SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,662 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

17,391 results · page 235 of 348

CVESummaryPriorityPublished
CVE-2012-6554functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the message[message_text] parameter to chat/add_messag, which is not properly handled when executing the…EXPLOITMEDIUM 6.5EPSS 16.7%23 May 2013
CVE-2013-2842Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of widgets.EXPLOITHIGH 7.5EPSS 12.0%22 May 2013
CVE-2013-2730Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2733.EXPLOITHIGH 10.0EPSS 78.8%16 May 2013
CVE-2013-2729Adobe Reader and Acrobat Arbitrary Integer Overflow VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 66.6%16 May 2013
CVE-2013-1670The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content…EXPLOITMEDIUM 4.3EPSS 10.9%16 May 2013
CVE-2013-1346mpengine.dll in Microsoft Malware Protection Engine before 1.1.9506.0 on x64 platforms allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.HIGH 9.3EPSS 11.6%15 May 2013
CVE-2013-1337Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass…HIGH 7.5EPSS 20.6%15 May 2013
CVE-2013-1336The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve…MEDIUM 5.0EPSS 19.3%15 May 2013
CVE-2013-1335Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."HIGH 9.3EPSS 20.9%15 May 2013
CVE-2013-1329Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."HIGH 9.3EPSS 20.8%15 May 2013
CVE-2013-1328Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."HIGH 9.3EPSS 20.8%15 May 2013
CVE-2013-1327Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper memory allocation, aka "Publisher Signed Integer Vulnerability."HIGH 9.3EPSS 20.8%15 May 2013
CVE-2013-1323Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."HIGH 9.3EPSS 20.8%15 May 2013
CVE-2013-1322Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."HIGH 10.0EPSS 25.3%15 May 2013
CVE-2013-1321Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Validation Vulnerability."HIGH 9.3EPSS 21.7%15 May 2013
CVE-2013-1320Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow Vulnerability."HIGH 10.0EPSS 29.0%15 May 2013
CVE-2013-1319Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."HIGH 10.0EPSS 25.1%15 May 2013
CVE-2013-1318Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."HIGH 10.0EPSS 26.2%15 May 2013
CVE-2013-1317Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper allocation-size calculation, aka "Publisher Integer Overflow Vulnerability."HIGH 9.3EPSS 20.9%15 May 2013
CVE-2013-1316Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Negative Value Allocation Vulnerability."HIGH 9.3EPSS 21.8%15 May 2013
CVE-2013-1312Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."HIGH 9.3EPSS 20.6%15 May 2013
CVE-2013-1311Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."EXPLOITHIGH 9.3EPSS 20.7%15 May 2013
CVE-2013-1310Use-after-free vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."HIGH 9.3EPSS 20.6%15 May 2013
CVE-2013-1309Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different…EXPLOITHIGH 9.3EPSS 39.1%15 May 2013
CVE-2013-1308Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different…HIGH 9.3EPSS 20.9%15 May 2013
CVE-2013-1307Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different…HIGH 9.3EPSS 20.6%15 May 2013
CVE-2013-1306Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different…EXPLOITHIGH 9.3EPSS 33.4%15 May 2013
CVE-2013-1305HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."HIGH 7.8EPSS 54.7%15 May 2013
CVE-2013-1302Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync…HIGH 9.3EPSS 21.9%15 May 2013
CVE-2013-1301Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."MEDIUM 4.3EPSS 16.7%15 May 2013
CVE-2013-1297Microsoft Internet Explorer 6 through 8 does not properly restrict data access by VBScript, which allows remote attackers to perform cross-domain reading of JSON files via a crafted web site, aka "JSON Array Information Disclosure Vulnerability."MEDIUM 4.3EPSS 16.8%15 May 2013
CVE-2013-0811Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different…HIGH 9.3EPSS 20.6%15 May 2013
CVE-2013-0096Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability."MEDIUM 6.8EPSS 16.1%15 May 2013
CVE-2013-2094Linux Kernel Privilege Escalation VulnerabilityKEVEXPLOIT ×3HIGH 8.4EPSS 47.7%14 May 2013
CVE-2013-3526Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the aoid parameter.EXPLOITMEDIUM 4.3EPSS 13.9%10 May 2013
CVE-2013-3522SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter.EXPLOIT ×2MEDIUM 6.5EPSS 27.1%10 May 2013
CVE-2013-0946Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to execute arbitrary code via crafted commands.EXPLOITHIGH 9.3EPSS 28.5%10 May 2013
CVE-2013-3336Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors.EXPLOITMEDIUM 5.0EPSS 74.3%9 May 2013
CVE-2013-3502monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and consequently obtain sensitive information, by leveraging a JOSSO SSO cookie.EXPLOITMEDIUM 6.5EPSS 53.7%8 May 2013
CVE-2013-1347Microsoft Internet Explorer Remote Code Execution VulnerabilityKEVEXPLOITHIGH 8.8EPSS 77.7%5 May 2013
CVE-2013-0726Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 13.00.0001 allows remote attackers to execute arbitrary code via a crafted pathname in an ERS file.EXPLOITHIGH 9.3EPSS 28.0%5 May 2013
CVE-2013-1884The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized…EXPLOITMEDIUM 5.0EPSS 50.5%2 May 2013
CVE-2013-1847The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.EXPLOITMEDIUM 5.0EPSS 51.4%2 May 2013
CVE-2013-1338Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different…HIGH 9.3EPSS 20.5%2 May 2013
CVE-2012-5946Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execute arbitrary code via a long TabCaption string.EXPLOITHIGH 9.3EPSS 33.8%30 April 2013
CVE-2013-1428Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of service (crash) or possibly execute arbitrary code via a large TCP packet.EXPLOITMEDIUM 6.5EPSS 60.7%26 April 2013
CVE-2013-3238phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature.EXPLOIT ×2MEDIUM 6.0EPSS 28.9%26 April 2013
CVE-2013-0233Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause…MEDIUM 6.8EPSS 14.1%25 April 2013
CVE-2013-3075Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities 7.10 and CitectScada 7.10r1, allow remote attackers to execute arbitrary code via a long string, as demonstrated by a long WzTitle…EXPLOITHIGH 10.0EPSS 10.8%19 April 2013
CVE-2013-2423Oracle JRE Unspecified VulnerabilityKEVEXPLOITLOW 3.7EPSS 85.2%17 April 2013

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.