SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,810 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 114 of 348

CVESummaryPriorityPublished
CVE-2013-2681Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.CRITICAL 9.8EPSS 10.1%5 February 2020
CVE-2020-3118Cisco IOS XR Software Discovery Protocol Format String VulnerabilityKEVHIGH 8.8EPSS 11.7%5 February 2020
CVE-2020-6754dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control.CRITICAL 9.8EPSS 94.8%5 February 2020
CVE-2019-12528It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.HIGH 7.5EPSS 10.5%4 February 2020
CVE-2020-8450Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.HIGH 7.3EPSS 71.8%4 February 2020
CVE-2013-2678Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the…HIGH 8.1EPSS 16.9%4 February 2020
CVE-2013-7052D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi scriptCRITICAL 9.8EPSS 24.7%4 February 2020
CVE-2013-7051D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parametersHIGH 8.8EPSS 15.6%4 February 2020
CVE-2020-8597eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.CRITICAL 9.8EPSS 19.9%3 February 2020
CVE-2019-16893The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi request.HIGH 7.5EPSS 37.8%3 February 2020
CVE-2013-2621Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.MEDIUM 6.1EPSS 10.7%3 February 2020
CVE-2020-7471Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column…CRITICAL 9.8EPSS 65.6%3 February 2020
CVE-2020-8515Multiple DrayTek Vigor Routers Web Management Page VulnerabilityKEVCRITICAL 9.8EPSS 100.0%1 February 2020
CVE-2020-8512In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.MEDIUM 6.1EPSS 14.8%1 February 2020
CVE-2014-8322Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.CRITICAL 9.8EPSS 23.9%31 January 2020
CVE-2013-0291NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure VulnerabilityHIGH 7.5EPSS 15.6%30 January 2020
CVE-2019-20445HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.CRITICAL 9.1EPSS 13.5%29 January 2020
CVE-2020-3716Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability.CRITICAL 9.8EPSS 14.0%29 January 2020
CVE-2013-2574An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could let a malicious user obtain sensitive information.HIGH 7.5EPSS 29.6%29 January 2020
CVE-2013-2573A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.CRITICAL 9.8EPSS 42.2%29 January 2020
CVE-2013-2572A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized…HIGH 7.5EPSS 16.4%29 January 2020
CVE-2019-18634In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process.HIGH 7.8EPSS 19.4%29 January 2020
CVE-2013-3215vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.CRITICAL 9.8EPSS 68.8%29 January 2020
CVE-2013-2570A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, which could let a remove malicious user execute arbitrary code.CRITICAL 9.8EPSS 26.6%29 January 2020
CVE-2013-2569A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stream.HIGH 7.5EPSS 31.0%29 January 2020
CVE-2013-2568A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.CRITICAL 9.8EPSS 48.5%29 January 2020
CVE-2020-8416IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to the PASV mode port.HIGH 7.5EPSS 14.2%29 January 2020
CVE-2013-2567An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information.HIGH 7.5EPSS 14.6%29 January 2020
CVE-2020-7247OpenSMTPD Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.0%29 January 2020
CVE-2019-20215D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTTP_ST is mishandled.CRITICAL 9.8EPSS 75.1%29 January 2020
CVE-2013-1603An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02,…MEDIUM 5.3EPSS 16.1%28 January 2020
CVE-2013-1602An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1.04_US , DCS-2102…HIGH 7.5EPSS 15.1%28 January 2020
CVE-2020-8417The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.HIGH 8.8EPSS 11.9%28 January 2020
CVE-2013-3214vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.CRITICAL 9.8EPSS 84.5%28 January 2020
CVE-2013-1601An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi…MEDIUM 5.3EPSS 12.7%28 January 2020
CVE-2013-1600An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-2121 1.06_FR, 1.06, and 1.05_RU, DCS-2102 1.06_FR.MEDIUM 5.3EPSS 18.5%28 January 2020
CVE-2013-2748Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.CRITICAL 9.8EPSS 13.1%28 January 2020
CVE-2013-1599A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02,…CRITICAL 9.8EPSS 40.4%28 January 2020
CVE-2013-4863The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute…HIGH 8.8EPSS 12.2%28 January 2020
CVE-2012-6610Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature.HIGH 8.8EPSS 10.9%28 January 2020
CVE-2013-2571Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.CRITICAL 9.8EPSS 16.2%28 January 2020
CVE-2020-7799An authenticated user, allowed to edit e-mail templates (Home -> Settings -> Email Templates) or themes (Home -> Settings -> Themes), can execute commands on the underlying operating system by abusing freemarker.template.utility.Execute in the Apache…HIGH 7.2EPSS 19.8%28 January 2020
CVE-2013-2474Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter.HIGH 7.5EPSS 10.0%27 January 2020
CVE-2019-19824On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available.HIGH 8.8EPSS 25.1%27 January 2020
CVE-2014-8741Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.CRITICAL 9.8EPSS 77.2%27 January 2020
CVE-2013-7390Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct…CRITICAL 9.8EPSS 74.5%27 January 2020
CVE-2019-19825On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass.CRITICAL 9.8EPSS 29.6%27 January 2020
CVE-2012-1495install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.CRITICAL 9.8EPSS 79.8%27 January 2020
CVE-2020-7980Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI.CRITICAL 9.8EPSS 82.5%25 January 2020
CVE-2019-1354A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.HIGH 8.8EPSS 22.6%24 January 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.