Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,407 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 148 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-0874 | The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require… | EXPLOITMEDIUM 6.8EPSS 15.6% | 5 February 2013 |
| CVE-2011-1350 | The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an application that uses a crafted length parameter in a request to the pvrsrvkm device. | EXPLOIT ✓HIGH 7.1EPSS 1.11% | 5 February 2013 |
| CVE-2013-1471 | Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the… | EXPLOITMEDIUM 4.3EPSS 2.02% | 4 February 2013 |
| CVE-2013-0230 | Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method. | EXPLOIT ×3 ✓HIGH 10.0EPSS 69.2% | 31 January 2013 |
| CVE-2013-0229 | The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read. | EXPLOIT ×2 ✓HIGH 7.8EPSS 76.4% | 31 January 2013 |
| CVE-2012-5965 | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) 1.3.1 allows remote attackers to execute arbitrary code… | EXPLOIT ✓HIGH 10.0EPSS 36.9% | 31 January 2013 |
| CVE-2012-5964 | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) 1.3.1 allows remote attackers to execute arbitrary code… | EXPLOIT ✓HIGH 10.0EPSS 36.9% | 31 January 2013 |
| CVE-2012-5963 | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) 1.3.1 allows remote attackers to execute arbitrary code… | EXPLOIT ✓HIGH 10.0EPSS 36.9% | 31 January 2013 |
| CVE-2012-5962 | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) 1.3.1 allows remote attackers to execute arbitrary code… | EXPLOIT ✓HIGH 10.0EPSS 36.9% | 31 January 2013 |
| CVE-2012-5961 | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) 1.3.1 allows remote attackers to execute arbitrary code… | EXPLOIT ✓HIGH 10.0EPSS 36.9% | 31 January 2013 |
| CVE-2012-5960 | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute… | EXPLOIT ✓HIGH 10.0EPSS 32.6% | 31 January 2013 |
| CVE-2012-5959 | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute… | EXPLOIT ✓HIGH 10.0EPSS 75.8% | 31 January 2013 |
| CVE-2012-5958 | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute… | EXPLOIT ×2 ✓HIGH 10.0EPSS 83.2% | 31 January 2013 |
| CVE-2013-0431 | Oracle JRE Sandbox Bypass Vulnerability | KEVEXPLOIT ✓MEDIUM 5.3EPSS 90.3% | 31 January 2013 |
| CVE-2012-6530 | Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create folder permission to execute arbitrary code via a crafted request. | EXPLOIT ×2HIGH 7.1EPSS 46.1% | 31 January 2013 |
| CVE-2012-6529 | Multiple SQL injection vulnerabilities in Marinet CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) galleryphoto.php or (2) gallery.php; or the roomid parameter to (3) room.php or (4) room2.php. | EXPLOIT ×3 ✓HIGH 7.5EPSS 1.11% | 31 January 2013 |
| CVE-2012-6528 | Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) themes/default/tile_search/index.tmpl.php, (2) login.php, (3) search.php, (4)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.85% | 31 January 2013 |
| CVE-2012-6526 | SQL injection vulnerability in show_code.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the code_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 31 January 2013 |
| CVE-2012-6525 | SQL injection vulnerability in members.php in PHPBridges allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 31 January 2013 |
| CVE-2012-6524 | SQL injection vulnerability in kommentar.php in pGB 2.12 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 31 January 2013 |
| CVE-2012-6523 | Multiple cross-site scripting (XSS) vulnerabilities in w-CMS 2.01 allow remote attackers to inject arbitrary web script or HTML via (1) the p parameter in the getMenus function in codes/wcms.php; or the COMMENT parameter in (2) blog.php, (3)… | EXPLOITMEDIUM 4.3EPSS 1.88% | 31 January 2013 |
| CVE-2012-6522 | Directory traversal vulnerability in the getContent function in codes/wcms.php in w-CMS 2.01 allows remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 4.04% | 31 January 2013 |
| CVE-2010-5287 | SQL injection vulnerability in default.php in Cornerstone Technologies webConductor allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 31 January 2013 |
| CVE-2013-0333 | lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL… | EXPLOIT ✓HIGH 7.5EPSS 95.3% | 30 January 2013 |
| CVE-2013-1451 | Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not ensure that the SSL lock icon is consistent with the Address bar, which makes it easier for… | EXPLOITMEDIUM 4.0EPSS 20.4% | 29 January 2013 |
| CVE-2012-4914 | Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a PDF document with a crafted stream. | EXPLOIT ×2 ✓HIGH 9.3EPSS 28.4% | 26 January 2013 |
| CVE-2012-6276 | Directory traversal vulnerability in the web-based management interface on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via the URL parameter. | EXPLOITMEDIUM 4.3EPSS 3.54% | 26 January 2013 |
| CVE-2012-6272 | Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote attackers to inject arbitrary web script or HTML via the topic parameter to html/index_main.htm in (1)… | EXPLOIT ✓MEDIUM 4.3EPSS 2.81% | 25 January 2013 |
| CVE-2012-6520 | Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.27% | 24 January 2013 |
| CVE-2012-6519 | SQL injection vulnerability in modules/poll/index.php in DIY-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter to mod.php. | EXPLOIT ✓HIGH 7.5EPSS 1.71% | 24 January 2013 |
| CVE-2012-6518 | Cross-site request forgery (CSRF) vulnerability in mod.php in DiY-CMS 1.0 allows remote attackers to hijack the authentication of administrators for requests that create a poll via an add action to the poll module. | EXPLOIT ✓MEDIUM 6.8EPSS 1.30% | 24 January 2013 |
| CVE-2012-6517 | Multiple cross-site scripting (XSS) vulnerabilities in DiY-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) question parameter to in /modules/poll/add.php or (2) question or (3) answer parameter to modules/poll/edit.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.85% | 24 January 2013 |
| CVE-2012-6516 | SQL injection vulnerability in PHP Ticket System Beta 1 allows remote attackers to execute arbitrary SQL commands via the q parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 24 January 2013 |
| CVE-2012-6513 | Cross-site scripting (XSS) vulnerability in index.php/Admin_Preferences in gpEasy CMS 2.3.3 allows remote attackers to inject arbitrary web script or HTML via the jsoncallback parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.61% | 24 January 2013 |
| CVE-2012-6510 | Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PWRS or (2) Description field when posting a new vehicle; (3) news title when creating news; (4)… | EXPLOITMEDIUM 4.3EPSS 1.64% | 24 January 2013 |
| CVE-2012-6509 | Unrestricted file upload vulnerability in NetArt Media Car Portal 3.0 allows remote attackers to execute arbitrary PHP code by uploading a file a double extension, as demonstrated by .php%00.jpg. | EXPLOITHIGH 7.5EPSS 6.80% | 24 January 2013 |
| CVE-2012-6508 | Multiple cross-site request forgery (CSRF) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change arbitrary user passwords via a nouveau action in the security… | EXPLOITMEDIUM 6.8EPSS 1.09% | 24 January 2013 |
| CVE-2012-6506 | Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in zing.inc.php or (2) notes parameter in… | EXPLOIT ✓MEDIUM 4.3EPSS 5.31% | 24 January 2013 |
| CVE-2012-6505 | Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.24% | 24 January 2013 |
| CVE-2012-6504 | SQL injection vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 24 January 2013 |
| CVE-2012-2099 | Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) search field, or the (2) Author or (3) select_sort parameters in an advanced search. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.53% | 24 January 2013 |
| CVE-2012-1922 | Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the authentication of administrators for requests that modify settings for (1) Mac Filtering via admin/formFilter, (2) IP/Port Filtering via… | EXPLOIT ×2MEDIUM 6.8EPSS 1.39% | 24 January 2013 |
| CVE-2011-4618 | Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 10.1% | 24 January 2013 |
| CVE-2013-0209 | lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted… | EXPLOIT ✓HIGH 7.5EPSS 45.2% | 23 January 2013 |
| CVE-2012-6315 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 23 January 2013 |
| CVE-2012-6096 | Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long… | EXPLOIT ×2 ✓HIGH 7.5EPSS 66.5% | 22 January 2013 |
| CVE-2013-0928 | The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitrary commands via a DCP "run command" operation. | EXPLOIT ✓HIGH 9.3EPSS 34.3% | 21 January 2013 |
| CVE-2013-0657 | Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol. | EXPLOIT ×2 ✓HIGH 10.0EPSS 21.3% | 21 January 2013 |
| CVE-2009-5134 | Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), allows user-assisted remote attackers to cause a denial of service (application crash) and possibly… | EXPLOIT ✓MEDIUM 6.8EPSS 7.71% | 18 January 2013 |
| CVE-2012-5875 | Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1) crafted Connection HTTP header; a return carriage control character in the (2) Accept Language header, (3) User-agent header, (4)… | EXPLOITMEDIUM 5.0EPSS 10.8% | 18 January 2013 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.