SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,407 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 150 of 501

CVESummaryPriorityPublished
CVE-2012-5858Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitrary phone contents by spoofing or controlling the IP address.EXPLOITMEDIUM 4.3EPSS 4.27%3 December 2012
CVE-2012-5367Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the sortField parameter to (1) viewCustomers, (2) viewPayGrades, or (3) viewSystemUsers in…EXPLOITMEDIUM 6.0EPSS 1.32%3 December 2012
CVE-2012-5615Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote…EXPLOIT ×2MEDIUM 5.0EPSS 14.8%3 December 2012
CVE-2012-5614Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a…EXPLOITMEDIUM 4.0EPSS 13.2%3 December 2012
CVE-2012-5613MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by…EXPLOIT ×3MEDIUM 6.0EPSS 31.7%3 December 2012
CVE-2012-5612Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute…EXPLOITMEDIUM 6.5EPSS 20.8%3 December 2012
CVE-2012-5611Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before…EXPLOITMEDIUM 6.5EPSS 24.0%3 December 2012
CVE-2012-6050The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request to download the router's DLLs or plugins, as…EXPLOITMEDIUM 6.4EPSS 9.41%27 November 2012
CVE-2012-6048Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file.EXPLOITMEDIUM 5.0EPSS 2.44%27 November 2012
CVE-2012-6047Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that add a user to an arbitrary group via the users page in an adminpanel action to…EXPLOITMEDIUM 6.8EPSS 0.95%27 November 2012
CVE-2012-6046Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the code parameter.EXPLOITHIGH 10.0EPSS 4.13%27 November 2012
CVE-2012-6045Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers to inject arbitrary web script or HTML via the query parameter.EXPLOITMEDIUM 4.3EPSS 1.62%27 November 2012
CVE-2010-5286Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITHIGH 10.0EPSS 12.1%26 November 2012
CVE-2010-5285Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrators for requests that add administrative users via the edituser action.EXPLOITMEDIUM 6.8EPSS 1.33%26 November 2012
CVE-2010-5284Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User parameter in the edit user profile feature to manageuser.php, (2) y parameter in a newcal action to…EXPLOITMEDIUM 4.3EPSS 1.98%26 November 2012
CVE-2010-5281Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 6.8EPSS 2.29%26 November 2012
CVE-2010-5280Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 for Joomla! allows remote attackers to include and execute arbitrary local files via a ..EXPLOITHIGH 7.5EPSS 5.46%26 November 2012
CVE-2012-6044M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.EXPLOITMEDIUM 4.3EPSS 2.48%26 November 2012
CVE-2012-6043Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.EXPLOITMEDIUM 4.3EPSS 1.63%26 November 2012
CVE-2012-6042GPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a lst file.EXPLOITMEDIUM 4.3EPSS 2.09%26 November 2012
CVE-2012-6041Double free vulnerability in GreenBrowser before 6.0.1002, when the keyword search bar (F6) is activated, allows remote attackers to execute arbitrary code via a crafted iframe.EXPLOITMEDIUM 6.8EPSS 3.65%26 November 2012
CVE-2012-6040Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.EXPLOITMEDIUM 4.3EPSS 1.61%26 November 2012
CVE-2012-6039SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to execute arbitrary SQL commands via the gal parameter.EXPLOITHIGH 7.5EPSS 1.11%26 November 2012
CVE-2012-6038admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, move, copy and delete files via the (1) dir parameter in…EXPLOITMEDIUM 6.5EPSS 2.71%26 November 2012
CVE-2012-2437cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.EXPLOITMEDIUM 5.0EPSS 2.43%26 November 2012
CVE-2012-0698tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003.EXPLOITMEDIUM 5.0EPSS 10.5%26 November 2012
CVE-2012-5533The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection:…EXPLOITMEDIUM 5.0EPSS 12.0%24 November 2012
CVE-2012-5864By directly visiting the pages within the device, attackers can gain unauthorized access with administrative privileges.EXPLOITHIGH 10.0EPSS 4.91%23 November 2012
CVE-2012-5863By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.EXPLOITHIGH 10.0EPSS 24.8%23 November 2012
CVE-2012-5862These Sinapsi devices store hard-coded passwords in the PHP file of the device.EXPLOITHIGH 10.0EPSS 12.1%23 November 2012
CVE-2012-5861These Sinapsi devices do not check the validity of the data before executing queries.EXPLOITHIGH 7.5EPSS 4.24%23 November 2012
CVE-2012-4409Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute arbitrary code via an encrypted file with a crafted header containing long salt data that is not properly…EXPLOIT ×2MEDIUM 6.8EPSS 15.1%21 November 2012
CVE-2012-2589Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —20 November 2012
CVE-2012-4366Belkin wireless routers Surf N150 Model F7D1301v1, N900 Model F9K1104v1, N450 Model F9K1105V2, and N300 Model F7D2301v1 generate a predictable default WPA2-PSK passphrase based on eight digits of the WAN MAC address, which allows remote attackers to…EXPLOITLOW 3.3EPSS 4.58%20 November 2012
CVE-2012-5919Multiple cross-site scripting (XSS) vulnerabilities in Havalite 1.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) find or (2) replace fields to havalite/findReplace.php; (3) username parameter to…EXPLOITMEDIUM 4.3EPSS 1.82%19 November 2012
CVE-2012-5918razorCMS 1.2 allows remote authenticated users to access administrator directories and files by creating and deleting a directory.EXPLOITMEDIUM 4.0EPSS 1.52%19 November 2012
CVE-2012-4552Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3d model file that triggers a long error message, as demonstrated by a .ase file.EXPLOITMEDIUM 6.8EPSS 9.97%18 November 2012
CVE-2012-4959Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a ..EXPLOIT ×2HIGH 10.0EPSS 71.2%18 November 2012
CVE-2012-4958Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a ..EXPLOITHIGH 7.8EPSS 73.5%18 November 2012
CVE-2012-4957Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record.EXPLOITHIGH 7.8EPSS 67.6%18 November 2012
CVE-2012-5917SnackAmp 3.1.3 allows remote attackers to cause a denial of service (application crash) via a long string in an aiff file.EXPLOITMEDIUM 4.3EPSS 2.51%17 November 2012
CVE-2012-5913Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.EXPLOITMEDIUM 4.3EPSS 8.69%17 November 2012
CVE-2012-5912Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.php or (2) single.php.EXPLOITHIGH 7.5EPSS 2.42%17 November 2012
CVE-2012-5909SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL commands via the conditions[usergroup][] parameter in a search action to admin/index.php.EXPLOITHIGH 7.5EPSS 1.11%17 November 2012
CVE-2012-5908Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the conditions[usergroup][] parameter in a search action to admin/index.php.EXPLOITMEDIUM 4.3EPSS 1.64%17 November 2012
CVE-2012-5907Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 7.65%17 November 2012
CVE-2012-5905Buffer overflow in KnFTPd 1.0.0 allows remote authenticated users to cause a denial of service (crash) via a long string in a FEAT command.EXPLOITMEDIUM 4.0EPSS 2.86%17 November 2012
CVE-2012-5903Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the scheduled parameter to index.php.EXPLOITMEDIUM 4.3EPSS 1.62%17 November 2012
CVE-2012-5900Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) OB_ID parameter in a single action to admin/action/objects.php, (2) AREA_ID parameter in a single action to…EXPLOITHIGH 7.5EPSS 1.28%17 November 2012
CVE-2012-5899Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the OTR_HEADS[] parameter in an edit action.EXPLOITMEDIUM 4.3EPSS 1.63%17 November 2012

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.