Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 33 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-3896 | Microsoft Silverlight Information Disclosure Vulnerability | KEVMEDIUM 5.5EPSS 69.6% | 9 October 2013 |
| CVE-2013-3893 | Microsoft Internet Explorer Resource Management Errors Vulnerability | KEVHIGH 8.8EPSS 85.9% | 18 September 2013 |
| CVE-2013-4810 | HP Multiple Products Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 79.0% | 16 September 2013 |
| CVE-2013-3346 | Adobe Reader and Acrobat Memory Corruption Vulnerability | KEVCRITICAL 9.8EPSS 78.6% | 30 August 2013 |
| CVE-2013-2251 | Apache Struts Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 20 July 2013 |
| CVE-2013-3163 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 70.7% | 10 July 2013 |
| CVE-2013-1690 | Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability | KEVHIGH 8.8EPSS 69.0% | 26 June 2013 |
| CVE-2013-2465 | Oracle Java SE Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 98.7% | 18 June 2013 |
| CVE-2013-1331 | Microsoft Office Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 81.9% | 12 June 2013 |
| CVE-2013-3660 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 39.6% | 24 May 2013 |
| CVE-2013-2729 | Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 66.6% | 16 May 2013 |
| CVE-2013-1675 | Mozilla Firefox Information Disclosure Vulnerability | KEVMEDIUM 6.5EPSS 6.70% | 16 May 2013 |
| CVE-2013-2094 | Linux Kernel Privilege Escalation Vulnerability | KEVHIGH 8.4EPSS 47.7% | 14 May 2013 |
| CVE-2013-1347 | Microsoft Internet Explorer Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 77.9% | 5 May 2013 |
| CVE-2013-2423 | Oracle JRE Unspecified Vulnerability | KEVLOW 3.7EPSS 85.3% | 17 April 2013 |
| CVE-2013-2596 | Linux Kernel Integer Overflow Vulnerability | KEVHIGH 7.8EPSS 3.21% | 13 April 2013 |
| CVE-2013-0074 | Microsoft Silverlight Double Dereference Vulnerability | KEVHIGH 7.8EPSS 81.0% | 13 March 2013 |
| CVE-2013-2551 | Microsoft Internet Explorer Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 74.1% | 11 March 2013 |
| CVE-2013-0648 | Adobe Flash Player Code Execution Vulnerability | KEVHIGH 8.8EPSS 11.1% | 27 February 2013 |
| CVE-2013-0643 | Adobe Flash Player Incorrect Default Permissions Vulnerability | KEVHIGH 8.8EPSS 10.5% | 27 February 2013 |
| CVE-2013-0641 | Adobe Reader Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 32.4% | 14 February 2013 |
| CVE-2013-0640 | Adobe Reader and Acrobat Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 87.0% | 14 February 2013 |
| CVE-2013-0431 | Oracle JRE Sandbox Bypass Vulnerability | KEVMEDIUM 5.3EPSS 90.0% | 31 January 2013 |
| CVE-2013-0632 | Adobe ColdFusion Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 93.7% | 17 January 2013 |
| CVE-2013-0422 | Oracle JRE Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 97.6% | 10 January 2013 |
| CVE-2013-0631 | Adobe ColdFusion Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 65.9% | 9 January 2013 |
| CVE-2013-0629 | Adobe ColdFusion Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 65.9% | 9 January 2013 |
| CVE-2013-0625 | Adobe ColdFusion Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 93.8% | 9 January 2013 |
| CVE-2012-4792 | Microsoft Internet Explorer Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 78.7% | 30 December 2012 |
| CVE-2012-2539 | Microsoft Word Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 53.2% | 12 December 2012 |
| CVE-2012-3152 | Oracle Fusion Middleware Unspecified Vulnerability | KEVCRITICAL 9.1EPSS 98.8% | 16 October 2012 |
| CVE-2012-0518 | Oracle Fusion Middleware Unspecified Vulnerability | KEVMEDIUM 4.7EPSS 4.69% | 16 October 2012 |
| CVE-2012-5076 | Oracle Java SE Sandbox Bypass Vulnerability | KEVCRITICAL 9.8EPSS 91.0% | 16 October 2012 |
| CVE-2012-5054 | Adobe Flash Player Integer Overflow Vulnerability | KEVHIGH 8.8EPSS 21.2% | 24 September 2012 |
| CVE-2012-4969 | Microsoft Internet Explorer Use-After-Free Vulnerability | KEVHIGH 8.1EPSS 81.7% | 18 September 2012 |
| CVE-2012-4681 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 98.5% | 28 August 2012 |
| CVE-2012-1535 | Adobe Flash Player Arbitrary Code Execution Vulnerability | KEVHIGH 7.8EPSS 70.4% | 15 August 2012 |
| CVE-2012-1856 | Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 72.2% | 15 August 2012 |
| CVE-2012-1854 | Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability | KEVHIGH 7.8EPSS 21.0% | 10 July 2012 |
| CVE-2012-1723 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 93.7% | 16 June 2012 |
| CVE-2012-1889 | Microsoft XML Core Services Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 83.6% | 13 June 2012 |
| CVE-2012-2034 | Adobe Flash Player Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 7.80% | 9 June 2012 |
| CVE-2012-0507 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 98.1% | 7 June 2012 |
| CVE-2012-1823 | PHP-CGI Query String Parameter Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 11 May 2012 |
| CVE-2012-1710 | Oracle Fusion Middleware Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 11.5% | 3 May 2012 |
| CVE-2012-0158 | Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 100.0% | 10 April 2012 |
| CVE-2012-0151 | Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 88.8% | 10 April 2012 |
| CVE-2012-0767 | Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 6.66% | 16 February 2012 |
| CVE-2012-0754 | Adobe Flash Player Memory Corruption Vulnerability | KEVHIGH 8.1EPSS 92.0% | 16 February 2012 |
| CVE-2012-0391 | Apache Struts 2 Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 75.6% | 8 January 2012 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.