SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

1,710 results · page 32 of 35

CVESummaryPriorityPublished
CVE-2015-0666Cisco Prime Data Center Network Manager (DCNM) Directory Traversal VulnerabilityKEVHIGH 7.5EPSS 40.4%3 April 2015
CVE-2015-2051D-Link DIR-645 Router Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 97.1%23 February 2015
CVE-2015-1427Elasticsearch Groovy Scripting Engine Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%17 February 2015
CVE-2015-0071Microsoft Internet Explorer ASLR Bypass VulnerabilityKEVMEDIUM 6.5EPSS 33.6%11 February 2015
CVE-2015-0313Adobe Flash Player Use-After-Free VulnerabilityKEVCRITICAL 9.8EPSS 95.3%2 February 2015
CVE-2015-0311Adobe Flash Player Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 85.8%23 January 2015
CVE-2015-0310Adobe Flash Player ASLR Bypass VulnerabilityKEVHIGH 7.8EPSS 15.2%23 January 2015
CVE-2015-0016Microsoft Windows TS WebProxy Directory Traversal VulnerabilityKEVHIGH 7.8EPSS 75.9%13 January 2015
CVE-2014-100005D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) VulnerabilityKEVHIGH 8.0EPSS 48.1%13 January 2015
CVE-2014-9163Adobe Flash Player Stack-Based Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 20.4%10 December 2014
CVE-2014-8439Adobe Flash Player Dereferenced Pointer VulnerabilityKEVHIGH 8.8EPSS 20.0%25 November 2014
CVE-2014-6324Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 87.4%18 November 2014
CVE-2014-6332Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 95.0%11 November 2014
CVE-2014-4077Microsoft IME Japanese Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 54.9%11 November 2014
CVE-2014-6352Microsoft Windows Code Injection VulnerabilityKEVHIGH 7.8EPSS 77.6%22 October 2014
CVE-2014-4148Microsoft Windows Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 59.8%15 October 2014
CVE-2014-4123Microsoft Internet Explorer Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 47.3%15 October 2014
CVE-2014-4114Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 81.6%15 October 2014
CVE-2014-4113Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 87.0%15 October 2014
CVE-2014-6287Rejetto HTTP File Server (HFS) Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.3%7 October 2014
CVE-2014-6278GNU Bash OS Command Injection VulnerabilityKEVHIGH 8.8EPSS 99.5%30 September 2014
CVE-2014-7169GNU Bourne-Again Shell (Bash) Arbitrary Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%25 September 2014
CVE-2014-6271GNU Bourne-Again Shell (Bash) Arbitrary Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%24 September 2014
CVE-2014-4404Apple OS X Heap-Based Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 49.0%18 September 2014
CVE-2013-2597Code Aurora ACDB Audio Driver Stack-based Buffer Overflow VulnerabilityKEVHIGH 8.4EPSS 1.52%31 August 2014
CVE-2014-2817Microsoft Internet Explorer Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 26.3%12 August 2014
CVE-2014-0546Adobe Reader and Acrobat Sandbox Bypass VulnerabilityKEVCRITICAL 9.8EPSS 22.3%12 August 2014
CVE-2014-3120Elasticsearch Remote Code Execution VulnerabilityKEVHIGH 8.1EPSS 88.6%28 July 2014
CVE-2013-3993IBM InfoSphere BigInsights Invalid Input VulnerabilityKEVMEDIUM 6.5EPSS 5.24%7 July 2014
CVE-2014-3153Linux Kernel Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 37.2%7 June 2014
CVE-2014-1812Microsoft Windows Group Policy Preferences Password Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 65.1%14 May 2014
CVE-2014-0196Linux Kernel Race Condition VulnerabilityKEVMEDIUM 5.5EPSS 22.5%7 May 2014
CVE-2014-0130Ruby on Rails Directory Traversal VulnerabilityKEVHIGH 7.5EPSS 53.7%7 May 2014
CVE-2014-1776Microsoft Internet Explorer Memory Corruption VulnerabilityKEVCRITICAL 9.8EPSS 88.0%27 April 2014
CVE-2014-0780InduSoft Web Studio NTWebServer Directory Traversal VulnerabilityKEVCRITICAL 9.8EPSS 74.0%25 April 2014
CVE-2014-0160OpenSSL Information Disclosure VulnerabilityKEVHIGH 7.5EPSS 100.0%7 April 2014
CVE-2014-1761Microsoft Word Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 77.5%25 March 2014
CVE-2014-2120Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 18.9%19 March 2014
CVE-2013-7331Microsoft Internet Explorer Information Disclosure VulnerabilityKEVMEDIUM 6.5EPSS 58.0%26 February 2014
CVE-2014-0502Adobe Flash Player Double Free VulnerablityKEVHIGH 8.8EPSS 24.2%21 February 2014
CVE-2014-0322Microsoft Internet Explorer Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 85.2%14 February 2014
CVE-2014-0497Adobe Flash Player Integer Underflow VulnerablityKEVCRITICAL 9.8EPSS 99.9%5 February 2014
CVE-2014-0496Adobe Reader and Acrobat Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 40.2%15 January 2014
CVE-2013-3900Microsoft WinVerifyTrust function Remote Code ExecutionKEVMEDIUM 5.5EPSS 44.6%11 December 2013
CVE-2013-5065Microsoft Windows Kernel Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 34.9%28 November 2013
CVE-2013-6282Linux Kernel Improper Input Validation VulnerabilityKEVHIGH 8.8EPSS 39.7%20 November 2013
CVE-2013-5223D-Link DSL-2760U Gateway Cross-Site Scripting VulnerabilityKEVMEDIUM 5.4EPSS 33.6%19 November 2013
CVE-2013-3918Microsoft Windows Out-of-Bounds Write VulnerabilityKEVHIGH 8.8EPSS 73.9%12 November 2013
CVE-2013-3906Microsoft Graphics Component Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 85.0%6 November 2013
CVE-2013-3897Microsoft Internet Explorer Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 77.5%9 October 2013

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.