SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,662 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 35 of 501

CVESummaryPriorityPublished
CVE-2012-3810Samsung Kies before 2.5.0.12094_27_11 has registry modification.EXPLOITHIGH 7.5EPSS 4.99%9 January 2020
CVE-2012-3809Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.EXPLOITHIGH 7.5EPSS 4.99%9 January 2020
CVE-2012-3808Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.EXPLOITHIGH 7.5EPSS 4.99%9 January 2020
CVE-2012-3807Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.EXPLOITCRITICAL 9.8EPSS 31.6%9 January 2020
CVE-2019-18859Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.EXPLOITMEDIUM 6.1EPSS 2.40%9 January 2020
CVE-2012-2226Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.EXPLOITCRITICAL 9.8EPSS 7.36%9 January 2020
CVE-2012-1915EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.EXPLOITMEDIUM 6.1EPSS 1.86%9 January 2020
CVE-2012-1261Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow and sFlow Analyzer 8.6.2.16204 and other versions before 9.0.1.19899 allows remote attackers to inject arbitrary web script or HTML…EXPLOITMEDIUM 6.1EPSS 2.22%9 January 2020
CVE-2012-1260Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allows remote attackers to inject arbitrary web script or HTML…EXPLOITMEDIUM 6.1EPSS 2.26%9 January 2020
CVE-2012-1259Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to…EXPLOITCRITICAL 9.8EPSS 4.25%9 January 2020
CVE-2012-1258cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and…EXPLOITMEDIUM 6.5EPSS 3.33%9 January 2020
CVE-2014-5287A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).EXPLOITHIGH 8.8EPSS 8.00%8 January 2020
CVE-2020-0009In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass.EXPLOITMEDIUM 5.5EPSS 0.68%8 January 2020
CVE-2014-2072Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checksEXPLOITCRITICAL 9.8EPSS 7.43%8 January 2020
CVE-2020-6170An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.EXPLOITCRITICAL 9.8EPSS 7.33%8 January 2020
CVE-2019-20361There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).EXPLOITCRITICAL 9.8EPSS 85.1%8 January 2020
CVE-2014-8673Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.EXPLOITCRITICAL 9.8EPSS 11.9%7 January 2020
CVE-2013-5657AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP requestEXPLOITHIGH 7.5EPSS 6.85%7 January 2020
CVE-2013-5656FuzeZip 1.0.0.131625 has a Local Buffer Overflow vulnerabilityEXPLOITHIGH 7.8EPSS 1.52%7 January 2020
CVE-2014-8674Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary…EXPLOITMEDIUM 5.4EPSS 2.65%6 January 2020
CVE-2015-4553A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.EXPLOITHIGH 8.8EPSS 56.7%6 January 2020
CVE-2019-19509A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the exec function without filtering, which can lead to command execution.EXPLOIT ×2HIGH 8.8EPSS 71.6%6 January 2020
CVE-2020-5515Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.EXPLOITHIGH 7.2EPSS 26.5%6 January 2020
CVE-2015-4039Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content.EXPLOITMEDIUM 5.4EPSS 2.79%6 January 2020
CVE-2019-15999A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device.EXPLOITMEDIUM 6.3EPSS 3.65%6 January 2020
CVE-2019-15984Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device.EXPLOITHIGH 7.2EPSS 46.9%6 January 2020
CVE-2019-15978Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying…EXPLOITHIGH 7.2EPSS 37.5%6 January 2020
CVE-2019-15977Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected…EXPLOITHIGH 7.5EPSS 38.1%6 January 2020
CVE-2019-15976Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected…EXPLOITCRITICAL 9.8EPSS 92.8%6 January 2020
CVE-2019-15975Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected…EXPLOITCRITICAL 9.8EPSS 96.5%6 January 2020
CVE-2019-20354The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal.EXPLOITMEDIUM 4.3EPSS 8.79%6 January 2020
CVE-2020-5192PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.EXPLOITHIGH 8.8EPSS 16.8%6 January 2020
CVE-2020-5191PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.EXPLOITMEDIUM 6.1EPSS 5.52%6 January 2020
CVE-2014-8516Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.EXPLOITCRITICAL 9.8EPSS 81.7%3 January 2020
CVE-2014-5140The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name…EXPLOITHIGH 8.8EPSS 2.68%3 January 2020
CVE-2012-5878Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath…EXPLOITCRITICAL 9.8EPSS 9.30%3 January 2020
CVE-2019-20204The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element.EXPLOITMEDIUM 5.4EPSS 3.38%2 January 2020
CVE-2015-5595Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumption).EXPLOITMEDIUM 6.5EPSS 1.45%31 December 2019
CVE-2015-5591SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.EXPLOITHIGH 7.2EPSS 2.24%31 December 2019
CVE-2019-10227openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.EXPLOITMEDIUM 6.1EPSS 1.23%31 December 2019
CVE-2019-9556FiberHome an5506-04-f RP2669 devices have XSS.EXPLOITMEDIUM 5.4EPSS 1.12%31 December 2019
CVE-2019-9554In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.EXPLOITMEDIUM 6.1EPSS 3.71%31 December 2019
CVE-2019-9553Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.EXPLOITMEDIUM 6.1EPSS 1.75%31 December 2019
CVE-2019-7751A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remote attacker to list or enumerate sensitive contents of files.EXPLOITHIGH 7.5EPSS 14.2%31 December 2019
CVE-2019-19032XMLBlueprint through 16.191112 is affected by XML External Entity Injection.EXPLOITHIGH 8.1EPSS 4.55%30 December 2019
CVE-2019-19031Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection.EXPLOITHIGH 8.1EPSS 5.21%30 December 2019
CVE-2019-17558Apache Solr VelocityResponseWriter Plug-In Remote Code Execution VulnerabilityKEVEXPLOIT ×2HIGH 7.5EPSS 98.6%30 December 2019
CVE-2019-20085TVT NVMS-1000 Directory Traversal VulnerabilityKEVEXPLOITHIGH 7.5EPSS 96.1%30 December 2019
CVE-2014-6420Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded picture.EXPLOITMEDIUM 6.1EPSS 1.76%27 December 2019
CVE-2014-5289Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request.EXPLOITCRITICAL 9.8EPSS 12.0%27 December 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.