Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,662 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,391 results · page 236 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-2419 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown… | EXPLOITMEDIUM 5.0EPSS 22.6% | 17 April 2013 |
| CVE-2013-1559 | Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect availability via unknown vectors related to Content Server. | EXPLOIT ✓MEDIUM 4.0EPSS 58.8% | 17 April 2013 |
| CVE-2013-1304 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different… | HIGH 9.3EPSS 20.0% | 9 April 2013 |
| CVE-2013-1303 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different… | HIGH 9.3EPSS 20.5% | 9 April 2013 |
| CVE-2013-1296 | The Remote Desktop ActiveX control in mstscax.dll in Microsoft Remote Desktop Connection Client 6.1 and 7.0 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a web page that triggers access to a… | HIGH 9.3EPSS 20.7% | 9 April 2013 |
| CVE-2013-1290 | Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list… | LOW 3.5EPSS 17.0% | 9 April 2013 |
| CVE-2013-1289 | Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string,… | MEDIUM 4.3EPSS 15.4% | 9 April 2013 |
| CVE-2013-1282 | The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), and Active Directory Services allows remote attackers to cause a denial of service (memory consumption and… | MEDIUM 5.0EPSS 27.0% | 9 April 2013 |
| CVE-2013-0680 | Stack-based buffer overflow in the web server in Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allows remote attackers to cause a denial of… | HIGH 7.5EPSS 18.8% | 5 April 2013 |
| CVE-2013-1899 | Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users to modify configuration settings… | MEDIUM 6.5EPSS 54.3% | 4 April 2013 |
| CVE-2013-1082 | Directory traversal vulnerability in DUSAP.php in Novell ZENworks Mobile Management before 2.7.1 allows remote attackers to include and execute arbitrary local files via the language parameter. | HIGH 7.5EPSS 12.8% | 29 March 2013 |
| CVE-2013-1080 | The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently… | EXPLOIT ✓HIGH 10.0EPSS 77.0% | 29 March 2013 |
| CVE-2013-1861 | MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted… | EXPLOIT ✓MEDIUM 5.0EPSS 18.7% | 28 March 2013 |
| CVE-2013-2266 | libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression, as… | HIGH 7.8EPSS 42.9% | 28 March 2013 |
| CVE-2013-0332 | Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 10.2% | 20 March 2013 |
| CVE-2013-0232 | includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command… | EXPLOIT ✓HIGH 7.5EPSS 47.9% | 20 March 2013 |
| CVE-2013-2492 | Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during… | EXPLOIT ✓MEDIUM 6.8EPSS 42.2% | 15 March 2013 |
| CVE-2013-2566 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use… | MEDIUM 5.9EPSS 84.4% | 15 March 2013 |
| CVE-2013-1814 | The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password… | EXPLOITMEDIUM 4.0EPSS 73.8% | 14 March 2013 |
| CVE-2013-1469 | Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 4.0EPSS 56.0% | 13 March 2013 |
| CVE-2013-2558 | Unspecified vulnerability in Microsoft Windows 8 allows remote attackers to cause a denial of service (reboot) or possibly have unknown other impact via a crafted TrueType Font (TTF) file, as demonstrated by the 120612-69701-01.dmp error report. | HIGH 10.0EPSS 14.4% | 13 March 2013 |
| CVE-2013-1288 | Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CTreeNode Use After Free Vulnerability." | HIGH 9.3EPSS 18.5% | 13 March 2013 |
| CVE-2013-0095 | Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5… | MEDIUM 5.0EPSS 20.8% | 13 March 2013 |
| CVE-2013-0094 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer removeChild Use After Free Vulnerability." | HIGH 9.3EPSS 18.5% | 13 March 2013 |
| CVE-2013-0093 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer onBeforeCopy Use After Free Vulnerability." | HIGH 9.3EPSS 18.5% | 13 March 2013 |
| CVE-2013-0092 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer GetMarkupPtr Use After Free Vulnerability." | HIGH 9.3EPSS 28.2% | 13 March 2013 |
| CVE-2013-0091 | Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CElement Use After Free Vulnerability." | HIGH 9.3EPSS 19.8% | 13 March 2013 |
| CVE-2013-0090 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CCaret Use After Free Vulnerability." | EXPLOIT ✓HIGH 8.8EPSS 38.2% | 13 March 2013 |
| CVE-2013-0089 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkupBehaviorContext Use After Free… | HIGH 9.3EPSS 18.5% | 13 March 2013 |
| CVE-2013-0088 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer saveHistory Use After Free Vulnerability." | HIGH 9.3EPSS 19.8% | 13 March 2013 |
| CVE-2013-0087 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer OnResize Use After Free Vulnerability." | HIGH 9.3EPSS 18.5% | 13 March 2013 |
| CVE-2013-0086 | Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability." | MEDIUM 5.0EPSS 24.0% | 13 March 2013 |
| CVE-2013-0085 | Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability." | HIGH 7.8EPSS 34.0% | 13 March 2013 |
| CVE-2013-0084 | Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory… | HIGH 7.5EPSS 21.3% | 13 March 2013 |
| CVE-2013-0083 | Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability." | MEDIUM 4.3EPSS 14.3% | 13 March 2013 |
| CVE-2013-0080 | Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability." | HIGH 7.5EPSS 19.3% | 13 March 2013 |
| CVE-2013-0079 | Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability." | HIGH 9.3EPSS 26.7% | 13 March 2013 |
| CVE-2013-0074 | Microsoft Silverlight Double Dereference Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 81.0% | 13 March 2013 |
| CVE-2013-1081 | Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote attackers to include and execute arbitrary local files via the language parameter. | EXPLOIT ✓HIGH 7.5EPSS 68.1% | 11 March 2013 |
| CVE-2013-2557 | The sandbox protection mechanism in Microsoft Internet Explorer 9 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN… | HIGH 7.5EPSS 10.9% | 11 March 2013 |
| CVE-2013-2552 | Unspecified vulnerability in Microsoft Internet Explorer 10 on Windows 8 allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a Medium integrity process, as demonstrated by VUPEN during a Pwn2Own competition at… | HIGH 7.5EPSS 14.4% | 11 March 2013 |
| CVE-2013-2551 | Microsoft Internet Explorer Use-After-Free Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 74.1% | 11 March 2013 |
| CVE-2012-5204 | Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service… | HIGH 7.5EPSS 18.5% | 9 March 2013 |
| CVE-2012-5203 | Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service… | HIGH 7.5EPSS 21.0% | 9 March 2013 |
| CVE-2012-5202 | Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service… | HIGH 7.5EPSS 21.0% | 9 March 2013 |
| CVE-2012-5201 | Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1611. | EXPLOIT ✓HIGH 10.0EPSS 63.7% | 9 March 2013 |
| CVE-2013-0249 | Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to cause a denial of service (crash)… | EXPLOITHIGH 7.5EPSS 21.6% | 8 March 2013 |
| CVE-2011-4969 | Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag. | MEDIUM 4.3EPSS 19.2% | 8 March 2013 |
| CVE-2013-1491 | The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via vectors related to 2D, as… | HIGH 10.0EPSS 16.4% | 8 March 2013 |
| CVE-2013-1488 | The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the… | EXPLOIT ✓HIGH 10.0EPSS 87.2% | 8 March 2013 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.