Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,416 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 154 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-2998 | SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 6.09% | 28 September 2012 |
| CVE-2012-1617 | Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 9.94% | 26 September 2012 |
| CVE-2012-1188 | Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) type or (2) querystring parameters to private/en/error or (3) name parameter to private/en/locale/index. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 4.46% | 26 September 2012 |
| CVE-2012-1116 | SQL injection vulnerability in Joomla! | EXPLOIT ✓HIGH 7.5EPSS 1.26% | 26 September 2012 |
| CVE-2012-0974 | Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sCity, (2) sPattern, (3) sPriceMax, and… | EXPLOIT ✓MEDIUM 4.3EPSS 3.52% | 25 September 2012 |
| CVE-2012-0973 | Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in… | EXPLOIT ✓HIGH 7.5EPSS 2.41% | 25 September 2012 |
| CVE-2012-0869 | Cross-site scripting (XSS) vulnerability in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20120215 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 4.85% | 25 September 2012 |
| CVE-2012-5159 | phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via… | EXPLOIT ✓HIGH 7.5EPSS 74.5% | 25 September 2012 |
| CVE-2012-0209 | Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js,… | EXPLOIT ✓HIGH 7.5EPSS 71.9% | 25 September 2012 |
| CVE-2012-5105 | Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.4 allow remote attackers to inject arbitrary web script or HTML via the dbsel parameter to (1) main.php or (2) index.php; or (3) nsextt parameter to index.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 5.10% | 23 September 2012 |
| CVE-2012-5104 | Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the Loginname parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.99% | 23 September 2012 |
| CVE-2012-5102 | Cross-site scripting (XSS) vulnerability in inc/extensions.php in VertrigoServ 2.25 allows remote attackers to inject arbitrary web script or HTML via the ext parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.80% | 23 September 2012 |
| CVE-2012-5100 | Directory traversal vulnerability in HServer 0.1.1 allows remote attackers to read arbitrary files via a (1) ..%5c (dot dot encoded backslash) or (2) %2e%2e%5c (encoded dot dot backslash) in the PATH_INFO. | EXPLOIT ✓MEDIUM 5.0EPSS 7.88% | 23 September 2012 |
| CVE-2012-5099 | Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.61% | 23 September 2012 |
| CVE-2012-5098 | Multiple SQL injection vulnerabilities in Php-X-Links, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to rate.php, (2) cid parameter to view.php, or (3) t parameter to pop.php. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 23 September 2012 |
| CVE-2011-5200 | Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 23 September 2012 |
| CVE-2011-5197 | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 23 September 2012 |
| CVE-2011-5196 | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files. | EXPLOIT ✓MEDIUM 6.8EPSS 1.33% | 23 September 2012 |
| CVE-2011-5195 | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference Systems 2.3.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload a PHP file. | EXPLOIT ✓MEDIUM 6.8EPSS 1.11% | 23 September 2012 |
| CVE-2011-5193 | Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter… | EXPLOIT ✓LOW 2.6EPSS 4.05% | 23 September 2012 |
| CVE-2012-3137 | The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and… | EXPLOITMEDIUM 6.4EPSS 31.4% | 21 September 2012 |
| CVE-2011-5186 | Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop plugin for e107 7 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.33% | 20 September 2012 |
| CVE-2011-5185 | Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows remote attackers to inject arbitrary web script or HTML via the comment parameter. | EXPLOITMEDIUM 4.3EPSS 1.35% | 20 September 2012 |
| CVE-2011-5184 | Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i 9.10 allow remote attackers to inject arbitrary web script or HTML via the (1) node parameter to nnm/mibdiscover; (2) nodename parameter to… | EXPLOIT ×5 ✓MEDIUM 4.3EPSS 2.71% | 20 September 2012 |
| CVE-2011-5183 | Multiple SQL injection vulnerabilities in OrderSys 1.6.4 and earlier allow remote attackers to execute arbitrary SQL commands via the where_clause parameter to (1) index.php, (2) index_long.php, or (3) index_short.php in ordering/interface_creator/. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 20 September 2012 |
| CVE-2011-5182 | Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.60% | 20 September 2012 |
| CVE-2011-5181 | Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 10.4% | 20 September 2012 |
| CVE-2011-5180 | Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.73% | 20 September 2012 |
| CVE-2011-5179 | Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 8.77% | 20 September 2012 |
| CVE-2011-5177 | Multiple cross-site scripting (XSS) vulnerabilities in admin/controller.php in eSyndiCat Pro 2.3.05 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to the admins (2) blocks, (3) articles, or (4) suggest-category;… | EXPLOIT ✓MEDIUM 4.3EPSS 1.61% | 20 September 2012 |
| CVE-2012-0988 | Multiple cross-site scripting (XSS) vulnerabilities in config/dmsDefaults.php in KnowledgeTree 3.7.0.2 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) login.php, (2) admin.php, or (3)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.80% | 20 September 2012 |
| CVE-2012-5005 | Cross-site request forgery (CSRF) vulnerability in admin/admin_options.php in VR GPub 4.0 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an add action. | EXPLOITMEDIUM 6.8EPSS 1.07% | 19 September 2012 |
| CVE-2012-5002 | Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 31.2% | 19 September 2012 |
| CVE-2012-5000 | SQL injection vulnerability in jokes/index.php in the Witze addon 0.9 for deV!L'z Clanportal allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action. | EXPLOITHIGH 7.5EPSS 1.12% | 19 September 2012 |
| CVE-2012-4999 | Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HTTP header fields such as (1) If-Modified-Since, (2) If-None-Match, or (3) If-Unmodified-Since. | EXPLOIT ✓MEDIUM 6.1EPSS 6.56% | 19 September 2012 |
| CVE-2012-4998 | Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script or HTML via the q parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.66% | 19 September 2012 |
| CVE-2012-4997 | Directory traversal vulnerability in acp/index.php in AneCMS allows remote attackers to include and execute arbitrary local files via a .. | EXPLOITHIGH 7.5EPSS 2.82% | 19 September 2012 |
| CVE-2012-4996 | Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php. | EXPLOITHIGH 7.5EPSS 1.24% | 19 September 2012 |
| CVE-2012-4993 | torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact. | EXPLOITHIGH 7.5EPSS 2.30% | 19 September 2012 |
| CVE-2012-4992 | Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox. | EXPLOITHIGH 9.0EPSS 17.7% | 19 September 2012 |
| CVE-2012-2105 | Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. | EXPLOITHIGH 7.5EPSS 1.92% | 19 September 2012 |
| CVE-2012-2586 | Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary web script or HTML via an e-mail message subject with (1) a JavaScript alert function used in conjunction with the fromCharCode method… | EXPLOIT ✓MEDIUM 4.3EPSS 2.47% | 19 September 2012 |
| CVE-2012-2578 | Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a JavaScript alert function used in conjunction with the fromCharCode method, (2) a… | EXPLOIT ✓MEDIUM 4.3EPSS 2.47% | 19 September 2012 |
| CVE-2012-0271 | Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a… | EXPLOIT ✓HIGH 10.0EPSS 17.2% | 19 September 2012 |
| CVE-2012-1901 | Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of users for requests that change account settings via a request to index.php/profile-edit-save or (2) hijack… | EXPLOIT ✓MEDIUM 6.8EPSS 1.23% | 18 September 2012 |
| CVE-2012-1184 | Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in an… | EXPLOITHIGH 7.5EPSS 16.4% | 18 September 2012 |
| CVE-2012-4425 | libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. | EXPLOITMEDIUM 6.9EPSS 1.09% | 18 September 2012 |
| CVE-2012-3524 | libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. | EXPLOITMEDIUM 6.9EPSS 4.48% | 18 September 2012 |
| CVE-2012-4969 | Microsoft Internet Explorer Use-After-Free Vulnerability | KEVEXPLOIT ✓HIGH 8.1EPSS 81.7% | 18 September 2012 |
| CVE-2012-2994 | The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for remote attackers to obtain access via a brute-force attack. | EXPLOIT ✓HIGH 7.5EPSS 6.27% | 18 September 2012 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.