Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,662 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 34 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-5340 | SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file. | EXPLOIT ✓HIGH 7.8EPSS 5.73% | 23 January 2020 |
| CVE-2013-1592 | A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30… | EXPLOIT ✓CRITICAL 9.8EPSS 24.4% | 23 January 2020 |
| CVE-2019-16516 | There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username. | EXPLOITMEDIUM 5.3EPSS 19.1% | 23 January 2020 |
| CVE-2012-6083 | Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet. | EXPLOIT ✓HIGH 7.5EPSS 11.7% | 23 January 2020 |
| CVE-2013-6792 | Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability | EXPLOIT ✓CRITICAL 9.8EPSS 2.99% | 23 January 2020 |
| CVE-2012-5699 | BabyGekko before 1.2.4 allows PHP file inclusion. | EXPLOIT ✓CRITICAL 9.8EPSS 4.94% | 23 January 2020 |
| CVE-2012-5698 | BabyGekko before 1.2.4 has SQL injection. | EXPLOIT ✓HIGH 8.8EPSS 1.75% | 23 January 2020 |
| CVE-2019-6146 | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. | EXPLOITMEDIUM 6.1EPSS 2.98% | 22 January 2020 |
| CVE-2019-18426 | WhatsApp Cross-Site Scripting Vulnerability | KEVEXPLOITHIGH 8.2EPSS 67.9% | 21 January 2020 |
| CVE-2020-6857 | CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. | EXPLOITMEDIUM 5.5EPSS 0.97% | 21 January 2020 |
| CVE-2012-5190 | Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability | EXPLOIT ✓CRITICAL 9.8EPSS 4.65% | 21 January 2020 |
| CVE-2011-4095 | Jara 1.6 has an XSS vulnerability | EXPLOIT ✓MEDIUM 6.1EPSS 1.95% | 21 January 2020 |
| CVE-2011-4094 | Jara 1.6 has a SQL injection vulnerability. | EXPLOITCRITICAL 9.8EPSS 2.74% | 21 January 2020 |
| CVE-2020-7246 | A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. | EXPLOIT ×4 ✓HIGH 8.8EPSS 83.2% | 21 January 2020 |
| CVE-2014-5007 | Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files… | EXPLOIT ×3 ✓CRITICAL 9.8EPSS 37.3% | 17 January 2020 |
| CVE-2020-6862 | V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. | EXPLOITMEDIUM 5.3EPSS 6.31% | 17 January 2020 |
| CVE-2019-19142 | Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI. | EXPLOITHIGH 7.5EPSS 7.81% | 17 January 2020 |
| CVE-2019-15742 | A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application. | EXPLOIT ✓HIGH 7.8EPSS 4.98% | 17 January 2020 |
| CVE-2020-7108 | The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field. | EXPLOITMEDIUM 5.4EPSS 3.46% | 16 January 2020 |
| CVE-2009-5068 | There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. | EXPLOIT ✓HIGH 7.2EPSS 1.73% | 15 January 2020 |
| CVE-2020-2555 | Oracle Multiple Products Remote Code Execution Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 97.1% | 15 January 2020 |
| CVE-2005-4891 | Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements. | EXPLOIT ✓CRITICAL 9.8EPSS 1.74% | 15 January 2020 |
| CVE-2020-2096 | Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability. | EXPLOITMEDIUM 6.1EPSS 92.8% | 15 January 2020 |
| CVE-2015-7874 | Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname. | EXPLOITCRITICAL 9.8EPSS 13.9% | 15 January 2020 |
| CVE-2015-5466 | Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.1090 allows local users to gain privileges via a crafted 0x96002404 IOCTL call. | EXPLOITHIGH 7.8EPSS 1.13% | 15 January 2020 |
| CVE-2015-7556 | DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program. | EXPLOITHIGH 7.8EPSS 1.29% | 15 January 2020 |
| CVE-2011-4336 | Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php. | EXPLOIT ✓MEDIUM 6.1EPSS 7.65% | 15 January 2020 |
| CVE-2012-1563 | Joomla! before 2.5.3 allows Admin Account Creation. | EXPLOITHIGH 7.5EPSS 8.90% | 15 January 2020 |
| CVE-2020-0646 | Microsoft .NET Framework Remote Code Execution Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 99.2% | 14 January 2020 |
| CVE-2020-0610 | A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway)… | EXPLOIT ×2CRITICAL 9.8EPSS 67.6% | 14 January 2020 |
| CVE-2020-0609 | A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway)… | EXPLOIT ×2CRITICAL 9.8EPSS 74.9% | 14 January 2020 |
| CVE-2020-0601 | Microsoft Windows CryptoAPI Spoofing Vulnerability | KEVEXPLOITHIGH 8.1EPSS 89.4% | 14 January 2020 |
| CVE-2020-5509 | PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image. | EXPLOITHIGH 7.2EPSS 5.81% | 14 January 2020 |
| CVE-2015-4107 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 14 January 2020 |
| CVE-2013-7185 | PotPlayer 1.5.40688: .avi File Memory Corruption | EXPLOITHIGH 7.8EPSS 2.75% | 14 January 2020 |
| CVE-2012-4750 | A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicious user execute arbitrary code or cause a Denial of Service | EXPLOITCRITICAL 9.8EPSS 8.91% | 13 January 2020 |
| CVE-2013-6225 | LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability | EXPLOITCRITICAL 9.8EPSS 26.6% | 13 January 2020 |
| CVE-2014-6039 | ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. | EXPLOITHIGH 7.5EPSS 68.8% | 13 January 2020 |
| CVE-2014-6038 | Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. | EXPLOITHIGH 7.5EPSS 72.8% | 13 January 2020 |
| CVE-2014-5381 | Grand MA 300 allows a brute-force attack on the PIN. | EXPLOIT ✓CRITICAL 9.8EPSS 7.06% | 13 January 2020 |
| CVE-2014-5380 | Grand MA 300 allows retrieval of the access PIN from sniffed data. | EXPLOIT ✓HIGH 7.5EPSS 4.34% | 13 January 2020 |
| CVE-2012-4284 | A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 69.5% | 10 January 2020 |
| CVE-2019-18194 | TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. | EXPLOIT ✓HIGH 7.8EPSS 2.21% | 10 January 2020 |
| CVE-2014-5093 | Status2k does not remove the install directory allowing credential reset. | EXPLOITCRITICAL 9.8EPSS 3.80% | 10 January 2020 |
| CVE-2014-5092 | Status2k allows Remote Command Execution in admin/options/editpl.php. | EXPLOITHIGH 8.8EPSS 7.11% | 10 January 2020 |
| CVE-2013-6231 | SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script | EXPLOITHIGH 8.8EPSS 9.88% | 10 January 2020 |
| CVE-2011-4595 | Pretty-Link WordPress plugin 1.5.2 has XSS | EXPLOIT ✓MEDIUM 6.1EPSS 2.41% | 10 January 2020 |
| CVE-2014-5081 | sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass | EXPLOITCRITICAL 9.8EPSS 10.5% | 10 January 2020 |
| CVE-2020-6756 | languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter. | EXPLOITCRITICAL 9.8EPSS 10.6% | 9 January 2020 |
| CVE-2020-5504 | In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. | EXPLOITHIGH 8.8EPSS 38.8% | 9 January 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.