Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
17,391 results · page 215 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-8601 | PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite number of referrals, as demonstrated by resolving domains hosted by… | MEDIUM 5.0EPSS 68.9% | 10 December 2014 |
| CVE-2014-8730 | The SSL profiles component in F5 BIG-IP LTM, APM, and ASM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, AAM 11.4.0 through 11.5.1, AFM 11.3.0 through 11.5.1, Analytics 11.0.0 through 11.5.1, Edge Gateway, WebAccelerator, and WOM 10.1.0 through 10.2.4… | MEDIUM 4.3EPSS 13.7% | 10 December 2014 |
| CVE-2014-9130 | scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping. | MEDIUM 5.0EPSS 13.2% | 8 December 2014 |
| CVE-2014-9029 | Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based… | HIGH 7.5EPSS 18.4% | 8 December 2014 |
| CVE-2014-9218 | libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password. | EXPLOITMEDIUM 5.0EPSS 10.7% | 8 December 2014 |
| CVE-2014-4880 | Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote attackers to execute arbitrary code via an RTSP PLAY request with a long Authorization header. | EXPLOIT ✓HIGH 7.5EPSS 70.7% | 8 December 2014 |
| CVE-2014-8877 | The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/,… | EXPLOITHIGH 10.0EPSS 14.4% | 5 December 2014 |
| CVE-2014-3997 | SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before… | EXPLOIT ✓HIGH 7.5EPSS 13.1% | 5 December 2014 |
| CVE-2014-3996 | SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service… | EXPLOIT ✓HIGH 7.5EPSS 38.4% | 5 December 2014 |
| CVE-2014-7868 | Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) OPM_BVNAME parameter in… | EXPLOIT ×2HIGH 7.5EPSS 73.3% | 4 December 2014 |
| CVE-2014-7867 | SQL injection vulnerability in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allows remote attackers or remote authenticated users to… | HIGH 7.5EPSS 39.9% | 4 December 2014 |
| CVE-2014-6036 | Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via… | EXPLOITMEDIUM 6.4EPSS 36.3% | 4 December 2014 |
| CVE-2014-6035 | Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier allows remote attackers to write and execute arbitrary files via a .. | EXPLOITHIGH 7.5EPSS 28.8% | 4 December 2014 |
| CVE-2014-6034 | Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8 through 11.3, Social IT Plus 11.0, and IT360 10.4 and earlier allows remote attackers or remote… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 79.0% | 4 December 2014 |
| CVE-2014-5446 | Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote attackers and remote authenticated users to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 54.7% | 4 December 2014 |
| CVE-2014-5445 | Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remote authenticated users to read arbitrary files via a full pathname in the schFilePath parameter to the… | EXPLOITMEDIUM 5.0EPSS 98.0% | 4 December 2014 |
| CVE-2014-8791 | project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter. | EXPLOIT ✓MEDIUM 6.0EPSS 14.8% | 2 December 2014 |
| CVE-2014-7816 | Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. | MEDIUM 5.0EPSS 25.1% | 1 December 2014 |
| CVE-2014-8801 | Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 18.0% | 28 November 2014 |
| CVE-2014-8799 | Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 67.6% | 28 November 2014 |
| CVE-2014-8424 | ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication. | EXPLOITHIGH 7.8EPSS 59.6% | 28 November 2014 |
| CVE-2014-8423 | Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors. | EXPLOITHIGH 10.0EPSS 62.5% | 28 November 2014 |
| CVE-2014-7142 | The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size. | MEDIUM 6.4EPSS 24.9% | 26 November 2014 |
| CVE-2014-7141 | The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet. | MEDIUM 6.4EPSS 76.1% | 26 November 2014 |
| CVE-2014-9034 | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a… | EXPLOIT ×2MEDIUM 5.0EPSS 82.7% | 25 November 2014 |
| CVE-2014-8439 | Adobe Flash Player Dereferenced Pointer Vulnerability | KEVHIGH 8.8EPSS 20.4% | 25 November 2014 |
| CVE-2014-8420 | The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote authenticated users to execute arbitrary code via unspecified vectors. | HIGH 9.0EPSS 24.0% | 25 November 2014 |
| CVE-2010-5312 | Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option. | MEDIUM 6.1EPSS 18.4% | 24 November 2014 |
| CVE-2014-9016 | The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request. | EXPLOITMEDIUM 5.0EPSS 82.2% | 24 November 2014 |
| CVE-2014-8682 | Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in… | EXPLOITHIGH 7.5EPSS 33.4% | 21 November 2014 |
| CVE-2014-8768 | Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame. | EXPLOITMEDIUM 5.0EPSS 19.8% | 20 November 2014 |
| CVE-2014-3625 | Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling. | MEDIUM 5.0EPSS 10.3% | 20 November 2014 |
| CVE-2014-8998 | lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.php, which is processed by the preg_replace function with the eval switch. | EXPLOIT ✓MEDIUM 6.5EPSS 35.9% | 20 November 2014 |
| CVE-2014-8387 | cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi. | EXPLOIT ✓HIGH 9.0EPSS 30.9% | 20 November 2014 |
| CVE-2014-6324 | Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 87.3% | 18 November 2014 |
| CVE-2014-8598 | The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive information via the export page. | EXPLOIT ✓MEDIUM 6.4EPSS 38.5% | 18 November 2014 |
| CVE-2014-7146 | The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an XML file, which is not properly handled when executing the preg_replace… | EXPLOIT ×2 ✓HIGH 7.5EPSS 50.6% | 18 November 2014 |
| CVE-2014-7992 | The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014. | MEDIUM 5.0EPSS 27.2% | 18 November 2014 |
| CVE-2014-8517 | The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP… | EXPLOIT ×2 ✓HIGH 7.5EPSS 69.1% | 17 November 2014 |
| CVE-2014-8499 | Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the… | EXPLOITMEDIUM 6.5EPSS 36.4% | 17 November 2014 |
| CVE-2014-8498 | SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands… | EXPLOITMEDIUM 6.5EPSS 12.7% | 17 November 2014 |
| CVE-2014-2268 | views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by… | EXPLOIT ✓MEDIUM 5.0EPSS 31.2% | 16 November 2014 |
| CVE-2014-7878 | The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to… | HIGH 10.0EPSS 10.3% | 14 November 2014 |
| CVE-2014-5424 | Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an invalid property value to an ActiveX control that was built with… | HIGH 7.5EPSS 11.0% | 14 November 2014 |
| CVE-2014-1635 | Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote attackers to execute arbitrary code via a long string in the jump parameter. | EXPLOIT ✓HIGH 10.0EPSS 67.5% | 12 November 2014 |
| CVE-2014-8440 | Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers… | EXPLOIT ✓HIGH 10.0EPSS 81.9% | 11 November 2014 |
| CVE-2014-0582 | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler… | HIGH 10.0EPSS 11.4% | 11 November 2014 |
| CVE-2014-6353 | Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 15.5% | 11 November 2014 |
| CVE-2014-6351 | Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 22.5% | 11 November 2014 |
| CVE-2014-6350 | Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-6349. | MEDIUM 4.3EPSS 20.6% | 11 November 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.