SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,407 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 152 of 501

CVESummaryPriorityPublished
CVE-2012-4751Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and 3.1.x before 3.1.11 allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with…EXPLOIT ×2MEDIUM 4.3EPSS 5.79%22 October 2012
CVE-2012-3001Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection vulnerability."EXPLOITHIGH 8.5EPSS 27.3%22 October 2012
CVE-2012-3221Unspecified vulnerability in the Oracle VM Virtual Box component in Oracle Virtualization 3.2, 4.0, and 4.1 allows local users to affect availability via unknown vectors related to VirtualBox Core.EXPLOITLOW 2.1EPSS 0.79%17 October 2012
CVE-2012-3186Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via…EXPLOITMEDIUM 4.9EPSS 4.21%17 October 2012
CVE-2012-3185Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via…EXPLOITMEDIUM 4.9EPSS 4.21%17 October 2012
CVE-2012-3184Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote attackers to affect integrity via unknown vectors related to Advanced…EXPLOITMEDIUM 4.3EPSS 4.46%17 October 2012
CVE-2012-3183Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via…EXPLOITMEDIUM 4.9EPSS 4.21%17 October 2012
CVE-2012-3153Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet.EXPLOITMEDIUM 6.4EPSS 98.2%16 October 2012
CVE-2012-3152Oracle Fusion Middleware Unspecified VulnerabilityKEVEXPLOIT ×2CRITICAL 9.1EPSS 98.8%16 October 2012
CVE-2012-5088Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.EXPLOITHIGH 10.0EPSS 78.7%16 October 2012
CVE-2012-5076Oracle Java SE Sandbox Bypass VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 91.3%16 October 2012
CVE-2012-5067Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Deployment.EXPLOITMEDIUM 5.0EPSS 64.0%16 October 2012
CVE-2012-1533Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related…EXPLOITHIGH 10.0EPSS 69.0%16 October 2012
CVE-2012-5386Directory traversal vulnerability in index.php in phpPaleo 4.8b180 allows remote attackers to include and execute arbitrary local files via a ..EXPLOITMEDIUM 6.8EPSS 2.32%11 October 2012
CVE-2012-5383Untrusted search path vulnerability in the installation functionality in Oracle MySQL 5.5.28, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the "C:\MySQL\MySQL Server 5.5\bin"…EXPLOITMEDIUM 6.2EPSS 0.83%11 October 2012
CVE-2012-5382Untrusted search path vulnerability in the installation functionality in Zend Server 5.6.0 SP4, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the…EXPLOITMEDIUM 6.0EPSS 0.87%11 October 2012
CVE-2012-5381Untrusted search path vulnerability in the installation functionality in PHP 5.3.17, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the C:\PHP directory, which may be added to the PATH…EXPLOITMEDIUM 6.0EPSS 0.85%11 October 2012
CVE-2012-5380Untrusted search path vulnerability in the installation functionality in Ruby 1.9.3-p194, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the C:\Ruby193\bin directory, which may be…EXPLOITMEDIUM 6.7EPSS 0.99%11 October 2012
CVE-2012-5379Untrusted search path vulnerability in the installation functionality in ActivePython 3.2.2.3, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the C:\Python27 or C:\Python27\Scripts…EXPLOITHIGH 7.3EPSS 1.23%11 October 2012
CVE-2012-5378Untrusted search path vulnerability in the installation functionality in ActiveTcl 8.5.12, when installed in the top-level C:\ directory, allows local users to gain privileges via a Trojan horse DLL in the C:\TD\bin directory, which is added to the PATH…EXPLOITMEDIUM 6.0EPSS 0.91%11 October 2012
CVE-2012-5377Untrusted search path vulnerability in the installation functionality in ActivePerl 5.16.1.1601, when installed in the top-level C:\ directory, allows local users to gain privileges via a Trojan horse DLL in the C:\Perl\Site\bin directory, which is…EXPLOITMEDIUM 6.0EPSS 1.27%11 October 2012
CVE-2009-5067Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 4.3EPSS 7.63%10 October 2012
CVE-2012-3993The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures of…EXPLOITHIGH 9.3EPSS 42.6%10 October 2012
CVE-2012-4399The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.EXPLOITHIGH 7.5EPSS 12.1%9 October 2012
CVE-2012-3549The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted ASCONF chunk.EXPLOITHIGH 7.8EPSS 7.81%9 October 2012
CVE-2012-5350SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in a paywithtweet shortcode.EXPLOITMEDIUM 6.0EPSS 2.37%9 October 2012
CVE-2012-5349Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin before 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) title, or (3) dl parameter.EXPLOITLOW 2.6EPSS 3.03%9 October 2012
CVE-2012-5348SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via the login parameter in a login action to index.php.EXPLOITMEDIUM 6.8EPSS 1.05%9 October 2012
CVE-2012-5347TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc or (2) info.php.EXPLOITHIGH 7.5EPSS 4.36%9 October 2012
CVE-2012-5346Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.EXPLOITMEDIUM 4.3EPSS 3.73%9 October 2012
CVE-2012-5345Buffer overflow in the Remote command server (Rcmd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to cause a denial of service (crash) via a long string to TCP port 23.EXPLOITMEDIUM 5.0EPSS 2.47%9 October 2012
CVE-2012-5344Directory traversal vulnerability in the WebServer (Thttpd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 7.15%9 October 2012
CVE-2012-5343Cross-site scripting (XSS) vulnerability in admin/login.php in Limny 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, related to the "PHP_SELF" variable.EXPLOITMEDIUM 4.3EPSS 1.93%9 October 2012
CVE-2012-5342Multiple SQL injection vulnerabilities in SenseSites CommonSense CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) special.php, (2) article.php, or (3) cat2.php.EXPLOIT ×3HIGH 7.5EPSS 1.06%9 October 2012
CVE-2012-5341Multiple cross-site scripting (XSS) vulnerabilities in statistik.php in Otterware StatIt 4 allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter, (2) show parameter in a stat_tld action, or (3) order parameter in a…EXPLOITMEDIUM 4.3EPSS 1.62%9 October 2012
CVE-2011-5209Cross-site scripting (XSS) vulnerability in search/ in GraphicsClone Script, possibly 1.11, allows remote attackers to inject arbitrary web script or HTML via the term parameter.EXPLOITMEDIUM 4.3EPSS 1.65%9 October 2012
CVE-2012-5335Directory traversal vulnerability in Tiny Server 1.1.5 allows remote authenticated users to read arbitrary files via a ..EXPLOITMEDIUM 4.0EPSS 6.51%8 October 2012
CVE-2012-5334SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid parameter.EXPLOITHIGH 7.5EPSS 1.26%8 October 2012
CVE-2012-5333SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 1.24%8 October 2012
CVE-2012-5331Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a ..EXPLOITMEDIUM 6.8EPSS 2.35%8 October 2012
CVE-2012-5330Multiple cross-site scripting (XSS) vulnerabilities in asaanCart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to calc.php, (2) chat.php, (3) register.php, or (4) index.php in libs/smarty_ajax/; or the (5) page…EXPLOITMEDIUM 4.3EPSS 1.63%8 October 2012
CVE-2012-5329Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application crash) via a long string in an APPE command.EXPLOIT ×2MEDIUM 4.0EPSS 8.54%8 October 2012
CVE-2012-1671Directory traversal vulnerability in index.php in phpPaleo 4.8b155 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOITMEDIUM 6.8EPSS 2.57%8 October 2012
CVE-2012-5326Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via an administrators action.EXPLOITMEDIUM 6.8EPSS 0.95%8 October 2012
CVE-2012-5324Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry…EXPLOITHIGH 9.3EPSS 6.28%8 October 2012
CVE-2012-5323Cross-site request forgery (CSRF) vulnerability in webconfig/admin_passwd/passwd.html/admin_passwd in Xavi X7968 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the…EXPLOITMEDIUM 6.8EPSS 1.04%8 October 2012
CVE-2012-5322Multiple cross-site scripting (XSS) vulnerabilities in Xavi X7968 allow remote attackers to inject arbitrary web script or HTML via the (1) pvcName parameter to webconfig/wan/confirm.html/confirm or (2) host_name_txtbox parameter to…EXPLOIT ×2MEDIUM 4.3EPSS 1.66%8 October 2012
CVE-2012-5321tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."EXPLOITMEDIUM 5.8EPSS 13.8%8 October 2012
CVE-2012-5320Cross-site request forgery (CSRF) vulnerability in password.cgi in Sagem F@ST 2604 253180972B allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.EXPLOITMEDIUM 6.8EPSS 1.08%8 October 2012
CVE-2012-5319Cross-site request forgery (CSRF) vulnerability in setup/security.cgi in D-Link DCS-900, DCS-2000, and DCS-5300 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the rootpass…EXPLOIT ×2MEDIUM 6.8EPSS 1.07%8 October 2012

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.