SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,416 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 154 of 501

CVESummaryPriorityPublished
CVE-2012-2998SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.EXPLOITHIGH 7.5EPSS 6.09%28 September 2012
CVE-2012-1617Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a ..EXPLOITMEDIUM 6.4EPSS 9.94%26 September 2012
CVE-2012-1188Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) type or (2) querystring parameters to private/en/error or (3) name parameter to private/en/locale/index.EXPLOIT ×2MEDIUM 4.3EPSS 4.46%26 September 2012
CVE-2012-1116SQL injection vulnerability in Joomla!EXPLOITHIGH 7.5EPSS 1.26%26 September 2012
CVE-2012-0974Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sCity, (2) sPattern, (3) sPriceMax, and…EXPLOITMEDIUM 4.3EPSS 3.52%25 September 2012
CVE-2012-0973Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in…EXPLOITHIGH 7.5EPSS 2.41%25 September 2012
CVE-2012-0869Cross-site scripting (XSS) vulnerability in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20120215 allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOITMEDIUM 4.3EPSS 4.85%25 September 2012
CVE-2012-5159phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via…EXPLOITHIGH 7.5EPSS 74.5%25 September 2012
CVE-2012-0209Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js,…EXPLOITHIGH 7.5EPSS 71.9%25 September 2012
CVE-2012-5105Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.4 allow remote attackers to inject arbitrary web script or HTML via the dbsel parameter to (1) main.php or (2) index.php; or (3) nsextt parameter to index.php.EXPLOIT ×2MEDIUM 4.3EPSS 5.10%23 September 2012
CVE-2012-5104Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the Loginname parameter.EXPLOITMEDIUM 4.3EPSS 1.99%23 September 2012
CVE-2012-5102Cross-site scripting (XSS) vulnerability in inc/extensions.php in VertrigoServ 2.25 allows remote attackers to inject arbitrary web script or HTML via the ext parameter.EXPLOITMEDIUM 4.3EPSS 1.80%23 September 2012
CVE-2012-5100Directory traversal vulnerability in HServer 0.1.1 allows remote attackers to read arbitrary files via a (1) ..%5c (dot dot encoded backslash) or (2) %2e%2e%5c (encoded dot dot backslash) in the PATH_INFO.EXPLOITMEDIUM 5.0EPSS 7.88%23 September 2012
CVE-2012-5099Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.EXPLOITMEDIUM 4.3EPSS 1.61%23 September 2012
CVE-2012-5098Multiple SQL injection vulnerabilities in Php-X-Links, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to rate.php, (2) cid parameter to view.php, or (3) t parameter to pop.php.EXPLOITHIGH 7.5EPSS 1.15%23 September 2012
CVE-2011-5200Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.EXPLOITHIGH 7.5EPSS 2.43%23 September 2012
CVE-2011-5197Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.EXPLOITMEDIUM 6.8EPSS 1.98%23 September 2012
CVE-2011-5196Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.EXPLOITMEDIUM 6.8EPSS 1.33%23 September 2012
CVE-2011-5195Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference Systems 2.3.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload a PHP file.EXPLOITMEDIUM 6.8EPSS 1.11%23 September 2012
CVE-2011-5193Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter…EXPLOITLOW 2.6EPSS 4.05%23 September 2012
CVE-2012-3137The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and…EXPLOITMEDIUM 6.4EPSS 31.4%21 September 2012
CVE-2011-5186Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop plugin for e107 7 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter.EXPLOITMEDIUM 4.3EPSS 1.33%20 September 2012
CVE-2011-5185Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.EXPLOITMEDIUM 4.3EPSS 1.35%20 September 2012
CVE-2011-5184Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i 9.10 allow remote attackers to inject arbitrary web script or HTML via the (1) node parameter to nnm/mibdiscover; (2) nodename parameter to…EXPLOIT ×5MEDIUM 4.3EPSS 2.71%20 September 2012
CVE-2011-5183Multiple SQL injection vulnerabilities in OrderSys 1.6.4 and earlier allow remote attackers to execute arbitrary SQL commands via the where_clause parameter to (1) index.php, (2) index_long.php, or (3) index_short.php in ordering/interface_creator/.EXPLOITHIGH 7.5EPSS 1.20%20 September 2012
CVE-2011-5182Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.EXPLOITMEDIUM 4.3EPSS 3.60%20 September 2012
CVE-2011-5181Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter.EXPLOITMEDIUM 4.3EPSS 10.4%20 September 2012
CVE-2011-5180Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.EXPLOITMEDIUM 4.3EPSS 3.73%20 September 2012
CVE-2011-5179Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.EXPLOITMEDIUM 4.3EPSS 8.77%20 September 2012
CVE-2011-5177Multiple cross-site scripting (XSS) vulnerabilities in admin/controller.php in eSyndiCat Pro 2.3.05 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to the admins (2) blocks, (3) articles, or (4) suggest-category;…EXPLOITMEDIUM 4.3EPSS 1.61%20 September 2012
CVE-2012-0988Multiple cross-site scripting (XSS) vulnerabilities in config/dmsDefaults.php in KnowledgeTree 3.7.0.2 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) login.php, (2) admin.php, or (3)…EXPLOITMEDIUM 4.3EPSS 1.80%20 September 2012
CVE-2012-5005Cross-site request forgery (CSRF) vulnerability in admin/admin_options.php in VR GPub 4.0 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an add action.EXPLOITMEDIUM 6.8EPSS 1.07%19 September 2012
CVE-2012-5002Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command.EXPLOIT ×2MEDIUM 6.8EPSS 31.2%19 September 2012
CVE-2012-5000SQL injection vulnerability in jokes/index.php in the Witze addon 0.9 for deV!L'z Clanportal allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.EXPLOITHIGH 7.5EPSS 1.12%19 September 2012
CVE-2012-4999Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HTTP header fields such as (1) If-Modified-Since, (2) If-None-Match, or (3) If-Unmodified-Since.EXPLOITMEDIUM 6.1EPSS 6.56%19 September 2012
CVE-2012-4998Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script or HTML via the q parameter.EXPLOITMEDIUM 4.3EPSS 1.66%19 September 2012
CVE-2012-4997Directory traversal vulnerability in acp/index.php in AneCMS allows remote attackers to include and execute arbitrary local files via a ..EXPLOITHIGH 7.5EPSS 2.82%19 September 2012
CVE-2012-4996Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.EXPLOITHIGH 7.5EPSS 1.24%19 September 2012
CVE-2012-4993torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact.EXPLOITHIGH 7.5EPSS 2.30%19 September 2012
CVE-2012-4992Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox.EXPLOITHIGH 9.0EPSS 17.7%19 September 2012
CVE-2012-2105Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.EXPLOITHIGH 7.5EPSS 1.92%19 September 2012
CVE-2012-2586Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary web script or HTML via an e-mail message subject with (1) a JavaScript alert function used in conjunction with the fromCharCode method…EXPLOITMEDIUM 4.3EPSS 2.47%19 September 2012
CVE-2012-2578Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a JavaScript alert function used in conjunction with the fromCharCode method, (2) a…EXPLOITMEDIUM 4.3EPSS 2.47%19 September 2012
CVE-2012-0271Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a…EXPLOITHIGH 10.0EPSS 17.2%19 September 2012
CVE-2012-1901Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of users for requests that change account settings via a request to index.php/profile-edit-save or (2) hijack…EXPLOITMEDIUM 6.8EPSS 1.23%18 September 2012
CVE-2012-1184Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in an…EXPLOITHIGH 7.5EPSS 16.4%18 September 2012
CVE-2012-4425libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable.EXPLOITMEDIUM 6.9EPSS 1.09%18 September 2012
CVE-2012-3524libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable.EXPLOITMEDIUM 6.9EPSS 4.48%18 September 2012
CVE-2012-4969Microsoft Internet Explorer Use-After-Free VulnerabilityKEVEXPLOITHIGH 8.1EPSS 81.7%18 September 2012
CVE-2012-2994The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for remote attackers to obtain access via a brute-force attack.EXPLOITHIGH 7.5EPSS 6.27%18 September 2012

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.