Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,662 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 237 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-1488 | The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the… | EXPLOIT ✓HIGH 10.0EPSS 87.2% | 8 March 2013 |
| CVE-2013-0401 | The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to execute arbitrary code via vectors related to AWT, as… | HIGH 10.0EPSS 10.3% | 8 March 2013 |
| CVE-2010-5107 | The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by… | HIGH 7.5EPSS 16.5% | 7 March 2013 |
| CVE-2013-1643 | The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity… | MEDIUM 5.0EPSS 10.1% | 6 March 2013 |
| CVE-2013-1493 | The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an… | EXPLOIT ✓HIGH 10.0EPSS 86.2% | 5 March 2013 |
| CVE-2013-0809 | Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code via unknown… | HIGH 10.0EPSS 10.8% | 5 March 2013 |
| CVE-2013-0648 | Adobe Flash Player Code Execution Vulnerability | KEVHIGH 8.8EPSS 11.1% | 27 February 2013 |
| CVE-2013-0643 | Adobe Flash Player Incorrect Default Permissions Vulnerability | KEVHIGH 8.8EPSS 10.5% | 27 February 2013 |
| CVE-2012-4558 | Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote… | MEDIUM 4.3EPSS 22.9% | 26 February 2013 |
| CVE-2012-3499 | Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap,… | MEDIUM 4.3EPSS 22.9% | 26 February 2013 |
| CVE-2013-0108 | An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open Manager (aka CPO-M) Station R100; and HMIWeb Browser client packages… | EXPLOIT ✓MEDIUM 6.8EPSS 26.6% | 24 February 2013 |
| CVE-2012-6275 | Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request. | EXPLOIT ✓HIGH 10.0EPSS 46.5% | 24 February 2013 |
| CVE-2012-6274 | BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors. | EXPLOIT ✓MEDIUM 5.0EPSS 46.9% | 24 February 2013 |
| CVE-2012-4705 | Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname. | EXPLOIT ✓HIGH 10.0EPSS 64.9% | 24 February 2013 |
| CVE-2013-0804 | The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 12.4% | 24 February 2013 |
| CVE-2012-0439 | An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an… | EXPLOIT ✓HIGH 9.3EPSS 39.2% | 24 February 2013 |
| CVE-2013-0658 | Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remote attackers to execute arbitrary code via a crafted HTTP request. | EXPLOIT ✓HIGH 10.0EPSS 21.5% | 15 February 2013 |
| CVE-2012-4711 | Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.exe 65.50.2011.18049 in KingView 6.55 allows remote attackers to execute arbitrary code or cause a denial of… | EXPLOIT ✓HIGH 10.0EPSS 61.5% | 15 February 2013 |
| CVE-2013-0641 | Adobe Reader Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 32.3% | 14 February 2013 |
| CVE-2013-0640 | Adobe Reader and Acrobat Memory Corruption Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 86.9% | 14 February 2013 |
| CVE-2013-1114 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud87527. | EXPLOIT ✓MEDIUM 4.3EPSS 10.3% | 13 February 2013 |
| CVE-2012-3363 | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE… | EXPLOITCRITICAL 9.1EPSS 50.2% | 13 February 2013 |
| CVE-2013-1313 | Object Linking and Embedding (OLE) Automation in Microsoft Windows XP SP3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted RTF document, aka "OLE Automation Remote Code Execution Vulnerability." | HIGH 9.3EPSS 22.7% | 13 February 2013 |
| CVE-2013-1281 | The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka… | HIGH 7.1EPSS 23.9% | 13 February 2013 |
| CVE-2013-0077 | Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office… | HIGH 9.3EPSS 24.2% | 13 February 2013 |
| CVE-2013-0075 | The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet… | HIGH 7.8EPSS 69.9% | 13 February 2013 |
| CVE-2013-0073 | The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via… | HIGH 10.0EPSS 29.6% | 13 February 2013 |
| CVE-2013-0030 | The Vector Markup Language (VML) implementation in Microsoft Internet Explorer 6 through 10 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via a crafted web site, aka "VML Memory Corruption Vulnerability." | HIGH 9.3EPSS 26.7% | 13 February 2013 |
| CVE-2013-0029 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CHTML Use After Free Vulnerability." | HIGH 7.5EPSS 30.3% | 13 February 2013 |
| CVE-2013-0028 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CObjectElement Use After Free Vulnerability." | HIGH 9.3EPSS 19.9% | 13 February 2013 |
| CVE-2013-0027 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CPasteCommand Use After Free Vulnerability." | HIGH 9.3EPSS 19.9% | 13 February 2013 |
| CVE-2013-0026 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer InsertElement Use After Free Vulnerability." | HIGH 9.3EPSS 19.9% | 13 February 2013 |
| CVE-2013-0025 | Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability." | EXPLOIT ×2 ✓HIGH 9.3EPSS 55.8% | 13 February 2013 |
| CVE-2013-0024 | Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer pasteHTML Use After Free Vulnerability." | HIGH 9.3EPSS 19.9% | 13 February 2013 |
| CVE-2013-0023 | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CDispNode Use After Free Vulnerability." | HIGH 9.3EPSS 18.6% | 13 February 2013 |
| CVE-2013-0022 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer LsGetTrailInfo Use After Free Vulnerability." | CRITICAL 9.0EPSS 16.8% | 13 February 2013 |
| CVE-2013-0021 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer vtable Use After Free Vulnerability." | HIGH 9.3EPSS 21.2% | 13 February 2013 |
| CVE-2013-0020 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkup Use After Free Vulnerability." | HIGH 9.3EPSS 28.3% | 13 February 2013 |
| CVE-2013-0019 | Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer COmWindowProxy Use After Free… | EXPLOIT ✓HIGH 9.3EPSS 34.9% | 13 February 2013 |
| CVE-2013-0018 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SetCapture Use After Free Vulnerability." | HIGH 9.3EPSS 19.9% | 13 February 2013 |
| CVE-2013-0015 | Microsoft Internet Explorer 6 through 9 does not properly perform auto-selection of the Shift JIS encoding, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers cross-domain scrolling… | MEDIUM 4.3EPSS 15.9% | 13 February 2013 |
| CVE-2013-0269 | The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the… | HIGH 7.5EPSS 13.9% | 13 February 2013 |
| CVE-2013-1373 | Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x… | HIGH 10.0EPSS 10.3% | 12 February 2013 |
| CVE-2013-1372 | Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x… | HIGH 10.0EPSS 10.3% | 12 February 2013 |
| CVE-2013-1370 | Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x… | HIGH 10.0EPSS 10.3% | 12 February 2013 |
| CVE-2013-1369 | Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x… | HIGH 10.0EPSS 10.3% | 12 February 2013 |
| CVE-2013-1368 | Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x… | HIGH 10.0EPSS 10.3% | 12 February 2013 |
| CVE-2013-1367 | Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x… | HIGH 10.0EPSS 10.3% | 12 February 2013 |
| CVE-2013-1366 | Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x… | HIGH 10.0EPSS 10.3% | 12 February 2013 |
| CVE-2013-1365 | Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x… | HIGH 10.0EPSS 10.3% | 12 February 2013 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.