SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,905 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 113 of 348

CVESummaryPriorityPublished
CVE-2013-2097ZPanel through 10.1.0 has Remote Command ExecutionHIGH 7.8EPSS 26.0%12 February 2020
CVE-2013-2010WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution VulnerabilityCRITICAL 9.8EPSS 73.9%12 February 2020
CVE-2014-9390Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all…CRITICAL 9.8EPSS 75.6%12 February 2020
CVE-2014-2595Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.CRITICAL 9.8EPSS 16.9%12 February 2020
CVE-2020-0767A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 17.6%11 February 2020
CVE-2020-0759A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 8.8EPSS 15.2%11 February 2020
CVE-2020-0734A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.HIGH 8.8EPSS 16.5%11 February 2020
CVE-2020-0729A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK…HIGH 8.8EPSS 30.9%11 February 2020
CVE-2020-0713A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.1%11 February 2020
CVE-2020-0712A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.1%11 February 2020
CVE-2020-0711A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.2%11 February 2020
CVE-2020-0710A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.1%11 February 2020
CVE-2020-0708A remote code execution vulnerability exists when the Windows Imaging Library improperly handles memory.To exploit this vulnerability, an attacker would first have to coerce a victim to open a specially crafted file.The security update addresses the…HIGH 7.8EPSS 13.5%11 February 2020
CVE-2020-0688Microsoft Exchange Server Validation Key Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 100.0%11 February 2020
CVE-2020-0681A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.HIGH 7.5EPSS 10.6%11 February 2020
CVE-2020-0674Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityKEVHIGH 7.5EPSS 86.9%11 February 2020
CVE-2020-0668An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.HIGH 7.8EPSS 25.9%11 February 2020
CVE-2020-0662A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.HIGH 8.8EPSS 13.3%11 February 2020
CVE-2020-0655A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.HIGH 8.0EPSS 65.7%11 February 2020
CVE-2020-0618Microsoft SQL Server Reporting Services Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 99.0%11 February 2020
CVE-2013-3684NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file uploadCRITICAL 9.8EPSS 19.2%11 February 2020
CVE-2013-1359An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the…CRITICAL 9.8EPSS 89.4%11 February 2020
CVE-2013-0803A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.CRITICAL 9.8EPSS 75.0%11 February 2020
CVE-2013-1360An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the…CRITICAL 9.8EPSS 23.2%11 February 2020
CVE-2020-8840FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.CRITICAL 9.8EPSS 26.6%10 February 2020
CVE-2012-4512The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."HIGH 8.8EPSS 11.7%8 February 2020
CVE-2014-8739Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1…CRITICAL 9.8EPSS 91.7%8 February 2020
CVE-2014-7863The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and…HIGH 7.5EPSS 83.4%8 February 2020
CVE-2019-19356Netis WF2419 Devices Remote Code Execution VulnerabilityKEVHIGH 7.5EPSS 28.2%7 February 2020
CVE-2014-5091A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.CRITICAL 9.8EPSS 15.2%7 February 2020
CVE-2014-5468A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.HIGH 8.8EPSS 52.6%7 February 2020
CVE-2019-15606Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisonsCRITICAL 9.8EPSS 20.0%7 February 2020
CVE-2019-15605HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformedCRITICAL 9.8EPSS 57.1%7 February 2020
CVE-2019-15604Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificateHIGH 7.5EPSS 20.5%7 February 2020
CVE-2013-3629ISPConfig 3.0.5.2 has Arbitrary PHP Code ExecutionHIGH 8.8EPSS 43.1%7 February 2020
CVE-2013-3628Zabbix 2.0.9 has an Arbitrary Command Execution VulnerabilityHIGH 8.8EPSS 67.5%7 February 2020
CVE-2013-3591vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution VulnerabilityHIGH 8.8EPSS 43.1%7 February 2020
CVE-2013-2009WordPress WP Super Cache Plugin 1.2 has Remote PHP Code ExecutionHIGH 8.8EPSS 13.0%7 February 2020
CVE-2020-8656The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.CRITICAL 9.8EPSS 84.6%7 February 2020
CVE-2020-8655EyesOfNetwork Improper Privilege Management VulnerabilityKEVHIGH 7.8EPSS 60.1%7 February 2020
CVE-2020-8654An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.HIGH 8.8EPSS 91.2%7 February 2020
CVE-2013-3568Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.HIGH 8.8EPSS 25.1%6 February 2020
CVE-2013-2683Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information.MEDIUM 5.3EPSS 13.4%6 February 2020
CVE-2020-8657EyesOfNetwork Use of Hard-Coded Credentials VulnerabilityKEVCRITICAL 9.8EPSS 91.9%6 February 2020
CVE-2020-8772The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php.CRITICAL 9.8EPSS 88.0%6 February 2020
CVE-2020-8771The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass.CRITICAL 9.8EPSS 46.5%6 February 2020
CVE-2014-2030Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld…HIGH 8.8EPSS 11.1%6 February 2020
CVE-2015-6000Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by…HIGH 8.8EPSS 40.2%6 February 2020
CVE-2020-8644PlaySMS Server-Side Template Injection VulnerabilityKEVCRITICAL 9.8EPSS 86.7%5 February 2020
CVE-2020-8641Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php page_slug parameter.HIGH 8.8EPSS 10.8%5 February 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.