Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,416 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 155 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-2996 | Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allows remote attackers to hijack the authentication of administrators for requests that create admin… | EXPLOITMEDIUM 6.8EPSS 1.67% | 17 September 2012 |
| CVE-2012-2995 | Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow remote attackers to inject arbitrary web script or HTML via (1) the wrsApprovedURL parameter to… | EXPLOITMEDIUM 4.3EPSS 2.50% | 17 September 2012 |
| CVE-2012-2575 | Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IFRAME element in the body of an HTML e-mail message. | EXPLOIT ✓MEDIUM 4.3EPSS 1.32% | 17 September 2012 |
| CVE-2012-4928 | Cross-site scripting (XSS) vulnerability in ow_updates/index.php in Oxwall 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the plugin parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.62% | 15 September 2012 |
| CVE-2012-4927 | SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php. | EXPLOITHIGH 7.5EPSS 2.24% | 15 September 2012 |
| CVE-2012-4926 | approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action. | EXPLOITMEDIUM 6.4EPSS 1.90% | 15 September 2012 |
| CVE-2012-4925 | Multiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbitrary SQL commands via the u parameter in a (1) app0 or (2) app1 action. | EXPLOITHIGH 7.5EPSS 1.24% | 15 September 2012 |
| CVE-2012-4924 | Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long parameter to the Alert method. | EXPLOIT ✓HIGH 9.3EPSS 36.3% | 15 September 2012 |
| CVE-2012-4923 | Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.83% | 15 September 2012 |
| CVE-2012-4336 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) an arbitrary parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.63% | 15 September 2012 |
| CVE-2012-3233 | Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusion 4.40.1148, and possibly before 4.50.1581, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | EXPLOIT ✓MEDIUM 4.3EPSS 2.00% | 15 September 2012 |
| CVE-2012-2275 | Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijack the authentication of users for requests that add, delete, or modify sensitive information, as demonstrated by changing the… | EXPLOITMEDIUM 6.8EPSS 2.73% | 15 September 2012 |
| CVE-2011-5173 | Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field in a bed file. | EXPLOITMEDIUM 6.8EPSS 3.48% | 15 September 2012 |
| CVE-2011-5172 | Stack-based buffer overflow in StoryBoard Quick 6 Build 3786, and possibly StoryBoard Artist and StoryBoard Studio, allows remote attackers to execute arbitrary code via a long string in the string element field in a frame xml file. | EXPLOITHIGH 9.3EPSS 6.37% | 15 September 2012 |
| CVE-2011-5171 | Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to execute arbitrary code via the (1) src and (2) name parameters in a p2g project file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 45.8% | 15 September 2012 |
| CVE-2011-5170 | Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u playlist. | EXPLOIT ×2 ✓HIGH 9.3EPSS 32.0% | 15 September 2012 |
| CVE-2011-5169 | SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2 allows remote attackers to execute arbitrary SQL commands via the scheduleID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 15 September 2012 |
| CVE-2011-5168 | SQL injection vulnerability in user.php in Banana Dance before B.1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.27% | 15 September 2012 |
| CVE-2011-5167 | Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long… | EXPLOIT ✓HIGH 9.3EPSS 9.76% | 15 September 2012 |
| CVE-2011-5166 | Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string to the (1) USER, (2) PASS, (3) REIN, (4) QUIT, (5) PORT, (6) PASV, (7) TYPE, (8) STRU, (9) MODE, (10) RETR, (11) STOR, (12) APPE,… | EXPLOIT ×4 ✓HIGH 7.5EPSS 6.48% | 15 September 2012 |
| CVE-2011-5165 | Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wav file. | EXPLOIT ×8 ✓HIGH 9.3EPSS 37.0% | 15 September 2012 |
| CVE-2011-5164 | Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response. | EXPLOIT ✓HIGH 9.3EPSS 28.6% | 15 September 2012 |
| CVE-2011-5162 | Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. | EXPLOIT ✓HIGH 9.3EPSS 6.85% | 15 September 2012 |
| CVE-2012-4909 | Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application. | EXPLOIT ✓MEDIUM 4.3EPSS 2.15% | 13 September 2012 |
| CVE-2012-4908 | Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors involving a symlink. | EXPLOIT ✓HIGH 7.5EPSS 3.35% | 13 September 2012 |
| CVE-2012-4906 | Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining credential data, a different vulnerability… | EXPLOIT ✓MEDIUM 5.0EPSS 3.10% | 13 September 2012 |
| CVE-2012-4905 | Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script or HTML via an extra in an Intent object, aka "Universal XSS (UXSS)." | EXPLOIT ✓MEDIUM 4.3EPSS 1.55% | 13 September 2012 |
| CVE-2012-2982 | file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character. | EXPLOIT ✓MEDIUM 6.5EPSS 62.2% | 11 September 2012 |
| CVE-2012-4891 | Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vector than CVE-2012-4889. | EXPLOITMEDIUM 4.3EPSS 3.94% | 10 September 2012 |
| CVE-2012-4889 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) subTab or (2) tab parameter to createAnomaly.do; (3) url, (4) subTab, or (5) tab… | EXPLOIT ×5 ✓MEDIUM 4.3EPSS 7.72% | 10 September 2012 |
| CVE-2012-2316 | Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary code via the… | EXPLOIT ✓MEDIUM 6.8EPSS 4.25% | 9 September 2012 |
| CVE-2012-2315 | admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action. | EXPLOIT ✓MEDIUM 4.0EPSS 6.22% | 9 September 2012 |
| CVE-2012-2115 | SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the u parameter. | EXPLOITHIGH 7.5EPSS 2.15% | 9 September 2012 |
| CVE-2012-1912 | Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. | EXPLOITMEDIUM 4.3EPSS 2.40% | 9 September 2012 |
| CVE-2012-1911 | Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. | EXPLOITHIGH 7.5EPSS 1.23% | 9 September 2012 |
| CVE-2011-5161 | Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a… | EXPLOITMEDIUM 6.8EPSS 1.97% | 9 September 2012 |
| CVE-2011-5160 | Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web script or HTML via the site parameter. | EXPLOIT ×2MEDIUM 4.3EPSS 1.33% | 9 September 2012 |
| CVE-2012-1666 | Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View before 5.1, and VMware ESX 4.1 before U3 and 5.0 before P03 allows local users to gain privileges… | EXPLOIT ✓MEDIUM 6.9EPSS 0.78% | 8 September 2012 |
| CVE-2010-5241 | Multiple untrusted search path vulnerabilities in Autodesk AutoCAD 2010 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) IBFS32.DLL file in the current working directory, as demonstrated by a directory that contains a .dwg… | EXPLOIT ✓MEDIUM 6.9EPSS 0.83% | 7 September 2012 |
| CVE-2010-5240 | Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) CrlRib.dll file in the current working directory, as demonstrated by a… | EXPLOIT ×2 ✓MEDIUM 6.9EPSS 2.80% | 7 September 2012 |
| CVE-2010-5239 | Untrusted search path vulnerability in DAEMON Tools Lite 4.35.6.0091 and Pro Standard 4.36.0309.0160 allows local users to gain privileges via a Trojan horse mfc80loc.dll file in the current working directory, as demonstrated by a directory that… | EXPLOITMEDIUM 6.9EPSS 1.06% | 7 September 2012 |
| CVE-2010-5236 | Untrusted search path vulnerability in Roxio Easy Media Creator Home 9.0.136 allows local users to gain privileges via a Trojan horse homeutils9.dll file in the current working directory, as demonstrated by a directory that contains a .roxio, .c2d, or… | EXPLOITMEDIUM 6.9EPSS 1.02% | 7 September 2012 |
| CVE-2010-5227 | Untrusted search path vulnerability in Opera before 10.62 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .htm, .mht, .mhtml, .xht, .xhtm, or .xhtl… | EXPLOIT ✓MEDIUM 6.9EPSS 0.98% | 7 September 2012 |
| CVE-2012-4878 | Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary files via a full pathname in the dir parameter in a contents/Files action. | EXPLOIT ✓MEDIUM 5.0EPSS 8.76% | 6 September 2012 |
| CVE-2012-4877 | Cross-site request forgery (CSRF) vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts. | EXPLOIT ✓MEDIUM 6.8EPSS 1.18% | 6 September 2012 |
| CVE-2012-4876 | Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long string to the OpenFileDlg method. | EXPLOIT ×2 ✓HIGH 10.0EPSS 71.2% | 6 September 2012 |
| CVE-2012-4873 | Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard before 4.34.21 allows remote attackers to inject arbitrary web script or HTML via the filename parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.63% | 6 September 2012 |
| CVE-2012-4871 | Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers to inject arbitrary web script or HTML via the gtitle parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.63% | 6 September 2012 |
| CVE-2012-1469 | Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote authenticated users to inject arbitrary web script or HTML via the (1) editor or (2) callback parameters to… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.08% | 6 September 2012 |
| CVE-2012-1468 | Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a file with an executable extension that is not ".php", then accessing it… | EXPLOIT ✓MEDIUM 6.0EPSS 3.48% | 6 September 2012 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.