SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,662 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 32 of 501

CVESummaryPriorityPublished
CVE-2014-5288A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.EXPLOITHIGH 8.8EPSS 1.57%7 February 2020
CVE-2013-3629ISPConfig 3.0.5.2 has Arbitrary PHP Code ExecutionEXPLOITHIGH 8.8EPSS 43.1%7 February 2020
CVE-2013-3628Zabbix 2.0.9 has an Arbitrary Command Execution VulnerabilityEXPLOITHIGH 8.8EPSS 67.5%7 February 2020
CVE-2013-3591vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution VulnerabilityEXPLOITHIGH 8.8EPSS 43.1%7 February 2020
CVE-2013-2009WordPress WP Super Cache Plugin 1.2 has Remote PHP Code ExecutionEXPLOITHIGH 8.8EPSS 13.0%7 February 2020
CVE-2013-0192File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.EXPLOITMEDIUM 4.9EPSS 3.76%7 February 2020
CVE-2020-8656The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.EXPLOIT ×2CRITICAL 9.8EPSS 84.6%7 February 2020
CVE-2020-8655EyesOfNetwork Improper Privilege Management VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 60.1%7 February 2020
CVE-2020-8654An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.EXPLOIT ×2HIGH 8.8EPSS 91.2%7 February 2020
CVE-2013-3568Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.EXPLOITHIGH 8.8EPSS 25.1%6 February 2020
CVE-2013-2684Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.EXPLOITMEDIUM 6.1EPSS 3.71%6 February 2020
CVE-2013-2683Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information.EXPLOITMEDIUM 5.3EPSS 13.4%6 February 2020
CVE-2020-8657EyesOfNetwork Use of Hard-Coded Credentials VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 91.9%6 February 2020
CVE-2012-6307A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious user execute arbitrary codeEXPLOITHIGH 8.8EPSS 5.56%6 February 2020
CVE-2014-2030Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld…EXPLOITHIGH 8.8EPSS 11.1%6 February 2020
CVE-2015-6000Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by…EXPLOITHIGH 8.8EPSS 40.2%6 February 2020
CVE-2012-2593Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.EXPLOITMEDIUM 6.1EPSS 6.23%6 February 2020
CVE-2020-8644PlaySMS Server-Side Template Injection VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 86.7%5 February 2020
CVE-2013-2682Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.EXPLOITMEDIUM 4.3EPSS 6.35%5 February 2020
CVE-2013-2681Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.EXPLOITCRITICAL 9.8EPSS 10.1%5 February 2020
CVE-2013-2680Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information.EXPLOITHIGH 7.5EPSS 8.73%5 February 2020
CVE-2019-15253A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management…EXPLOITMEDIUM 4.8EPSS 3.12%5 February 2020
CVE-2019-15126Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set…EXPLOITLOW 3.1EPSS 7.26%5 February 2020
CVE-2020-8615A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).EXPLOITMEDIUM 6.5EPSS 8.83%4 February 2020
CVE-2013-2678Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the…EXPLOIT ×3HIGH 8.1EPSS 16.9%4 February 2020
CVE-2013-7055D-Link DIR-100 4.03B07 has PPTP and poe information disclosureEXPLOITCRITICAL 9.8EPSS 6.98%4 February 2020
CVE-2013-7054D-Link DIR-100 4.03B07: cli.cgi XSSEXPLOITMEDIUM 6.1EPSS 3.50%4 February 2020
CVE-2013-7053D-Link DIR-100 4.03B07: cli.cgi CSRFEXPLOITHIGH 8.8EPSS 3.38%4 February 2020
CVE-2013-7052D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi scriptEXPLOITCRITICAL 9.8EPSS 24.7%4 February 2020
CVE-2013-7051D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parametersEXPLOITHIGH 8.8EPSS 15.6%4 February 2020
CVE-2012-5686ZPanel 10.0.1 has insufficient entropy for its password reset process.EXPLOITCRITICAL 9.8EPSS 4.76%4 February 2020
CVE-2019-16893The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi request.EXPLOITHIGH 7.5EPSS 37.8%3 February 2020
CVE-2020-8547phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.EXPLOITCRITICAL 9.8EPSS 5.86%3 February 2020
CVE-2013-2624Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information through a specially crafted URL request.EXPLOITMEDIUM 5.3EPSS 6.49%3 February 2020
CVE-2013-2623Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email" parameter in index.php.EXPLOITMEDIUM 6.1EPSS 2.83%3 February 2020
CVE-2013-2621Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.EXPLOITMEDIUM 6.1EPSS 10.7%3 February 2020
CVE-2020-8515Multiple DrayTek Vigor Routers Web Management Page VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%1 February 2020
CVE-2020-8512In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.EXPLOITMEDIUM 6.1EPSS 14.8%1 February 2020
CVE-2020-8505School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.EXPLOITMEDIUM 6.5EPSS 1.10%31 January 2020
CVE-2020-8504School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.EXPLOITMEDIUM 6.5EPSS 1.10%31 January 2020
CVE-2014-8322Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.EXPLOITCRITICAL 9.8EPSS 23.9%31 January 2020
CVE-2014-3868Multiple SQL injection vulnerabilities in ZeusCart 4.x.EXPLOITHIGH 8.8EPSS 2.46%31 January 2020
CVE-2014-3119Multiple SQL injection vulnerabilities in web2Project 3.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search_string parameter in the contacts module to index.php or allow remote attackers to execute…EXPLOITHIGH 8.8EPSS 1.73%31 January 2020
CVE-2020-8495In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrative privileges within the…EXPLOITHIGH 7.5EPSS 3.14%30 January 2020
CVE-2020-8493A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via…EXPLOITMEDIUM 4.8EPSS 1.49%30 January 2020
CVE-2013-4241Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the…EXPLOITMEDIUM 6.1EPSS 3.66%30 January 2020
CVE-2013-2294Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/shortlog.php or branch name to the (2) Shortlog table…EXPLOITMEDIUM 6.1EPSS 3.96%30 January 2020
CVE-2013-0291NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure VulnerabilityEXPLOITHIGH 7.5EPSS 15.6%30 January 2020
CVE-2013-3320Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields.EXPLOIT ×2MEDIUM 6.1EPSS 2.30%29 January 2020
CVE-2013-2574An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could let a malicious user obtain sensitive information.EXPLOITHIGH 7.5EPSS 29.6%29 January 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.