Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,388 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 145 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-3576 | ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands via shell metacharacters in the PATH_INFO to smhutil/snmpchp.php.en. | EXPLOIT ✓HIGH 9.0EPSS 66.6% | 14 June 2013 |
| CVE-2013-3575 | hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows remote attackers to include arbitrary hpdiags/frontend2/help/ .html files via the path parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 3.84% | 14 June 2013 |
| CVE-2013-3574 | Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathname in the argument to the devicePath (aka mount)… | EXPLOIT ✓HIGH 7.8EPSS 4.91% | 14 June 2013 |
| CVE-2013-3120 | Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | EXPLOIT ✓HIGH 9.3EPSS 31.6% | 12 June 2013 |
| CVE-2013-3111 | Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | EXPLOIT ✓HIGH 9.3EPSS 33.5% | 12 June 2013 |
| CVE-2013-4074 | The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause… | EXPLOIT ✓MEDIUM 5.0EPSS 60.6% | 9 June 2013 |
| CVE-2013-0143 | cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters… | EXPLOIT ✓MEDIUM 6.5EPSS 6.97% | 7 June 2013 |
| CVE-2013-2852 | Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including… | EXPLOIT ✓MEDIUM 6.9EPSS 1.02% | 7 June 2013 |
| CVE-2013-2333 | Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1680. | EXPLOIT ✓HIGH 10.0EPSS 89.8% | 6 June 2013 |
| CVE-2013-0984 | Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted message. | EXPLOIT ✓HIGH 9.3EPSS 14.4% | 5 June 2013 |
| CVE-2013-0136 | Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file… | EXPLOIT ✓HIGH 8.5EPSS 40.3% | 1 June 2013 |
| CVE-2013-3721 | SQL injection vulnerability in awards.php in PsychoStats 3.2.2b allows remote attackers to execute arbitrary SQL commands via the d parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.22% | 31 May 2013 |
| CVE-2013-3130 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×3 ✓UnscoredEPSS — | 30 May 2013 |
| CVE-2013-3661 | The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether… | EXPLOIT ×3 ✓MEDIUM 4.9EPSS 3.85% | 24 May 2013 |
| CVE-2013-3660 | Microsoft Win32k Privilege Escalation Vulnerability | KEVEXPLOIT ×3 ✓HIGH 7.8EPSS 39.3% | 24 May 2013 |
| CVE-2013-1017 | Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted dref atoms in a movie file. | EXPLOIT ✓HIGH 9.3EPSS 32.6% | 24 May 2013 |
| CVE-2011-4520 | Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page. | EXPLOIT ✓MEDIUM 4.3EPSS 2.37% | 23 May 2013 |
| CVE-2011-4519 | Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page. | EXPLOIT ✓MEDIUM 4.3EPSS 2.37% | 23 May 2013 |
| CVE-2011-4518 | Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors. | EXPLOIT ✓MEDIUM 5.0EPSS 26.4% | 23 May 2013 |
| CVE-2012-6560 | SQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands via the status parameter. | EXPLOITHIGH 7.5EPSS 1.13% | 23 May 2013 |
| CVE-2012-6559 | Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) mac, (3) graphtype, (4) name, or (5) type parameter to stats.php; or (6) comment parameter to… | EXPLOITMEDIUM 4.3EPSS 1.63% | 23 May 2013 |
| CVE-2012-6557 | Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) AboutMe/RealName, (2) AboutMe/Name, (3) AboutMe/Quote, (4) AboutMe/Loc, (5)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.63% | 23 May 2013 |
| CVE-2012-6556 | Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) User/FirstName or (2) User/LastName parameter to the edit user page. | EXPLOIT ✓MEDIUM 4.3EPSS 1.71% | 23 May 2013 |
| CVE-2012-6555 | Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or HTML via the discussion title. | EXPLOIT ✓MEDIUM 4.3EPSS 2.07% | 23 May 2013 |
| CVE-2012-6554 | functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the message[message_text] parameter to chat/add_messag, which is not properly handled when executing the… | EXPLOIT ✓MEDIUM 6.5EPSS 16.7% | 23 May 2013 |
| CVE-2013-2842 | Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of widgets. | EXPLOITHIGH 7.5EPSS 12.0% | 22 May 2013 |
| CVE-2013-0145 | Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in a read request. | EXPLOIT ✓MEDIUM 5.0EPSS 8.87% | 20 May 2013 |
| CVE-2013-2730 | Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2733. | EXPLOIT ✓HIGH 10.0EPSS 78.8% | 16 May 2013 |
| CVE-2013-2729 | Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 66.6% | 16 May 2013 |
| CVE-2013-1670 | The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content… | EXPLOIT ✓MEDIUM 4.3EPSS 10.9% | 16 May 2013 |
| CVE-2013-1311 | Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability." | EXPLOIT ✓HIGH 9.3EPSS 20.7% | 15 May 2013 |
| CVE-2013-1309 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different… | EXPLOIT ✓HIGH 9.3EPSS 39.1% | 15 May 2013 |
| CVE-2013-1306 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different… | EXPLOIT ✓HIGH 9.3EPSS 33.4% | 15 May 2013 |
| CVE-2013-2094 | Linux Kernel Privilege Escalation Vulnerability | KEVEXPLOIT ×3 ✓HIGH 8.4EPSS 47.7% | 14 May 2013 |
| CVE-2013-3538 | Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id_post or (2) pg parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.25% | 13 May 2013 |
| CVE-2013-3537 | Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_post or (2) pg parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.22% | 13 May 2013 |
| CVE-2013-3536 | SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and earlier for WHMCS allows remote attackers to execute arbitrary SQL commands via the hash parameter. | EXPLOITHIGH 7.5EPSS 2.24% | 13 May 2013 |
| CVE-2013-3535 | Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_email, (2) header_title, (3) site_title parameter to admin/settings; (4) recaptcha_private or… | EXPLOITMEDIUM 4.3EPSS 4.18% | 13 May 2013 |
| CVE-2013-3532 | SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter. | EXPLOIT ✓HIGH 7.5EPSS 5.39% | 10 May 2013 |
| CVE-2013-3531 | SQL injection vulnerability in meneger.php in RadioCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the playlist_id parameter. | EXPLOITHIGH 7.5EPSS 2.22% | 10 May 2013 |
| CVE-2013-3530 | SQL injection vulnerability in playlist.php in the Spiffy XSPF Player plugin 0.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the playlist_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.64% | 10 May 2013 |
| CVE-2013-3529 | Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) photo-message, or (3) youtube-message… | EXPLOITMEDIUM 4.3EPSS 4.58% | 10 May 2013 |
| CVE-2013-3528 | Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection." | EXPLOIT ✓HIGH 7.5EPSS 5.67% | 10 May 2013 |
| CVE-2013-3527 | Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordrequest. | EXPLOITHIGH 7.5EPSS 3.51% | 10 May 2013 |
| CVE-2013-3526 | Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the aoid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 13.9% | 10 May 2013 |
| CVE-2013-3525 | SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.81% | 10 May 2013 |
| CVE-2013-3524 | SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remote attackers to execute arbitrary SQL commands via the itemid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.57% | 10 May 2013 |
| CVE-2013-3522 | SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter. | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 27.1% | 10 May 2013 |
| CVE-2013-0946 | Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to execute arbitrary code via crafted commands. | EXPLOITHIGH 9.3EPSS 28.5% | 10 May 2013 |
| CVE-2013-3336 | Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors. | EXPLOITMEDIUM 5.0EPSS 74.3% | 9 May 2013 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.