SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

1,710 results · page 33 of 35

CVESummaryPriorityPublished
CVE-2013-3896Microsoft Silverlight Information Disclosure VulnerabilityKEVMEDIUM 5.5EPSS 69.6%9 October 2013
CVE-2013-3893Microsoft Internet Explorer Resource Management Errors VulnerabilityKEVHIGH 8.8EPSS 85.9%18 September 2013
CVE-2013-4810HP Multiple Products Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 79.0%16 September 2013
CVE-2013-3346Adobe Reader and Acrobat Memory Corruption VulnerabilityKEVCRITICAL 9.8EPSS 78.6%30 August 2013
CVE-2013-2251Apache Struts Improper Input Validation VulnerabilityKEVCRITICAL 9.8EPSS 100.0%20 July 2013
CVE-2013-3163Microsoft Internet Explorer Memory Corruption VulnerabilityKEVHIGH 8.8EPSS 70.7%10 July 2013
CVE-2013-1690Mozilla Firefox and Thunderbird Denial-of-Service VulnerabilityKEVHIGH 8.8EPSS 69.0%26 June 2013
CVE-2013-2465Oracle Java SE Unspecified VulnerabilityKEVCRITICAL 9.8EPSS 98.7%18 June 2013
CVE-2013-1331Microsoft Office Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 81.9%12 June 2013
CVE-2013-3660Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 39.6%24 May 2013
CVE-2013-2729Adobe Reader and Acrobat Arbitrary Integer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 66.6%16 May 2013
CVE-2013-1675Mozilla Firefox Information Disclosure VulnerabilityKEVMEDIUM 6.5EPSS 6.70%16 May 2013
CVE-2013-2094Linux Kernel Privilege Escalation VulnerabilityKEVHIGH 8.4EPSS 47.7%14 May 2013
CVE-2013-1347Microsoft Internet Explorer Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 77.9%5 May 2013
CVE-2013-2423Oracle JRE Unspecified VulnerabilityKEVLOW 3.7EPSS 85.3%17 April 2013
CVE-2013-2596Linux Kernel Integer Overflow VulnerabilityKEVHIGH 7.8EPSS 3.21%13 April 2013
CVE-2013-0074Microsoft Silverlight Double Dereference VulnerabilityKEVHIGH 7.8EPSS 81.0%13 March 2013
CVE-2013-2551Microsoft Internet Explorer Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 74.1%11 March 2013
CVE-2013-0648Adobe Flash Player Code Execution VulnerabilityKEVHIGH 8.8EPSS 11.1%27 February 2013
CVE-2013-0643Adobe Flash Player Incorrect Default Permissions VulnerabilityKEVHIGH 8.8EPSS 10.5%27 February 2013
CVE-2013-0641Adobe Reader Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 32.4%14 February 2013
CVE-2013-0640Adobe Reader and Acrobat Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 87.0%14 February 2013
CVE-2013-0431Oracle JRE Sandbox Bypass VulnerabilityKEVMEDIUM 5.3EPSS 90.0%31 January 2013
CVE-2013-0632Adobe ColdFusion Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 93.7%17 January 2013
CVE-2013-0422Oracle JRE Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 97.6%10 January 2013
CVE-2013-0631Adobe ColdFusion Information Disclosure VulnerabilityKEVHIGH 7.5EPSS 65.9%9 January 2013
CVE-2013-0629Adobe ColdFusion Directory Traversal VulnerabilityKEVHIGH 7.5EPSS 65.9%9 January 2013
CVE-2013-0625Adobe ColdFusion Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 93.8%9 January 2013
CVE-2012-4792Microsoft Internet Explorer Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 78.7%30 December 2012
CVE-2012-2539Microsoft Word Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 53.2%12 December 2012
CVE-2012-3152Oracle Fusion Middleware Unspecified VulnerabilityKEVCRITICAL 9.1EPSS 98.8%16 October 2012
CVE-2012-0518Oracle Fusion Middleware Unspecified VulnerabilityKEVMEDIUM 4.7EPSS 4.69%16 October 2012
CVE-2012-5076Oracle Java SE Sandbox Bypass VulnerabilityKEVCRITICAL 9.8EPSS 91.0%16 October 2012
CVE-2012-5054Adobe Flash Player Integer Overflow VulnerabilityKEVHIGH 8.8EPSS 21.2%24 September 2012
CVE-2012-4969Microsoft Internet Explorer Use-After-Free VulnerabilityKEVHIGH 8.1EPSS 81.7%18 September 2012
CVE-2012-4681Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 98.5%28 August 2012
CVE-2012-1535Adobe Flash Player Arbitrary Code Execution VulnerabilityKEVHIGH 7.8EPSS 70.4%15 August 2012
CVE-2012-1856Microsoft Office MSCOMCTL.OCX Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 72.2%15 August 2012
CVE-2012-1854Microsoft Visual Basic for Applications Insecure Library Loading VulnerabilityKEVHIGH 7.8EPSS 21.0%10 July 2012
CVE-2012-1723Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 93.7%16 June 2012
CVE-2012-1889Microsoft XML Core Services Memory Corruption VulnerabilityKEVHIGH 8.8EPSS 83.6%13 June 2012
CVE-2012-2034Adobe Flash Player Memory Corruption VulnerabilityKEVHIGH 7.5EPSS 7.80%9 June 2012
CVE-2012-0507Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 98.1%7 June 2012
CVE-2012-1823PHP-CGI Query String Parameter VulnerabilityKEVCRITICAL 9.8EPSS 100.0%11 May 2012
CVE-2012-1710Oracle Fusion Middleware Unspecified VulnerabilityKEVCRITICAL 9.8EPSS 11.5%3 May 2012
CVE-2012-0158Microsoft MSCOMCTL.OCX Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 100.0%10 April 2012
CVE-2012-0151Microsoft Windows Authenticode Signature Verification Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 88.8%10 April 2012
CVE-2012-0767Adobe Flash Player Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 6.66%16 February 2012
CVE-2012-0754Adobe Flash Player Memory Corruption VulnerabilityKEVHIGH 8.1EPSS 92.0%16 February 2012
CVE-2012-0391Apache Struts 2 Improper Input Validation VulnerabilityKEVCRITICAL 9.8EPSS 75.6%8 January 2012

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.