.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.64% | 29 July 2013 |
| CVE-2013-4950 | Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the element_2 parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.89% | 29 July 2013 |
| CVE-2013-4949 | Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in the upload form's directory in data/. | EXPLOIT ✓MEDIUM 6.8EPSS 5.45% | 29 July 2013 |
| CVE-2013-4948 | SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.46% | 29 July 2013 |
| CVE-2013-4946 | Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script or HTML via the (1) SelTab parameter to QV_admin.aspx, the (2) CallBack parameter to QV_grid.aspx, or… | EXPLOITMEDIUM 4.3EPSS 1.61% | 29 July 2013 |
| CVE-2013-4945 | Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ, (2) TABLE_WIDGET_1, (3) TABLE_WIDGET_2, (4) browserDateTimeInfo, or (5)… | EXPLOITHIGH 7.5EPSS 1.11% | 29 July 2013 |
| CVE-2013-3515 | Multiple cross-site scripting (XSS) vulnerabilities in OpenX Source 2.8.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) package parameter to www/admin/plugin-index.php or the (2) group parameter to… | EXPLOITMEDIUM 4.3EPSS 4.23% | 29 July 2013 |
| CVE-2013-4800 | Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1735. | EXPLOIT ✓HIGH 9.3EPSS 39.3% | 29 July 2013 |
| CVE-2013-4798 | Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1705. | EXPLOIT ✓HIGH 10.0EPSS 67.0% | 29 July 2013 |
| CVE-2013-2370 | Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1671. | EXPLOIT ✓HIGH 7.5EPSS 61.9% | 29 July 2013 |
| CVE-2013-4015 | Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute… | EXPLOIT ✓MEDIUM 6.9EPSS 2.81% | 26 July 2013 |
| CVE-2013-3431 | Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to… | EXPLOITHIGH 7.8EPSS 9.26% | 25 July 2013 |
| CVE-2013-3430 | Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288. | EXPLOITHIGH 9.0EPSS 8.27% | 25 July 2013 |
| CVE-2013-3429 | Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a crafted URL, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37163. | EXPLOITHIGH 7.8EPSS 10.2% | 25 July 2013 |
| CVE-2013-4890 | The DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon crash) via a long URI to TCP port 5600. | EXPLOITHIGH 7.8EPSS 2.60% | 23 July 2013 |
| CVE-2013-4883 | Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA) 4.5 through 4.6, allow remote attackers to inject arbitrary web script or HTML via the (1) instanceId… | EXPLOITMEDIUM 4.3EPSS 5.07% | 22 July 2013 |
| CVE-2013-4882 | Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent (MA) 4.5 and 4.6, allow remote authenticated users to execute arbitrary SQL commands via the uid… | EXPLOITMEDIUM 6.5EPSS 3.91% | 22 July 2013 |
| CVE-2013-2251 | Apache Struts Improper Input Validation Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 100.0% | 20 July 2013 |
| CVE-2013-2248 | Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix. | EXPLOIT ✓MEDIUM 5.8EPSS 94.7% | 20 July 2013 |
| CVE-2013-2028 | The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which… | EXPLOIT ×4 ✓HIGH 7.5EPSS 87.5% | 20 July 2013 |
| CVE-2012-3414 | Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the… | EXPLOIT ✓MEDIUM 4.3EPSS 9.09% | 19 July 2013 |
| CVE-2013-4878 | The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted… | EXPLOIT ✓HIGH 7.5EPSS 31.1% | 18 July 2013 |
| CVE-2013-4011 | Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat. | EXPLOIT ×2 ✓HIGH 7.2EPSS 2.85% | 18 July 2013 |
| CVE-2013-1606 | Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allows remote attackers to execute arbitrary code via a long rtsp: URI in a DESCRIBE request. | EXPLOIT ✓HIGH 7.5EPSS 23.4% | 18 July 2013 |
| CVE-2013-3803 | Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.129 and earlier, and 11.1.2.2.305 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related… | EXPLOIT ✓LOW 3.5EPSS 6.43% | 17 July 2013 |
| CVE-2013-3763 | Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2013-3764. | EXPLOIT ✓MEDIUM 5.5EPSS 59.8% | 17 July 2013 |
| CVE-2013-2134 | Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135. | EXPLOIT ✓HIGH 9.3EPSS 70.2% | 16 July 2013 |
| CVE-2013-4117 | Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ID parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 13.0% | 16 July 2013 |
| CVE-2013-2765 | The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header. | EXPLOITMEDIUM 5.0EPSS 13.7% | 15 July 2013 |
| CVE-2013-2784 | Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bounds checking of data in Modbus/TCP packets, which allows remote attackers to cause a denial of service (networking outage) via a… | EXPLOITHIGH 7.8EPSS 4.04% | 10 July 2013 |
| CVE-2013-2115 | Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. | EXPLOIT ✓HIGH 8.1EPSS 74.6% | 10 July 2013 |
| CVE-2013-1966 | Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. | EXPLOIT ✓HIGH 9.3EPSS 73.7% | 10 July 2013 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.