Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
17,391 results · page 209 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2015-3622 | The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate. | MEDIUM 4.3EPSS 32.9% | 12 May 2015 |
| CVE-2015-2845 | The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arbitrary commands via the $type portion of the PATH_INFO. | EXPLOIT ×2 ✓HIGH 10.0EPSS 71.5% | 12 May 2015 |
| CVE-2015-2844 | The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $action portion of the PATH_INFO. | EXPLOIT ✓HIGH 10.0EPSS 12.6% | 12 May 2015 |
| CVE-2015-2843 | Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute arbitrary SQL commands via the (1) user_name or (2) user_pass parameter in go_login.php or the PATH_INFO to (3)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 37.9% | 12 May 2015 |
| CVE-2015-2842 | Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3.3-1421902800 allows remote attackers to execute arbitrary code by uploading a file with an executable… | EXPLOIT ✓HIGH 10.0EPSS 13.1% | 12 May 2015 |
| CVE-2015-1880 | Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | MEDIUM 4.3EPSS 14.2% | 12 May 2015 |
| CVE-2015-1155 | The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to bypass the Same Origin Policy and read arbitrary files via a crafted web site. | MEDIUM 4.3EPSS 10.9% | 8 May 2015 |
| CVE-2015-3435 | Samsung Security Manager (SSM) before 1.31 allows remote attackers to execute arbitrary code by uploading a file with an HTTP (1) PUT or (2) MOVE request. | HIGH 10.0EPSS 10.2% | 1 May 2015 |
| CVE-2015-3337 | Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors. | EXPLOITMEDIUM 4.3EPSS 32.9% | 1 May 2015 |
| CVE-2014-8361 | Realtek SDK Improper Input Validation Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 100.0% | 1 May 2015 |
| CVE-2015-3457 | Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter. | MEDIUM 5.0EPSS 25.1% | 29 April 2015 |
| CVE-2015-1399 | PHP remote file inclusion vulnerability in the fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary PHP code via a… | MEDIUM 6.5EPSS 10.0% | 29 April 2015 |
| CVE-2015-1398 | Multiple directory traversal vulnerabilities in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote authenticated users to include and execute certain PHP files via (1) .. | MEDIUM 6.5EPSS 14.3% | 29 April 2015 |
| CVE-2015-1397 | SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary SQL commands via the… | EXPLOITMEDIUM 6.5EPSS 52.3% | 29 April 2015 |
| CVE-2015-3148 | cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request. | MEDIUM 5.0EPSS 14.1% | 24 April 2015 |
| CVE-2015-3145 | The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a… | HIGH 7.5EPSS 37.4% | 24 April 2015 |
| CVE-2015-3144 | The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a… | HIGH 9.0EPSS 11.0% | 24 April 2015 |
| CVE-2015-3143 | cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015. | MEDIUM 5.0EPSS 12.8% | 24 April 2015 |
| CVE-2015-3035 | TP-Link Multiple Archer Devices Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 83.9% | 22 April 2015 |
| CVE-2015-0135 | IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of service (integer truncation and application crash) via a crafted GIF image, aka SPR KLYH9T7NT9. | HIGH 10.0EPSS 39.8% | 21 April 2015 |
| CVE-2015-2825 | Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct… | EXPLOITHIGH 7.5EPSS 14.4% | 21 April 2015 |
| CVE-2015-1701 | Microsoft Win32k Privilege Escalation Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 56.2% | 21 April 2015 |
| CVE-2015-0969 | SearchBlox before 8.2 allows remote attackers to obtain sensitive information via a pretty=true action to the _cluster/health URI. | MEDIUM 5.0EPSS 13.4% | 18 April 2015 |
| CVE-2015-3043 | Adobe Flash Player Memory Corruption Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 73.9% | 14 April 2015 |
| CVE-2015-3042 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a… | EXPLOIT ✓HIGH 10.0EPSS 36.8% | 14 April 2015 |
| CVE-2015-0359 | Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability… | EXPLOIT ✓HIGH 10.0EPSS 92.1% | 14 April 2015 |
| CVE-2015-0358 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different… | HIGH 10.0EPSS 10.4% | 14 April 2015 |
| CVE-2015-0346 | Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability… | HIGH 10.0EPSS 10.4% | 14 April 2015 |
| CVE-2015-1668 | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 15.7% | 14 April 2015 |
| CVE-2015-1667 | Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 12.9% | 14 April 2015 |
| CVE-2015-1666 | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 12.9% | 14 April 2015 |
| CVE-2015-1665 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 15.7% | 14 April 2015 |
| CVE-2015-1662 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 12.9% | 14 April 2015 |
| CVE-2015-1661 | Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability." | MEDIUM 4.3EPSS 14.6% | 14 April 2015 |
| CVE-2015-1660 | Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 12.9% | 14 April 2015 |
| CVE-2015-1659 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 15.7% | 14 April 2015 |
| CVE-2015-1657 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 12.9% | 14 April 2015 |
| CVE-2015-1652 | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 15.7% | 14 April 2015 |
| CVE-2015-1651 | Use-after-free vulnerability in Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability." | HIGH 9.3EPSS 16.5% | 14 April 2015 |
| CVE-2015-1650 | Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web… | HIGH 9.3EPSS 26.6% | 14 April 2015 |
| CVE-2015-1649 | Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps Server 2010 SP2 allows remote attackers to… | HIGH 9.3EPSS 23.1% | 14 April 2015 |
| CVE-2015-1648 | ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is disabled, allows remote attackers to obtain sensitive configuration-file information via a crafted request, aka "ASP.NET… | LOW 2.6EPSS 34.6% | 14 April 2015 |
| CVE-2015-1646 | Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted DTD, aka "MSXML3 Same Origin Policy SFB Vulnerability." | MEDIUM 4.3EPSS 16.9% | 14 April 2015 |
| CVE-2015-1645 | Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to execute arbitrary code via a crafted Enhanced Metafile (EMF) image, aka "EMF Processing Remote Code Execution… | HIGH 9.3EPSS 25.3% | 14 April 2015 |
| CVE-2015-1641 | Microsoft Office Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 96.7% | 14 April 2015 |
| CVE-2015-1638 | Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active… | MEDIUM 5.8EPSS 12.7% | 14 April 2015 |
| CVE-2015-1635 | Microsoft HTTP.sys Remote Code Execution Vulnerability | KEVEXPLOIT ×2CRITICAL 9.8EPSS 100.0% | 14 April 2015 |
| CVE-2015-3008 | Asterisk Open Source 1.8 before 1.8.32.3, 11.x before 11.17.1, 12.x before 12.8.2, and 13.x before 13.3.2 and Certified Asterisk 1.8.28 before 1.8.28-cert5, 11.6 before 11.6-cert11, and 13.1 before 13.1-cert2, when registering a SIP TLS device, does not… | MEDIUM 4.3EPSS 46.2% | 10 April 2015 |
| CVE-2015-2295 | Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the… | EXPLOITMEDIUM 6.8EPSS 65.7% | 10 April 2015 |
| CVE-2015-0248 | The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically… | MEDIUM 5.0EPSS 12.1% | 8 April 2015 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.