Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
17,391 results · page 217 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-7237 | lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions and upload files with restricted names via a null byte (%00) in a filename to bin/upload.cgi, as demonstrated using… | MEDIUM 6.8EPSS 20.1% | 16 October 2014 |
| CVE-2014-3704 | The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys. | EXPLOIT ×5 ✓HIGH 7.5EPSS 100.0% | 16 October 2014 |
| CVE-2014-4278 | Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors… | HIGH 7.5EPSS 10.4% | 15 October 2014 |
| CVE-2014-4148 | Microsoft Windows Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 59.9% | 15 October 2014 |
| CVE-2014-4141 | Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | EXPLOITHIGH 9.3EPSS 30.5% | 15 October 2014 |
| CVE-2014-4140 | Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability." | MEDIUM 4.3EPSS 20.7% | 15 October 2014 |
| CVE-2014-4138 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | EXPLOIT ✓HIGH 9.3EPSS 32.2% | 15 October 2014 |
| CVE-2014-4137 | Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 22.7% | 15 October 2014 |
| CVE-2014-4134 | Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 17.2% | 15 October 2014 |
| CVE-2014-4133 | Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 16.7% | 15 October 2014 |
| CVE-2014-4132 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 16.6% | 15 October 2014 |
| CVE-2014-4130 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 21.2% | 15 October 2014 |
| CVE-2014-4129 | Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 24.5% | 15 October 2014 |
| CVE-2014-4128 | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 17.2% | 15 October 2014 |
| CVE-2014-4127 | Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 16.4% | 15 October 2014 |
| CVE-2014-4126 | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 21.4% | 15 October 2014 |
| CVE-2014-4124 | Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-4123. | MEDIUM 6.8EPSS 11.6% | 15 October 2014 |
| CVE-2014-4123 | Microsoft Internet Explorer Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 47.1% | 15 October 2014 |
| CVE-2014-4122 | Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain potentially sensitive information about memory addresses by leveraging the predictability of an executable image's location,… | MEDIUM 4.3EPSS 13.1% | 15 October 2014 |
| CVE-2014-4121 | Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | HIGH 10.0EPSS 19.2% | 15 October 2014 |
| CVE-2014-4117 | Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP1 and SP2, and Word Web Apps 2010 Gold, SP1, and SP2 allow… | HIGH 9.3EPSS 17.5% | 15 October 2014 |
| CVE-2014-4114 | Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability | KEVEXPLOIT ×6 ✓HIGH 7.8EPSS 81.6% | 15 October 2014 |
| CVE-2014-4113 | Microsoft Win32k Privilege Escalation Vulnerability | KEVEXPLOIT ×4 ✓HIGH 7.8EPSS 87.0% | 15 October 2014 |
| CVE-2014-4075 | Cross-site scripting (XSS) vulnerability in System.Web.Mvc.dll in Microsoft ASP.NET Model View Controller (MVC) 2.0 through 5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted web page, aka "MVC XSS Vulnerability." | MEDIUM 4.3EPSS 20.2% | 15 October 2014 |
| CVE-2014-4073 | Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka ".NET… | HIGH 10.0EPSS 23.4% | 15 October 2014 |
| CVE-2014-0569 | Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before… | EXPLOIT ✓HIGH 9.3EPSS 91.3% | 15 October 2014 |
| CVE-2014-3566 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. | LOW 3.4EPSS 100.0% | 15 October 2014 |
| CVE-2014-4872 | 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 79.3% | 10 October 2014 |
| CVE-2014-3581 | The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP… | MEDIUM 5.0EPSS 13.6% | 10 October 2014 |
| CVE-2014-7205 | Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 78.6% | 8 October 2014 |
| CVE-2014-7235 | htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP… | EXPLOITHIGH 10.0EPSS 43.3% | 7 October 2014 |
| CVE-2014-6287 | Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability | KEVEXPLOIT ×4 ✓CRITICAL 9.8EPSS 99.3% | 7 October 2014 |
| CVE-2014-2044 | Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an… | EXPLOIT ✓HIGH 7.5EPSS 12.4% | 6 October 2014 |
| CVE-2014-6278 | GNU Bash OS Command Injection Vulnerability | KEVEXPLOIT ×5 ✓HIGH 8.8EPSS 99.5% | 30 September 2014 |
| CVE-2013-3632 | The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter. | EXPLOIT ✓HIGH 8.8EPSS 57.1% | 29 September 2014 |
| CVE-2014-7187 | Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply… | EXPLOIT ×2 ✓HIGH 10.0EPSS 58.5% | 28 September 2014 |
| CVE-2014-7186 | The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here… | EXPLOIT ×2 ✓HIGH 10.0EPSS 64.3% | 28 September 2014 |
| CVE-2014-6277 | GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer… | EXPLOIT ×3 ✓HIGH 10.0EPSS 64.3% | 27 September 2014 |
| CVE-2014-6446 | The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php. | EXPLOIT ✓HIGH 7.5EPSS 46.2% | 26 September 2014 |
| CVE-2014-1568 | Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x… | HIGH 7.5EPSS 16.7% | 25 September 2014 |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | KEVEXPLOIT ×15 ✓CRITICAL 9.8EPSS 99.9% | 25 September 2014 |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | KEVEXPLOIT ×21 ✓CRITICAL 9.8EPSS 100.0% | 24 September 2014 |
| CVE-2006-1318 | Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka… | HIGH 9.3EPSS 15.5% | 19 September 2014 |
| CVE-2014-4404 | Apple OS X Heap-Based Buffer Overflow Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 48.9% | 18 September 2014 |
| CVE-2014-6270 | Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which… | MEDIUM 6.8EPSS 23.3% | 12 September 2014 |
| CVE-2013-4444 | Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file. | MEDIUM 6.8EPSS 14.0% | 12 September 2014 |
| CVE-2014-3609 | HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values." | MEDIUM 5.0EPSS 56.2% | 11 September 2014 |
| CVE-2014-6043 | ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. | EXPLOITMEDIUM 6.5EPSS 12.8% | 11 September 2014 |
| CVE-2014-5460 | Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in… | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 70.9% | 11 September 2014 |
| CVE-2014-5519 | The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. | EXPLOITHIGH 7.5EPSS 65.0% | 11 September 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.