SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

17,391 results · page 217 of 348

CVESummaryPriorityPublished
CVE-2014-7237lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions and upload files with restricted names via a null byte (%00) in a filename to bin/upload.cgi, as demonstrated using…MEDIUM 6.8EPSS 20.1%16 October 2014
CVE-2014-3704The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.EXPLOIT ×5HIGH 7.5EPSS 100.0%16 October 2014
CVE-2014-4278Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors…HIGH 7.5EPSS 10.4%15 October 2014
CVE-2014-4148Microsoft Windows Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 59.9%15 October 2014
CVE-2014-4141Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."EXPLOITHIGH 9.3EPSS 30.5%15 October 2014
CVE-2014-4140Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."MEDIUM 4.3EPSS 20.7%15 October 2014
CVE-2014-4138Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 32.2%15 October 2014
CVE-2014-4137Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…HIGH 9.3EPSS 22.7%15 October 2014
CVE-2014-4134Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."HIGH 9.3EPSS 17.2%15 October 2014
CVE-2014-4133Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…HIGH 9.3EPSS 16.7%15 October 2014
CVE-2014-4132Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…HIGH 9.3EPSS 16.6%15 October 2014
CVE-2014-4130Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…HIGH 9.3EPSS 21.2%15 October 2014
CVE-2014-4129Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."HIGH 9.3EPSS 24.5%15 October 2014
CVE-2014-4128Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."HIGH 9.3EPSS 17.2%15 October 2014
CVE-2014-4127Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."HIGH 9.3EPSS 16.4%15 October 2014
CVE-2014-4126Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."HIGH 9.3EPSS 21.4%15 October 2014
CVE-2014-4124Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-4123.MEDIUM 6.8EPSS 11.6%15 October 2014
CVE-2014-4123Microsoft Internet Explorer Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 47.1%15 October 2014
CVE-2014-4122Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain potentially sensitive information about memory addresses by leveraging the predictability of an executable image's location,…MEDIUM 4.3EPSS 13.1%15 October 2014
CVE-2014-4121Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted…HIGH 10.0EPSS 19.2%15 October 2014
CVE-2014-4117Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP1 and SP2, and Word Web Apps 2010 Gold, SP1, and SP2 allow…HIGH 9.3EPSS 17.5%15 October 2014
CVE-2014-4114Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution VulnerabilityKEVEXPLOIT ×6HIGH 7.8EPSS 81.6%15 October 2014
CVE-2014-4113Microsoft Win32k Privilege Escalation VulnerabilityKEVEXPLOIT ×4HIGH 7.8EPSS 87.0%15 October 2014
CVE-2014-4075Cross-site scripting (XSS) vulnerability in System.Web.Mvc.dll in Microsoft ASP.NET Model View Controller (MVC) 2.0 through 5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted web page, aka "MVC XSS Vulnerability."MEDIUM 4.3EPSS 20.2%15 October 2014
CVE-2014-4073Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka ".NET…HIGH 10.0EPSS 23.4%15 October 2014
CVE-2014-0569Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before…EXPLOITHIGH 9.3EPSS 91.3%15 October 2014
CVE-2014-3566The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.LOW 3.4EPSS 100.0%15 October 2014
CVE-2014-487211.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1)…EXPLOIT ×2HIGH 7.5EPSS 79.3%10 October 2014
CVE-2014-3581The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP…MEDIUM 5.0EPSS 13.6%10 October 2014
CVE-2014-7205Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.EXPLOITHIGH 10.0EPSS 78.6%8 October 2014
CVE-2014-7235htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP…EXPLOITHIGH 10.0EPSS 43.3%7 October 2014
CVE-2014-6287Rejetto HTTP File Server (HFS) Remote Code Execution VulnerabilityKEVEXPLOIT ×4CRITICAL 9.8EPSS 99.3%7 October 2014
CVE-2014-2044Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an…EXPLOITHIGH 7.5EPSS 12.4%6 October 2014
CVE-2014-6278GNU Bash OS Command Injection VulnerabilityKEVEXPLOIT ×5HIGH 8.8EPSS 99.5%30 September 2014
CVE-2013-3632The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.EXPLOITHIGH 8.8EPSS 57.1%29 September 2014
CVE-2014-7187Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply…EXPLOIT ×2HIGH 10.0EPSS 58.5%28 September 2014
CVE-2014-7186The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here…EXPLOIT ×2HIGH 10.0EPSS 64.3%28 September 2014
CVE-2014-6277GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer…EXPLOIT ×3HIGH 10.0EPSS 64.3%27 September 2014
CVE-2014-6446The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.EXPLOITHIGH 7.5EPSS 46.2%26 September 2014
CVE-2014-1568Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x…HIGH 7.5EPSS 16.7%25 September 2014
CVE-2014-7169GNU Bourne-Again Shell (Bash) Arbitrary Code Execution VulnerabilityKEVEXPLOIT ×15CRITICAL 9.8EPSS 99.9%25 September 2014
CVE-2014-6271GNU Bourne-Again Shell (Bash) Arbitrary Code Execution VulnerabilityKEVEXPLOIT ×21CRITICAL 9.8EPSS 100.0%24 September 2014
CVE-2006-1318Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka…HIGH 9.3EPSS 15.5%19 September 2014
CVE-2014-4404Apple OS X Heap-Based Buffer Overflow VulnerabilityKEVEXPLOITHIGH 7.8EPSS 48.9%18 September 2014
CVE-2014-6270Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which…MEDIUM 6.8EPSS 23.3%12 September 2014
CVE-2013-4444Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.MEDIUM 6.8EPSS 14.0%12 September 2014
CVE-2014-3609HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."MEDIUM 5.0EPSS 56.2%11 September 2014
CVE-2014-6043ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do.EXPLOITMEDIUM 6.5EPSS 12.8%11 September 2014
CVE-2014-5460Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in…EXPLOIT ×2MEDIUM 6.5EPSS 70.9%11 September 2014
CVE-2014-5519The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp.EXPLOITHIGH 7.5EPSS 65.0%11 September 2014

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.