Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
394,905 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 113 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-2097 | ZPanel through 10.1.0 has Remote Command Execution | HIGH 7.8EPSS 26.0% | 12 February 2020 |
| CVE-2013-2010 | WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability | CRITICAL 9.8EPSS 73.9% | 12 February 2020 |
| CVE-2014-9390 | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all… | CRITICAL 9.8EPSS 75.6% | 12 February 2020 |
| CVE-2014-2595 | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string. | CRITICAL 9.8EPSS 16.9% | 12 February 2020 |
| CVE-2020-0767 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 17.6% | 11 February 2020 |
| CVE-2020-0759 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 15.2% | 11 February 2020 |
| CVE-2020-0734 | A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 16.5% | 11 February 2020 |
| CVE-2020-0729 | A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK… | HIGH 8.8EPSS 30.9% | 11 February 2020 |
| CVE-2020-0713 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 10.1% | 11 February 2020 |
| CVE-2020-0712 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 10.1% | 11 February 2020 |
| CVE-2020-0711 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 10.2% | 11 February 2020 |
| CVE-2020-0710 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 10.1% | 11 February 2020 |
| CVE-2020-0708 | A remote code execution vulnerability exists when the Windows Imaging Library improperly handles memory.To exploit this vulnerability, an attacker would first have to coerce a victim to open a specially crafted file.The security update addresses the… | HIGH 7.8EPSS 13.5% | 11 February 2020 |
| CVE-2020-0688 | Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 100.0% | 11 February 2020 |
| CVE-2020-0681 | A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. | HIGH 7.5EPSS 10.6% | 11 February 2020 |
| CVE-2020-0674 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 86.9% | 11 February 2020 |
| CVE-2020-0668 | An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. | HIGH 7.8EPSS 25.9% | 11 February 2020 |
| CVE-2020-0662 | A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 13.3% | 11 February 2020 |
| CVE-2020-0655 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. | HIGH 8.0EPSS 65.7% | 11 February 2020 |
| CVE-2020-0618 | Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 99.0% | 11 February 2020 |
| CVE-2013-3684 | NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload | CRITICAL 9.8EPSS 19.2% | 11 February 2020 |
| CVE-2013-1359 | An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the… | CRITICAL 9.8EPSS 89.4% | 11 February 2020 |
| CVE-2013-0803 | A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code. | CRITICAL 9.8EPSS 75.0% | 11 February 2020 |
| CVE-2013-1360 | An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the… | CRITICAL 9.8EPSS 23.2% | 11 February 2020 |
| CVE-2020-8840 | FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter. | CRITICAL 9.8EPSS 26.6% | 10 February 2020 |
| CVE-2012-4512 | The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion." | HIGH 8.8EPSS 11.7% | 8 February 2020 |
| CVE-2014-8739 | Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1… | CRITICAL 9.8EPSS 91.7% | 8 February 2020 |
| CVE-2014-7863 | The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and… | HIGH 7.5EPSS 83.4% | 8 February 2020 |
| CVE-2019-19356 | Netis WF2419 Devices Remote Code Execution Vulnerability | KEVHIGH 7.5EPSS 28.2% | 7 February 2020 |
| CVE-2014-5091 | A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code. | CRITICAL 9.8EPSS 15.2% | 7 February 2020 |
| CVE-2014-5468 | A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code. | HIGH 8.8EPSS 52.6% | 7 February 2020 |
| CVE-2019-15606 | Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons | CRITICAL 9.8EPSS 20.0% | 7 February 2020 |
| CVE-2019-15605 | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed | CRITICAL 9.8EPSS 57.1% | 7 February 2020 |
| CVE-2019-15604 | Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate | HIGH 7.5EPSS 20.5% | 7 February 2020 |
| CVE-2013-3629 | ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution | HIGH 8.8EPSS 43.1% | 7 February 2020 |
| CVE-2013-3628 | Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability | HIGH 8.8EPSS 67.5% | 7 February 2020 |
| CVE-2013-3591 | vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability | HIGH 8.8EPSS 43.1% | 7 February 2020 |
| CVE-2013-2009 | WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution | HIGH 8.8EPSS 13.0% | 7 February 2020 |
| CVE-2020-8656 | The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php. | CRITICAL 9.8EPSS 84.6% | 7 February 2020 |
| CVE-2020-8655 | EyesOfNetwork Improper Privilege Management Vulnerability | KEVHIGH 7.8EPSS 60.1% | 7 February 2020 |
| CVE-2020-8654 | An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field. | HIGH 8.8EPSS 91.2% | 7 February 2020 |
| CVE-2013-3568 | Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. | HIGH 8.8EPSS 25.1% | 6 February 2020 |
| CVE-2013-2683 | Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information. | MEDIUM 5.3EPSS 13.4% | 6 February 2020 |
| CVE-2020-8657 | EyesOfNetwork Use of Hard-Coded Credentials Vulnerability | KEVCRITICAL 9.8EPSS 91.9% | 6 February 2020 |
| CVE-2020-8772 | The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. | CRITICAL 9.8EPSS 88.0% | 6 February 2020 |
| CVE-2020-8771 | The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. | CRITICAL 9.8EPSS 46.5% | 6 February 2020 |
| CVE-2014-2030 | Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld… | HIGH 8.8EPSS 11.1% | 6 February 2020 |
| CVE-2015-6000 | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by… | HIGH 8.8EPSS 40.2% | 6 February 2020 |
| CVE-2020-8644 | PlaySMS Server-Side Template Injection Vulnerability | KEVCRITICAL 9.8EPSS 86.7% | 5 February 2020 |
| CVE-2020-8641 | Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php page_slug parameter. | HIGH 8.8EPSS 10.8% | 5 February 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.