SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,662 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 34 of 501

CVESummaryPriorityPublished
CVE-2012-5340SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file.EXPLOITHIGH 7.8EPSS 5.73%23 January 2020
CVE-2013-1592A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30…EXPLOITCRITICAL 9.8EPSS 24.4%23 January 2020
CVE-2019-16516There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.EXPLOITMEDIUM 5.3EPSS 19.1%23 January 2020
CVE-2012-6083Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.EXPLOITHIGH 7.5EPSS 11.7%23 January 2020
CVE-2013-6792Google Android prior to 4.4 has an APK Signature Security Bypass VulnerabilityEXPLOITCRITICAL 9.8EPSS 2.99%23 January 2020
CVE-2012-5699BabyGekko before 1.2.4 allows PHP file inclusion.EXPLOITCRITICAL 9.8EPSS 4.94%23 January 2020
CVE-2012-5698BabyGekko before 1.2.4 has SQL injection.EXPLOITHIGH 8.8EPSS 1.75%23 January 2020
CVE-2019-6146It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection.EXPLOITMEDIUM 6.1EPSS 2.98%22 January 2020
CVE-2019-18426WhatsApp Cross-Site Scripting VulnerabilityKEVEXPLOITHIGH 8.2EPSS 67.9%21 January 2020
CVE-2020-6857CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key.EXPLOITMEDIUM 5.5EPSS 0.97%21 January 2020
CVE-2012-5190Prizm Content Connect 5.1 has an Arbitrary File Upload VulnerabilityEXPLOITCRITICAL 9.8EPSS 4.65%21 January 2020
CVE-2011-4095Jara 1.6 has an XSS vulnerabilityEXPLOITMEDIUM 6.1EPSS 1.95%21 January 2020
CVE-2011-4094Jara 1.6 has a SQL injection vulnerability.EXPLOITCRITICAL 9.8EPSS 2.74%21 January 2020
CVE-2020-7246A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.EXPLOIT ×4HIGH 8.8EPSS 83.2%21 January 2020
CVE-2014-5007Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files…EXPLOIT ×3CRITICAL 9.8EPSS 37.3%17 January 2020
CVE-2020-6862V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability.EXPLOITMEDIUM 5.3EPSS 6.31%17 January 2020
CVE-2019-19142Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI.EXPLOITHIGH 7.5EPSS 7.81%17 January 2020
CVE-2019-15742A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application.EXPLOITHIGH 7.8EPSS 4.98%17 January 2020
CVE-2020-7108The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.EXPLOITMEDIUM 5.4EPSS 3.46%16 January 2020
CVE-2009-5068There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3.EXPLOITHIGH 7.2EPSS 1.73%15 January 2020
CVE-2020-2555Oracle Multiple Products Remote Code Execution VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 97.1%15 January 2020
CVE-2005-4891Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.EXPLOITCRITICAL 9.8EPSS 1.74%15 January 2020
CVE-2020-2096Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.EXPLOITMEDIUM 6.1EPSS 92.8%15 January 2020
CVE-2015-7874Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname.EXPLOITCRITICAL 9.8EPSS 13.9%15 January 2020
CVE-2015-5466Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.1090 allows local users to gain privileges via a crafted 0x96002404 IOCTL call.EXPLOITHIGH 7.8EPSS 1.13%15 January 2020
CVE-2015-7556DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program.EXPLOITHIGH 7.8EPSS 1.29%15 January 2020
CVE-2011-4336Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.EXPLOITMEDIUM 6.1EPSS 7.65%15 January 2020
CVE-2012-1563Joomla! before 2.5.3 allows Admin Account Creation.EXPLOITHIGH 7.5EPSS 8.90%15 January 2020
CVE-2020-0646Microsoft .NET Framework Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.2%14 January 2020
CVE-2020-0610A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway)…EXPLOIT ×2CRITICAL 9.8EPSS 67.6%14 January 2020
CVE-2020-0609A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway)…EXPLOIT ×2CRITICAL 9.8EPSS 74.9%14 January 2020
CVE-2020-0601Microsoft Windows CryptoAPI Spoofing VulnerabilityKEVEXPLOITHIGH 8.1EPSS 89.4%14 January 2020
CVE-2020-5509PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image.EXPLOITHIGH 7.2EPSS 5.81%14 January 2020
CVE-2015-4107Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —14 January 2020
CVE-2013-7185PotPlayer 1.5.40688: .avi File Memory CorruptionEXPLOITHIGH 7.8EPSS 2.75%14 January 2020
CVE-2012-4750A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicious user execute arbitrary code or cause a Denial of ServiceEXPLOITCRITICAL 9.8EPSS 8.91%13 January 2020
CVE-2013-6225LiveZilla 5.0.1.4 has a Remote Code Execution vulnerabilityEXPLOITCRITICAL 9.8EPSS 26.6%13 January 2020
CVE-2014-6039ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability.EXPLOITHIGH 7.5EPSS 68.8%13 January 2020
CVE-2014-6038Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability.EXPLOITHIGH 7.5EPSS 72.8%13 January 2020
CVE-2014-5381Grand MA 300 allows a brute-force attack on the PIN.EXPLOITCRITICAL 9.8EPSS 7.06%13 January 2020
CVE-2014-5380Grand MA 300 allows retrieval of the access PIN from sniffed data.EXPLOITHIGH 7.5EPSS 4.34%13 January 2020
CVE-2012-4284A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary codeEXPLOIT ×2CRITICAL 9.8EPSS 69.5%10 January 2020
CVE-2019-18194TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation.EXPLOITHIGH 7.8EPSS 2.21%10 January 2020
CVE-2014-5093Status2k does not remove the install directory allowing credential reset.EXPLOITCRITICAL 9.8EPSS 3.80%10 January 2020
CVE-2014-5092Status2k allows Remote Command Execution in admin/options/editpl.php.EXPLOITHIGH 8.8EPSS 7.11%10 January 2020
CVE-2013-6231SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP scriptEXPLOITHIGH 8.8EPSS 9.88%10 January 2020
CVE-2011-4595Pretty-Link WordPress plugin 1.5.2 has XSSEXPLOITMEDIUM 6.1EPSS 2.41%10 January 2020
CVE-2014-5081sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypassEXPLOITCRITICAL 9.8EPSS 10.5%10 January 2020
CVE-2020-6756languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.EXPLOITCRITICAL 9.8EPSS 10.6%9 January 2020
CVE-2020-5504In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page.EXPLOITHIGH 8.8EPSS 38.8%9 January 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.