SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,407 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 151 of 501

CVESummaryPriorityPublished
CVE-2012-5898Cross-site request forgery (CSRF) vulnerability in SAMEDIA LandShop 0.9.2 allows remote attackers to hijack the authentication of administrators for requests that change account settings.EXPLOITMEDIUM 6.8EPSS 1.08%17 November 2012
CVE-2012-5897The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the…EXPLOITHIGH 9.3EPSS 3.83%17 November 2012
CVE-2012-5896The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Add method, which allows remote attackers to execute arbitrary code via a memory address in the first argument,…EXPLOIT ×2HIGH 10.0EPSS 69.4%17 November 2012
CVE-2012-5894SQL injection vulnerability in hava_post.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the postId parameter.EXPLOITHIGH 7.5EPSS 1.12%17 November 2012
CVE-2012-5891Multiple cross-site request forgery (CSRF) vulnerabilities in photo/pass.php in DAlbum 1.44 build 174 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an add action, (2) change user…EXPLOITMEDIUM 6.8EPSS 1.07%17 November 2012
CVE-2012-5851html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS)…EXPLOITMEDIUM 4.3EPSS 2.28%15 November 2012
CVE-2012-4951Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.EXPLOITHIGH 7.5EPSS 1.52%15 November 2012
CVE-2012-4949SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query URI for a REST service.EXPLOITMEDIUM 6.5EPSS 4.39%14 November 2012
CVE-2012-3569Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.EXPLOIT ×2HIGH 9.3EPSS 47.7%14 November 2012
CVE-2012-2619The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung, and Sony products, allow remote attackers to cause a denial of service (out-of-bounds read and Wi-Fi…EXPLOITHIGH 7.8EPSS 12.9%14 November 2012
CVE-2012-4515Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when…EXPLOITMEDIUM 6.8EPSS 6.44%11 November 2012
CVE-2012-4514rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."EXPLOITMEDIUM 5.0EPSS 9.70%11 November 2012
CVE-2012-4513khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.EXPLOITMEDIUM 6.4EPSS 12.6%11 November 2012
CVE-2012-3755Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Targa image.EXPLOITHIGH 9.3EPSS 10.2%9 November 2012
CVE-2012-3753Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIME type.EXPLOITHIGH 9.3EPSS 35.1%9 November 2012
CVE-2012-3752Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted style element in a QuickTime TeXML file.EXPLOITHIGH 9.3EPSS 36.0%9 November 2012
CVE-2012-3748Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.EXPLOITMEDIUM 5.1EPSS 16.7%3 November 2012
CVE-2012-0025Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.EXPLOITMEDIUM 6.8EPSS 6.36%2 November 2012
CVE-2012-5687Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.8EPSS 68.7%1 November 2012
CVE-2012-5409AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute…EXPLOITHIGH 10.0EPSS 15.8%1 November 2012
CVE-2012-4940Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a ..EXPLOITMEDIUM 6.4EPSS 83.6%31 October 2012
CVE-2012-4939Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP…EXPLOITMEDIUM 4.3EPSS 7.17%31 October 2012
CVE-2012-5692Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impact and remote attack vectors.EXPLOIT ×3HIGH 10.0EPSS 26.0%31 October 2012
CVE-2012-5470libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file.EXPLOITMEDIUM 4.3EPSS 5.85%26 October 2012
CVE-2011-5233Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.EXPLOITMEDIUM 4.3EPSS 9.32%25 October 2012
CVE-2011-5232Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —25 October 2012
CVE-2011-5230Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to…EXPLOITHIGH 7.5EPSS 2.24%25 October 2012
CVE-2011-5229SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.EXPLOITHIGH 7.5EPSS 2.22%25 October 2012
CVE-2011-5228Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web script or HTML via the ss parameter.EXPLOITMEDIUM 4.3EPSS 3.89%25 October 2012
CVE-2011-5227Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers to execute arbitrary code via a long PRIO field in a message to UDP port 514.EXPLOITHIGH 10.0EPSS 77.0%25 October 2012
CVE-2011-5222SQL injection vulnerability in rub2_w.php in PHP Flirt-Projekt 4.8 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the rub parameter.EXPLOITHIGH 7.5EPSS 2.24%25 October 2012
CVE-2011-5219Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 9.16%25 October 2012
CVE-2011-5218SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.EXPLOITHIGH 7.5EPSS 2.23%25 October 2012
CVE-2011-5214Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3)…EXPLOIT ×4MEDIUM 4.3EPSS 4.85%25 October 2012
CVE-2011-5213Multiple SQL injection vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login[username] parameter to index.php, (2) parent_id parameter to modules/Documents/version_list.php, or (3)…EXPLOIT ×2HIGH 7.5EPSS 2.45%25 October 2012
CVE-2012-5672Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file…EXPLOITMEDIUM 4.3EPSS 12.5%25 October 2012
CVE-2012-5388Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wlcms_o_developer_name parameter in a save action to…EXPLOITLOW 3.5EPSS 3.90%24 October 2012
CVE-2012-5387Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify the developer name via the…EXPLOITMEDIUM 6.8EPSS 2.99%24 October 2012
CVE-2012-5453SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbitrary SQL commands via the field parameter.EXPLOITMEDIUM 6.5EPSS 2.74%22 October 2012
CVE-2012-5452Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/add/; (2) cost, (3) days, or (4) title[en] parameter to plans/add/; (5)…EXPLOITMEDIUM 4.3EPSS 5.08%22 October 2012
CVE-2012-5167Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to course_category/index_inline_editor_submit.php or (2) user/index_inline_editor_submit.php; or…EXPLOITHIGH 7.5EPSS 4.70%22 October 2012
CVE-2012-4989Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject arbitrary web script or HTML via the parent parameter in an info action.EXPLOITMEDIUM 4.3EPSS 4.39%22 October 2012
CVE-2012-4773Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding an…EXPLOIT ×2MEDIUM 6.8EPSS 3.49%22 October 2012
CVE-2012-4772SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id parameter.EXPLOITHIGH 7.5EPSS 3.72%22 October 2012
CVE-2012-4771Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group…EXPLOITMEDIUM 4.3EPSS 4.39%22 October 2012
CVE-2012-4231Cross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject arbitrary web script or HTML via the path parameter.EXPLOITMEDIUM 4.3EPSS 4.30%22 October 2012
CVE-2012-1900Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action.EXPLOITMEDIUM 6.8EPSS 2.63%22 October 2012
CVE-2011-5212SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field.EXPLOITHIGH 7.5EPSS 3.42%22 October 2012
CVE-2011-5211Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field.EXPLOITMEDIUM 4.3EPSS 3.86%22 October 2012
CVE-2010-4821Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.EXPLOITMEDIUM 4.3EPSS 4.74%22 October 2012

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.