Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,662 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 33 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-2573 | A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code. | EXPLOIT ✓CRITICAL 9.8EPSS 42.2% | 29 January 2020 |
| CVE-2013-2572 | A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized… | EXPLOIT ✓HIGH 7.5EPSS 16.4% | 29 January 2020 |
| CVE-2019-18634 | In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. | EXPLOIT ×2HIGH 7.8EPSS 19.4% | 29 January 2020 |
| CVE-2013-3215 | vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. | EXPLOITCRITICAL 9.8EPSS 68.8% | 29 January 2020 |
| CVE-2013-2570 | A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, which could let a remove malicious user execute arbitrary code. | EXPLOIT ✓CRITICAL 9.8EPSS 26.6% | 29 January 2020 |
| CVE-2013-2569 | A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stream. | EXPLOIT ✓HIGH 7.5EPSS 31.0% | 29 January 2020 |
| CVE-2013-2568 | A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code. | EXPLOIT ✓CRITICAL 9.8EPSS 48.5% | 29 January 2020 |
| CVE-2020-8416 | IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to the PASV mode port. | EXPLOITHIGH 7.5EPSS 14.2% | 29 January 2020 |
| CVE-2013-2567 | An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information. | EXPLOIT ✓HIGH 7.5EPSS 14.6% | 29 January 2020 |
| CVE-2020-7247 | OpenSMTPD Remote Code Execution Vulnerability | KEVEXPLOIT ×3 ✓CRITICAL 9.8EPSS 99.0% | 29 January 2020 |
| CVE-2013-0161 | Havalite CMS 1.1.7 has a stored XSS vulnerability | EXPLOIT ✓MEDIUM 5.4EPSS 0.97% | 29 January 2020 |
| CVE-2019-20215 | D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTTP_ST is mishandled. | EXPLOIT ✓CRITICAL 9.8EPSS 75.1% | 29 January 2020 |
| CVE-2020-8425 | Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php. | EXPLOITMEDIUM 6.5EPSS 1.23% | 28 January 2020 |
| CVE-2020-8424 | Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php. | EXPLOITHIGH 8.8EPSS 1.55% | 28 January 2020 |
| CVE-2013-1603 | An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02,… | EXPLOIT ✓MEDIUM 5.3EPSS 16.1% | 28 January 2020 |
| CVE-2013-1602 | An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1.04_US , DCS-2102… | EXPLOIT ✓HIGH 7.5EPSS 15.1% | 28 January 2020 |
| CVE-2013-3214 | vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 84.5% | 28 January 2020 |
| CVE-2013-3212 | vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code. | EXPLOITHIGH 8.1EPSS 7.54% | 28 January 2020 |
| CVE-2013-1601 | An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi… | EXPLOIT ✓MEDIUM 5.3EPSS 12.7% | 28 January 2020 |
| CVE-2013-1600 | An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-2121 1.06_FR, 1.06, and 1.05_RU, DCS-2102 1.06_FR. | EXPLOIT ✓MEDIUM 5.3EPSS 18.5% | 28 January 2020 |
| CVE-2013-2748 | Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system. | EXPLOITCRITICAL 9.8EPSS 13.1% | 28 January 2020 |
| CVE-2013-2714 | Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter. | EXPLOIT ✓MEDIUM 6.1EPSS 2.74% | 28 January 2020 |
| CVE-2013-1599 | A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02,… | EXPLOIT ✓CRITICAL 9.8EPSS 40.4% | 28 January 2020 |
| CVE-2013-4865 | Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 1.73% | 28 January 2020 |
| CVE-2013-4864 | MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue. | EXPLOIT ✓CRITICAL 9.8EPSS 6.31% | 28 January 2020 |
| CVE-2013-4863 | The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute… | EXPLOIT ×2 ✓HIGH 8.8EPSS 12.2% | 28 January 2020 |
| CVE-2013-4862 | MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwords via the cgi-bin/cmh/backup.sh… | EXPLOIT ✓HIGH 8.1EPSS 3.72% | 28 January 2020 |
| CVE-2013-4861 | Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. | EXPLOIT ✓MEDIUM 6.5EPSS 6.63% | 28 January 2020 |
| CVE-2013-2571 | Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer. | EXPLOIT ✓CRITICAL 9.8EPSS 16.2% | 28 January 2020 |
| CVE-2020-7934 | In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. | EXPLOITMEDIUM 5.4EPSS 4.46% | 28 January 2020 |
| CVE-2013-2474 | Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter. | EXPLOITHIGH 7.5EPSS 10.0% | 27 January 2020 |
| CVE-2013-2267 | PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system. | EXPLOIT ✓HIGH 7.2EPSS 8.83% | 27 January 2020 |
| CVE-2012-6448 | Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOIT ✓MEDIUM 6.1EPSS 1.53% | 27 January 2020 |
| CVE-2019-19143 | TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI. | EXPLOITMEDIUM 6.1EPSS 7.31% | 27 January 2020 |
| CVE-2014-8741 | Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors. | EXPLOIT ✓CRITICAL 9.8EPSS 77.2% | 27 January 2020 |
| CVE-2013-7390 | Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct… | EXPLOIT ×3 ✓CRITICAL 9.8EPSS 74.5% | 27 January 2020 |
| CVE-2020-7949 | schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a GetValue call. | EXPLOITHIGH 7.8EPSS 4.17% | 27 January 2020 |
| CVE-2012-1496 | Local file inclusion in WebCalendar before 1.2.5. | EXPLOIT ✓HIGH 8.8EPSS 2.53% | 27 January 2020 |
| CVE-2012-1495 | install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 79.8% | 27 January 2020 |
| CVE-2011-4558 | Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters. | EXPLOITHIGH 7.2EPSS 4.27% | 27 January 2020 |
| CVE-2020-7991 | Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password. | EXPLOIT ✓HIGH 8.8EPSS 3.08% | 26 January 2020 |
| CVE-2020-7980 | Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. | EXPLOITCRITICAL 9.8EPSS 82.5% | 25 January 2020 |
| CVE-2013-1744 | IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands. | EXPLOIT ✓CRITICAL 9.8EPSS 5.13% | 25 January 2020 |
| CVE-2013-1598 | A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user execute arbitrary code. | EXPLOIT ✓HIGH 8.8EPSS 20.5% | 24 January 2020 |
| CVE-2013-1597 | A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credentials. | EXPLOIT ✓MEDIUM 6.5EPSS 14.2% | 24 January 2020 |
| CVE-2019-19363 | An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. | EXPLOIT ×2 ✓HIGH 7.8EPSS 4.44% | 24 January 2020 |
| CVE-2013-1596 | An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554. | EXPLOIT ✓MEDIUM 5.3EPSS 10.4% | 24 January 2020 |
| CVE-2013-1595 | A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or cause a… | EXPLOIT ✓CRITICAL 9.8EPSS 41.6% | 24 January 2020 |
| CVE-2013-1594 | An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party credentials stored in clear text. | EXPLOIT ✓HIGH 7.5EPSS 7.33% | 24 January 2020 |
| CVE-2012-6649 | WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload. | EXPLOIT ✓CRITICAL 9.8EPSS 16.3% | 23 January 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.