Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,407 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 153 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-1416 | Multiple cross-site request forgery (CSRF) vulnerabilities in SocialCMS 1.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrator accounts via a member_new action to my_admin/admin1_members.php… | EXPLOIT ×2MEDIUM 6.8EPSS 1.12% | 8 October 2012 |
| CVE-2012-1308 | Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU_4.00 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter. | EXPLOITMEDIUM 6.8EPSS 2.43% | 8 October 2012 |
| CVE-2012-1189 | Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an engine sample attribute… | EXPLOIT ✓HIGH 9.3EPSS 9.59% | 8 October 2012 |
| CVE-2011-4929 | Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors. | EXPLOIT ✓HIGH 7.5EPSS 46.4% | 8 October 2012 |
| CVE-2011-4342 | PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter. | EXPLOITHIGH 7.5EPSS 10.7% | 8 October 2012 |
| CVE-2012-5318 | Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin 1.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with a double extension, then accessing it via a direct… | EXPLOITMEDIUM 6.8EPSS 6.51% | 8 October 2012 |
| CVE-2012-5315 | Multiple cross-site scripting (XSS) vulnerabilities in php ireport 1.0 allow remote attackers to inject arbitrary web script or HTML via the message parameter to (1) messages_viewer.php, (2) home.php, or (3) history.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.61% | 8 October 2012 |
| CVE-2012-5313 | SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands via the TOPIC_ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 8 October 2012 |
| CVE-2012-5312 | SQL injection vulnerability in Tribiq CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 8 October 2012 |
| CVE-2012-1125 | Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with a PHP extension, then accessing it via a… | EXPLOITMEDIUM 6.8EPSS 11.6% | 8 October 2012 |
| CVE-2011-4640 | Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.0EPSS 7.32% | 8 October 2012 |
| CVE-2010-5063 | SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the ratearticleselect parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 8 October 2012 |
| CVE-2012-1414 | Cross-site request forgery (CSRF) vulnerability in manager/news.php in Plume CMS 1.2.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that create News pages via a publish action. | EXPLOITMEDIUM 6.8EPSS 0.95% | 7 October 2012 |
| CVE-2011-4909 | Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.88% | 7 October 2012 |
| CVE-2010-5278 | Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 18.6% | 7 October 2012 |
| CVE-2011-3918 | The Zygote process in Android 4.0.3 and earlier accepts fork requests from processes with arbitrary UIDs, which allows remote attackers to cause a denial of service (reboot loop) via a crafted application. | EXPLOITHIGH 7.8EPSS 1.35% | 7 October 2012 |
| CVE-2012-5306 | Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as used in D-Link DCS-5605 PTZ IP Network Camera, allows remote attackers to cause a denial of service (crash) and possibly execute… | EXPLOIT ✓HIGH 9.3EPSS 12.1% | 6 October 2012 |
| CVE-2012-1153 | Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 32.4% | 6 October 2012 |
| CVE-2012-5295 | Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the windowed parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.63% | 4 October 2012 |
| CVE-2012-5294 | SQL injection vulnerability in art_detalle.php in MyStore Xpress Tienda Virtual allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 4 October 2012 |
| CVE-2011-5207 | Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arbitrary web script or HTML via the tcp_name_post_XXXXX parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 4.54% | 4 October 2012 |
| CVE-2011-5204 | Akiva WebBoard 8.x stores passwords in plaintext, which allows local users to obtain sensitive information by reading from the database. | EXPLOIT ✓LOW 1.9EPSS 0.82% | 4 October 2012 |
| CVE-2011-5203 | SQL injection vulnerability in WB/Default.asp in Akiva WebBoard before 8 SR 1 allows remote attackers to execute arbitrary SQL commands via the name parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 4 October 2012 |
| CVE-2012-5293 | Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[root_path] parameter to usr/extensions/get_tree.inc.php or (2) root_path parameter to… | EXPLOIT ✓HIGH 7.5EPSS 2.68% | 4 October 2012 |
| CVE-2012-5292 | Multiple SQL injection vulnerabilities in Atar2b CMS 4.0.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) gallery_e.php, (2) pageE.php, or (3) pageH.php. | EXPLOIT ×3 ✓HIGH 7.5EPSS 1.11% | 4 October 2012 |
| CVE-2012-5291 | SQL injection vulnerability in team.php in Posse Softball Director CMS allows remote attackers to execute arbitrary SQL commands via the idteam parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 4 October 2012 |
| CVE-2012-5288 | SQL injection vulnerability in page.php in phpMyDirectory 1.3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 4 October 2012 |
| CVE-2012-3819 | Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, allows remote attackers to cause a denial of service (daemon crash) via a long request. | EXPLOIT ✓MEDIUM 5.0EPSS 2.33% | 4 October 2012 |
| CVE-2012-3430 | The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg… | EXPLOIT ✓LOW 2.1EPSS 0.95% | 3 October 2012 |
| CVE-2012-3375 | The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a… | EXPLOIT ✓MEDIUM 4.9EPSS 1.02% | 3 October 2012 |
| CVE-2012-4242 | Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page. | EXPLOIT ✓MEDIUM 4.3EPSS 9.28% | 1 October 2012 |
| CVE-2012-1604 | Cross-site scripting (XSS) vulnerability in NextBBS 0.6 allows remote attackers to inject arbitrary web script or HTML via the do parameter to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 2.05% | 1 October 2012 |
| CVE-2012-1603 | Multiple SQL injection vulnerabilities in ajaxserver.php in NextBBS 0.6 allow remote attackers to execute arbitrary SQL commands via the (1) curstr parameter in the findUsers function, (2) id parameter in the isIdAvailable function, or (3) username… | EXPLOIT ✓HIGH 7.5EPSS 1.45% | 1 October 2012 |
| CVE-2012-1470 | Multiple cross-site scripting (XSS) vulnerabilities in code_editor.php in ocPortal before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) path or (2) line parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.68% | 1 October 2012 |
| CVE-2012-0989 | Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.63% | 1 October 2012 |
| CVE-2012-5231 | miniCMS 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code via a crafted (1) pagename or (2) area variable containing an executable extension, which is not properly handled by (a) update.php when writing files to content/, or (b)… | EXPLOITHIGH 7.5EPSS 2.66% | 1 October 2012 |
| CVE-2012-5229 | Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the border parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.73% | 1 October 2012 |
| CVE-2012-5228 | Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the testtarget parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.65% | 1 October 2012 |
| CVE-2012-5227 | SQL injection vulnerability in administrer/tva.php in Peel SHOPPING 2.8 and 2.9 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOITHIGH 7.5EPSS 1.11% | 1 October 2012 |
| CVE-2012-5226 | Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING 2.8 and 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) motclef parameter to achat/recherche.php or (2) PATH_INFO to index.php. | EXPLOITMEDIUM 4.3EPSS 1.61% | 1 October 2012 |
| CVE-2012-5225 | Cross-site scripting (XSS) vulnerability in webscr.php in xClick Cart 1.0.1 and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the shopping_url parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.80% | 1 October 2012 |
| CVE-2012-5224 | PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pages[template] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.57% | 1 October 2012 |
| CVE-2012-5223 | The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted… | EXPLOIT ✓HIGH 7.5EPSS 40.5% | 1 October 2012 |
| CVE-2012-1898 | Multiple cross-site scripting (XSS) vulnerabilities in wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user[name], (2) user[email], or (3) user[username] parameters. | EXPLOITMEDIUM 4.3EPSS 1.62% | 1 October 2012 |
| CVE-2012-1897 | Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via the user id number to admin/user/delete; (2) delete… | EXPLOITMEDIUM 6.8EPSS 1.19% | 1 October 2012 |
| CVE-2012-4415 | Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name. | EXPLOIT ✓HIGH 7.5EPSS 13.6% | 1 October 2012 |
| CVE-2011-4551 | Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.64% | 1 October 2012 |
| CVE-2012-5049 | APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. | EXPLOIT ✓HIGH 7.8EPSS 3.43% | 28 September 2012 |
| CVE-2012-5048 | APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted packet. | EXPLOIT ✓HIGH 7.8EPSS 6.72% | 28 September 2012 |
| CVE-2012-4051 | Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Suite before 8.61 allow remote attackers to hijack the authentication of administrators for requests that (1)… | EXPLOITMEDIUM 6.8EPSS 1.47% | 28 September 2012 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.