Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
17,391 results · page 224 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-2928 | The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11.3.0 through 11.5.1, BIG-IP Analytics 11.0.0 through 11.5.1, BIG-IP Edge… | EXPLOIT ✓HIGH 7.1EPSS 39.1% | 12 May 2014 |
| CVE-2014-3214 | The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that triggers a response with unspecified… | MEDIUM 5.0EPSS 17.3% | 9 May 2014 |
| CVE-2014-2913 | Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. | EXPLOIT ×2HIGH 7.5EPSS 15.3% | 7 May 2014 |
| CVE-2014-0196 | Linux Kernel Race Condition Vulnerability | KEVEXPLOITMEDIUM 5.5EPSS 22.5% | 7 May 2014 |
| CVE-2014-0130 | Ruby on Rails Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 53.7% | 7 May 2014 |
| CVE-2014-0198 | The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL… | MEDIUM 4.3EPSS 43.8% | 6 May 2014 |
| CVE-2014-3220 | F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/. | EXPLOITHIGH 9.0EPSS 11.0% | 5 May 2014 |
| CVE-2014-3000 | The TCP reassembly function in the inet module in FreeBSD 8.3 before p16, 8.4 before p9, 9.1 before p12, 9.2 before p5, and 10.0 before p2 allows remote attackers to cause a denial of service (undefined memory access and system crash) or possibly read… | HIGH 7.8EPSS 12.8% | 2 May 2014 |
| CVE-2014-0114 | Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to… | EXPLOIT ✓HIGH 7.5EPSS 99.0% | 30 April 2014 |
| CVE-2014-0515 | Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the… | EXPLOIT ✓HIGH 10.0EPSS 94.6% | 29 April 2014 |
| CVE-2014-0113 | CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted… | EXPLOIT ✓HIGH 7.5EPSS 77.8% | 29 April 2014 |
| CVE-2014-0112 | ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. | EXPLOIT ×2 ✓HIGH 7.5EPSS 97.9% | 29 April 2014 |
| CVE-2014-2383 | dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a… | EXPLOIT ✓MEDIUM 6.8EPSS 39.2% | 28 April 2014 |
| CVE-2014-3007 | Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py. | HIGH 10.0EPSS 11.6% | 27 April 2014 |
| CVE-2014-1776 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVCRITICAL 9.8EPSS 88.0% | 27 April 2014 |
| CVE-2014-1766 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at… | EXPLOITHIGH 9.3EPSS 33.3% | 27 April 2014 |
| CVE-2014-1765 | Multiple use-after-free vulnerabilities in Microsoft Internet Explorer 6 through 11 allow remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at… | HIGH 7.6EPSS 15.7% | 27 April 2014 |
| CVE-2014-1764 | Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging "object confusion" in a broker process, as demonstrated by VUPEN during a Pwn2Own competition at… | EXPLOITHIGH 10.0EPSS 37.4% | 27 April 2014 |
| CVE-2014-1763 | Use-after-free vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at… | HIGH 10.0EPSS 22.6% | 27 April 2014 |
| CVE-2014-1762 | Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a… | EXPLOITHIGH 7.5EPSS 70.7% | 27 April 2014 |
| CVE-2014-2994 | Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to execute arbitrary code via an HTML file containing an IMG element with a long URL (src attribute). | EXPLOITHIGH 10.0EPSS 26.4% | 27 April 2014 |
| CVE-2013-5660 | Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file. | EXPLOIT ✓HIGH 9.3EPSS 11.2% | 25 April 2014 |
| CVE-2014-2908 | Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOITMEDIUM 4.3EPSS 20.9% | 25 April 2014 |
| CVE-2014-0780 | InduSoft Web Studio NTWebServer Directory Traversal Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 74.4% | 25 April 2014 |
| CVE-2011-5279 | CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a \n (newline) character… | MEDIUM 5.0EPSS 19.2% | 23 April 2014 |
| CVE-2014-2269 | modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPassword parameters. | MEDIUM 6.4EPSS 15.8% | 22 April 2014 |
| CVE-2013-6213 | Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 Patch 1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1833. | HIGH 10.0EPSS 10.5% | 19 April 2014 |
| CVE-2014-2286 | main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack… | HIGH 7.5EPSS 16.4% | 18 April 2014 |
| CVE-2014-0054 | The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct… | MEDIUM 6.8EPSS 91.4% | 17 April 2014 |
| CVE-2013-2143 | The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account. | EXPLOIT ✓MEDIUM 6.5EPSS 48.2% | 17 April 2014 |
| CVE-2014-0644 | EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE)… | EXPLOITHIGH 7.8EPSS 53.3% | 17 April 2014 |
| CVE-2013-4694 | Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. | EXPLOIT ×2 ✓HIGH 7.5EPSS 17.2% | 16 April 2014 |
| CVE-2014-2424 | Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related to CEP system. | EXPLOIT ✓MEDIUM 4.0EPSS 47.4% | 16 April 2014 |
| CVE-2014-0514 | The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute arbitrary code via a crafted PDF document, a related issue to CVE-2012-6636. | EXPLOIT ×2 ✓HIGH 9.3EPSS 72.2% | 15 April 2014 |
| CVE-2014-0107 | The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or… | HIGH 7.5EPSS 13.8% | 15 April 2014 |
| CVE-2013-5704 | The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. | MEDIUM 5.0EPSS 56.3% | 15 April 2014 |
| CVE-2010-5298 | Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an… | MEDIUM 4.0EPSS 34.1% | 14 April 2014 |
| CVE-2014-0128 | Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, related to state management. | MEDIUM 5.0EPSS 32.9% | 14 April 2014 |
| CVE-2014-0787 | Stack-based buffer overflow in WellinTech KingSCADA before 3.1.2.13 allows remote attackers to execute arbitrary code via a crafted packet. | EXPLOITHIGH 10.0EPSS 16.0% | 12 April 2014 |
| CVE-2014-0763 | An attacker using SQL injection may use arguments to construct queries without proper sanitization. | HIGH 7.5EPSS 19.2% | 12 April 2014 |
| CVE-2014-2850 | The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter. | EXPLOIT ✓HIGH 8.5EPSS 57.7% | 11 April 2014 |
| CVE-2014-2849 | The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request. | EXPLOIT ✓HIGH 8.5EPSS 60.3% | 11 April 2014 |
| CVE-2014-2127 | Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 before 8.6(1.13), 9.0 before 9.0(4.1), and 9.1 before 9.1(4.3) does not properly process management-session information during… | HIGH 8.5EPSS 11.5% | 10 April 2014 |
| CVE-2014-1760 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 12.6% | 8 April 2014 |
| CVE-2014-1759 | pubconv.dll in Microsoft Publisher 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via a crafted .pub file, aka "Arbitrary Pointer Dereference… | HIGH 9.3EPSS 14.3% | 8 April 2014 |
| CVE-2014-1758 | Stack-based buffer overflow in Microsoft Word 2003 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Word Stack Overflow Vulnerability." | HIGH 9.3EPSS 16.7% | 8 April 2014 |
| CVE-2014-1757 | Microsoft Word 2007 SP3 and 2010 SP1 and SP2, and Office Compatibility Pack SP3, allocates memory incorrectly for file conversions from a binary (aka .doc) format to a newer format, which allows remote attackers to execute arbitrary code via a crafted… | HIGH 9.3EPSS 17.3% | 8 April 2014 |
| CVE-2014-1755 | Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than… | HIGH 9.3EPSS 20.3% | 8 April 2014 |
| CVE-2014-1753 | Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 20.3% | 8 April 2014 |
| CVE-2014-1752 | Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | HIGH 9.3EPSS 20.3% | 8 April 2014 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.