SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 31 of 501

CVESummaryPriorityPublished
CVE-2014-4170A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.EXPLOITCRITICAL 9.8EPSS 14.5%13 February 2020
CVE-2012-1500Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.EXPLOITMEDIUM 5.4EPSS 1.12%13 February 2020
CVE-2020-7209LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.EXPLOITCRITICAL 9.8EPSS 98.8%13 February 2020
CVE-2019-18915A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33.EXPLOITHIGH 7.8EPSS 1.48%13 February 2020
CVE-2011-4908TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.EXPLOIT ×2CRITICAL 9.8EPSS 55.8%12 February 2020
CVE-2011-4906Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.EXPLOITCRITICAL 9.8EPSS 9.58%12 February 2020
CVE-2011-3336regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.EXPLOITHIGH 7.5EPSS 6.49%12 February 2020
CVE-2020-8947functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than…EXPLOITHIGH 7.2EPSS 22.5%12 February 2020
CVE-2013-2637A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.EXPLOITMEDIUM 6.1EPSS 4.30%12 February 2020
CVE-2013-6236IZON IP 2.0.2: hard-coded password vulnerabilityEXPLOITCRITICAL 9.8EPSS 10.2%12 February 2020
CVE-2013-2097ZPanel through 10.1.0 has Remote Command ExecutionEXPLOIT ×2HIGH 7.8EPSS 26.0%12 February 2020
CVE-2013-1938Zimbra 2013 has XSS in aspell.phpEXPLOITMEDIUM 6.1EPSS 3.25%12 February 2020
CVE-2020-8839Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.EXPLOITMEDIUM 6.1EPSS 2.07%12 February 2020
CVE-2015-7890Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter.EXPLOITMEDIUM 5.5EPSS 1.29%12 February 2020
CVE-2013-2010WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution VulnerabilityEXPLOITCRITICAL 9.8EPSS 73.9%12 February 2020
CVE-2013-1410Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilitiesEXPLOITMEDIUM 6.1EPSS 1.50%12 February 2020
CVE-2014-2560The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.EXPLOITHIGH 7.5EPSS 1.68%12 February 2020
CVE-2014-4968The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for Android allow remote attackers to execute arbitrary code via a crafted web site, a related issue to CVE-2012-6636.EXPLOITHIGH 8.8EPSS 6.23%12 February 2020
CVE-2014-2595Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.EXPLOITCRITICAL 9.8EPSS 16.9%12 February 2020
CVE-2020-0688Microsoft Exchange Server Validation Key Remote Code Execution VulnerabilityKEVEXPLOIT ×2HIGH 8.8EPSS 100.0%11 February 2020
CVE-2020-0683Microsoft Windows Installer Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 7.61%11 February 2020
CVE-2020-0674Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityKEVEXPLOIT ×2HIGH 7.5EPSS 86.9%11 February 2020
CVE-2020-0618Microsoft SQL Server Reporting Services Remote Code Execution VulnerabilityKEVEXPLOITHIGH 8.8EPSS 99.0%11 February 2020
CVE-2012-2517Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.EXPLOITMEDIUM 6.1EPSS 1.89%11 February 2020
CVE-2012-2452Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to modules.php or (2) img_url to…EXPLOIT ×2MEDIUM 6.1EPSS 1.70%11 February 2020
CVE-2012-2216Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —11 February 2020
CVE-2012-1124SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.EXPLOITCRITICAL 9.8EPSS 4.27%11 February 2020
CVE-2013-5582Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file.EXPLOITHIGH 7.8EPSS 3.64%11 February 2020
CVE-2009-4067Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attackers to execute arbitrary code, cause a denial of service via a crafted USB device, or take full…EXPLOITMEDIUM 6.8EPSS 2.06%11 February 2020
CVE-2014-7969Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —11 February 2020
CVE-2013-3684NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file uploadEXPLOITCRITICAL 9.8EPSS 19.2%11 February 2020
CVE-2013-1359An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the…EXPLOIT ×2CRITICAL 9.8EPSS 89.4%11 February 2020
CVE-2013-0803A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.EXPLOITCRITICAL 9.8EPSS 75.0%11 February 2020
CVE-2013-1360An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the…EXPLOITCRITICAL 9.8EPSS 23.2%11 February 2020
CVE-2014-8347An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges.EXPLOITHIGH 7.8EPSS 1.35%11 February 2020
CVE-2013-5945Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77…EXPLOITCRITICAL 9.8EPSS 9.78%11 February 2020
CVE-2013-2108WordPress WP Cleanfix Plugin 2.4.4 has CSRFEXPLOITMEDIUM 5.4EPSS 2.19%10 February 2020
CVE-2014-5086A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code.EXPLOITHIGH 8.8EPSS 9.78%10 February 2020
CVE-2014-5085A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code.EXPLOITHIGH 8.8EPSS 5.80%10 February 2020
CVE-2014-5084A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execute arbitrary code.EXPLOITHIGH 8.8EPSS 7.74%10 February 2020
CVE-2014-5083A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code.EXPLOITHIGH 8.8EPSS 5.80%10 February 2020
CVE-2020-8825index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.EXPLOITMEDIUM 5.4EPSS 1.88%10 February 2020
CVE-2012-4512The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."EXPLOITHIGH 8.8EPSS 11.7%8 February 2020
CVE-2014-8739Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1…EXPLOIT ×2CRITICAL 9.8EPSS 91.7%8 February 2020
CVE-2014-7863The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and…EXPLOITHIGH 7.5EPSS 83.4%8 February 2020
CVE-2014-2225Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to…EXPLOITHIGH 8.8EPSS 1.28%8 February 2020
CVE-2011-3642Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in…EXPLOITCRITICAL 9.6EPSS 8.75%8 February 2020
CVE-2014-5091A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.EXPLOITCRITICAL 9.8EPSS 15.2%7 February 2020
CVE-2014-5087A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.EXPLOITCRITICAL 9.8EPSS 7.18%7 February 2020
CVE-2014-5468A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.EXPLOITHIGH 8.8EPSS 52.6%7 February 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.