SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

17,391 results · page 213 of 348

CVESummaryPriorityPublished
CVE-2015-0318Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a…EXPLOITHIGH 10.0EPSS 75.2%6 February 2015
CVE-2014-7864Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attackers and remote authenticated users to execute arbitrary…EXPLOITHIGH 7.5EPSS 22.7%4 February 2015
CVE-2015-0313Adobe Flash Player Use-After-Free VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 95.3%2 February 2015
CVE-2014-4492libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an _networkd context via a crafted XPC…EXPLOITHIGH 7.5EPSS 19.7%30 January 2015
CVE-2015-0235Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2…EXPLOIT ×2HIGH 10.0EPSS 94.6%28 January 2015
CVE-2015-1376pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.EXPLOITMEDIUM 4.0EPSS 33.1%28 January 2015
CVE-2015-1375pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.EXPLOITHIGH 7.5EPSS 11.9%28 January 2015
CVE-2015-1365Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 13.0%27 January 2015
CVE-2015-0232The exif_process_unicode function in ext/exif/exif.c in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free and application crash) via…MEDIUM 6.8EPSS 16.2%27 January 2015
CVE-2015-0231Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that…HIGH 7.5EPSS 42.6%27 January 2015
CVE-2014-8158Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.MEDIUM 6.8EPSS 14.4%26 January 2015
CVE-2014-8157Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.HIGH 7.5EPSS 16.9%26 January 2015
CVE-2015-0311Adobe Flash Player Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 85.8%23 January 2015
CVE-2015-0310Adobe Flash Player ASLR Bypass VulnerabilityKEVHIGH 7.8EPSS 15.1%23 January 2015
CVE-2015-0925The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subprocess reached through a named pipe, as demonstrated…EXPLOITHIGH 9.0EPSS 52.2%22 January 2015
CVE-2015-0554The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly restrict access to the web interface, which allows remote attackers to obtain sensitive information or cause a denial of service (device…EXPLOITHIGH 9.4EPSS 38.9%21 January 2015
CVE-2015-0382Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.MEDIUM 4.3EPSS 10.1%21 January 2015
CVE-2014-6593Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.EXPLOITMEDIUM 4.0EPSS 66.4%21 January 2015
CVE-2014-9195Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.EXPLOITHIGH 7.5EPSS 80.7%17 January 2015
CVE-2014-9308Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote authenticated users to execute arbitrary code by uploading a file with an…EXPLOIT ×2MEDIUM 6.5EPSS 50.6%15 January 2015
CVE-2014-8636The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges…EXPLOITHIGH 7.5EPSS 64.8%14 January 2015
CVE-2015-0016Microsoft Windows TS WebProxy Directory Traversal VulnerabilityKEVEXPLOITHIGH 7.8EPSS 75.8%13 January 2015
CVE-2015-0015Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (system hang and RADIUS outage) via crafted username strings to (1) Internet Authentication Service (IAS) or…HIGH 7.8EPSS 78.7%13 January 2015
CVE-2015-0014Buffer overflow in the Telnet service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary…HIGH 10.0EPSS 96.9%13 January 2015
CVE-2015-0006The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication…MEDIUM 6.1EPSS 11.6%13 January 2015
CVE-2015-0002The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify…EXPLOITHIGH 7.2EPSS 13.8%13 January 2015
CVE-2014-10037Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a ..EXPLOITHIGH 7.5EPSS 18.8%13 January 2015
CVE-2014-100015Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write to arbitrary files via a ..EXPLOIT ×2MEDIUM 6.4EPSS 57.4%13 January 2015
CVE-2014-10021Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the…EXPLOIT ×2HIGH 7.5EPSS 59.0%13 January 2015
CVE-2014-10011Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView camera TV-IP422WN allows remote attackers to execute arbitrary code via a long string to the (1) CGI_ParamSet, (2) OpenFileDlg, (3)…EXPLOITHIGH 7.5EPSS 10.1%13 January 2015
CVE-2014-100005D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) VulnerabilityKEVHIGH 8.0EPSS 43.5%13 January 2015
CVE-2014-100002Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.EXPLOITMEDIUM 5.0EPSS 59.9%13 January 2015
CVE-2015-0922McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.MEDIUM 5.0EPSS 13.3%9 January 2015
CVE-2015-0921XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to…MEDIUM 4.0EPSS 17.4%9 January 2015
CVE-2015-0206Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate records for the next epoch, leading to…MEDIUM 5.0EPSS 57.4%9 January 2015
CVE-2015-0205The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to…MEDIUM 5.0EPSS 22.3%9 January 2015
CVE-2015-0204The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak…MEDIUM 4.3EPSS 98.7%9 January 2015
CVE-2014-8275OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted…MEDIUM 5.0EPSS 15.8%9 January 2015
CVE-2014-3571OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DTLS message that is processed with a different read operation for…MEDIUM 5.0EPSS 23.0%9 January 2015
CVE-2014-3570The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calculate the square of a BIGNUM value, which might make it easier for remote attackers to defeat cryptographic protection mechanisms via…MEDIUM 5.0EPSS 21.9%9 January 2015
CVE-2014-9583common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass…EXPLOIT ×2HIGH 10.0EPSS 80.2%8 January 2015
CVE-2014-9473Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then…EXPLOITHIGH 7.5EPSS 13.8%8 January 2015
CVE-2014-9567Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the…EXPLOIT ×2HIGH 7.5EPSS 43.3%7 January 2015
CVE-2013-2131Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function.EXPLOITMEDIUM 5.0EPSS 10.6%4 January 2015
CVE-2014-9427sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not properly consider the mapping's length during processing of an invalid file that begins with a…HIGH 7.5EPSS 18.3%3 January 2015
CVE-2014-9456Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Event element in an XML file.EXPLOITHIGH 10.0EPSS 10.5%2 January 2015
CVE-2014-9119Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 15.7%31 December 2014
CVE-2014-8109mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote…MEDIUM 4.3EPSS 22.0%29 December 2014
CVE-2011-4722Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.8EPSS 58.2%28 December 2014
CVE-2014-9222AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.HIGH 10.0EPSS 63.7%24 December 2014

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.