Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,416 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 158 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-2570 | Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HTML via the symb parameter. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.66% | 15 August 2012 |
| CVE-2012-1535 | Adobe Flash Player Arbitrary Code Execution Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 70.4% | 15 August 2012 |
| CVE-2012-4335 | Samsung NET-i viewer 1.37.120316 allows remote attackers to cause a denial of service (infinite loop) via a negative size value in a TCP request to (1) NiwMasterService or (2) NiwStorageService. | EXPLOIT ✓HIGH 7.8EPSS 3.48% | 14 August 2012 |
| CVE-2012-4334 | The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remote attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 6.75% | 14 August 2012 |
| CVE-2012-4333 | Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow remote attackers to execute arbitrary code via a long string in the fname… | EXPLOIT ×2 ✓HIGH 10.0EPSS 59.6% | 14 August 2012 |
| CVE-2012-4330 | The Samsung D6000 TV and possibly other products allows remote attackers to cause a denial of service (crash) via a long string in certain fields, as demonstrated by the MAC address field, possibly a buffer overflow. | EXPLOIT ×2 ✓HIGH 7.8EPSS 13.9% | 14 August 2012 |
| CVE-2012-4329 | The Samsung D6000 TV and possibly other products allow remote attackers to cause a denial of service (continuous restart) via a crafted controller name. | EXPLOIT ×2 ✓HIGH 7.8EPSS 13.3% | 14 August 2012 |
| CVE-2012-2209 | Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Piwigo before 2.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) section parameter in the configuration module, (2) installstatus parameter in the… | EXPLOITMEDIUM 4.3EPSS 4.24% | 14 August 2012 |
| CVE-2012-2208 | Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOITHIGH 7.5EPSS 9.43% | 14 August 2012 |
| CVE-2011-5099 | SQL injection vulnerability in helper/popup.php in the ccNewsletter (mod_ccnewsletter) component 1.0.7 through 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.28% | 14 August 2012 |
| CVE-2012-4325 | Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts. | EXPLOIT ✓MEDIUM 6.8EPSS 1.07% | 14 August 2012 |
| CVE-2012-1835 | Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to app/view/agenda-widget-form.php; (2) args,… | EXPLOIT ×4 ✓MEDIUM 4.3EPSS 8.95% | 14 August 2012 |
| CVE-2012-4282 | SQL injection vulnerability in photo.php in Trombinoscope 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.22% | 13 August 2012 |
| CVE-2012-2332 | SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[plugin_to_conf] parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.66% | 13 August 2012 |
| CVE-2012-2331 | Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the serendipity[textarea] parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 4.68% | 13 August 2012 |
| CVE-2012-2274 | Cross-site scripting (XSS) vulnerability in pivotx/ajaxhelper.php in PivotX 2.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.26% | 13 August 2012 |
| CVE-2010-5096 | Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the keywords parameter in a (1) do_search action to search.php or (2) do_stuff action to private.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 5.58% | 13 August 2012 |
| CVE-2012-4281 | Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parameter to (1) holiday.php or (2) holiday_book.php, (3) id parameter to pages.php, (4) fid parameter to… | EXPLOIT ✓HIGH 7.5EPSS 2.16% | 13 August 2012 |
| CVE-2012-4280 | Multiple cross-site request forgery (CSRF) vulnerabilities in admin/agenteditor.php in Free Realty 3.1-0.6 allow remote attackers to hijack the authentication of administrators for requests that (1) add an agent via an addagent action or (2) modify an… | EXPLOIT ✓MEDIUM 6.8EPSS 1.09% | 13 August 2012 |
| CVE-2012-4279 | Multiple SQL injection vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to agentdisplay.php or (2) edit parameter to admin/admin.php. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 13 August 2012 |
| CVE-2012-4278 | Multiple cross-site scripting (XSS) vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) notes parameter to (a) admin/agenteditor.php; (2) title, (3) previewdesc, (4) fulldesc, or (5) notes… | EXPLOIT ✓MEDIUM 4.3EPSS 1.65% | 13 August 2012 |
| CVE-2012-4267 | Cross-site scripting (XSS) vulnerability in user/register in Sockso 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.56% | 13 August 2012 |
| CVE-2012-4266 | Cross-site scripting (XSS) vulnerability in client_details.php in Proman Xpress 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the cl_comments parameter. | EXPLOITMEDIUM 4.3EPSS 1.65% | 13 August 2012 |
| CVE-2012-4265 | SQL injection vulnerability in category_edit.php in Proman Xpress 5.0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOITHIGH 7.5EPSS 1.05% | 13 August 2012 |
| CVE-2012-2371 | Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pagination_wp_facethumb parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 12.8% | 13 August 2012 |
| CVE-2012-4262 | Multiple cross-site scripting (XSS) vulnerabilities in myCare2x allow remote attackers to inject arbitrary web script or HTML via the (1) name_last, (2) name_first, (3) name_middle, or (4) name_maiden parameter to modules/patient/mycare_pid.php; (5)… | EXPLOIT ✓MEDIUM 4.3EPSS 2.38% | 13 August 2012 |
| CVE-2012-4261 | SQL injection vulnerability in modules/patient/mycare2x_pat_info.php in myCare2x allows remote attackers to execute arbitrary SQL commands via the lang parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.09% | 13 August 2012 |
| CVE-2012-4260 | Multiple SQL injection vulnerabilities in myCare2x allow remote attackers to execute arbitrary SQL commands via the (1) aktion or (2) callurl parameter to modules/patient/mycare2x_pat_info.php; (3) dept_nr or (4) pid parameter to… | EXPLOIT ✓HIGH 7.5EPSS 1.71% | 13 August 2012 |
| CVE-2012-4259 | Cross-site scripting (XSS) vulnerability in the contacts in (1) XPhone UC Web and the (2) web frontend for XPhone Virtual Directory in C4B XPhone Unified Communications (UC) 2011 Web 4.1.890S R1 allows remote attackers to inject arbitrary web script or… | EXPLOITMEDIUM 4.3EPSS 1.90% | 13 August 2012 |
| CVE-2012-4258 | Multiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrary SQL commands via the (1) link_idd parameter to 1_mobile/listings.php or (2) userid parameter to 1_mobile/agentprofile.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.12% | 13 August 2012 |
| CVE-2012-4254 | MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php. | EXPLOIT ✓MEDIUM 4.3EPSS 2.44% | 13 August 2012 |
| CVE-2012-4253 | Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 8.46% | 13 August 2012 |
| CVE-2012-4252 | Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove file access restriction via a deletehtaccess action, (2) drop a database… | EXPLOIT ✓MEDIUM 5.1EPSS 1.12% | 13 August 2012 |
| CVE-2012-4251 | Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to… | EXPLOIT ×4 ✓MEDIUM 4.3EPSS 1.87% | 13 August 2012 |
| CVE-2012-4250 | Stack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung NET-i viewer 1.37 allows remote attackers to execute arbitrary code via a long string in the first argument. | EXPLOITHIGH 9.3EPSS 6.24% | 13 August 2012 |
| CVE-2012-2590 | Multiple cross-site scripting (XSS) vulnerabilities in ESCON SupportPortal Professional Edition 3.0 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted SRC attribute of an… | EXPLOIT ✓MEDIUM 4.3EPSS 1.32% | 12 August 2012 |
| CVE-2012-2587 | Multiple cross-site scripting (XSS) vulnerabilities in AfterLogic MailSuite Pro 6.3 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with a crafted SRC attribute of (1) an IFRAME element or (2) a SCRIPT element. | EXPLOIT ✓MEDIUM 4.3EPSS 1.32% | 12 August 2012 |
| CVE-2012-2585 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.35% | 12 August 2012 |
| CVE-2012-2573 | Multiple cross-site scripting (XSS) vulnerabilities in T-dah WebMail 3.2.0-2.3 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.34% | 12 August 2012 |
| CVE-2012-2571 | Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail Server 3.8.1.6 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression… | EXPLOIT ✓MEDIUM 4.3EPSS 1.32% | 12 August 2012 |
| CVE-2012-4070 | SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL commands via the oid parameter in a homepage action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 12 August 2012 |
| CVE-2012-2584 | Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) the Cascading Style Sheets (CSS) expression property in conjunction with a… | EXPLOIT ✓MEDIUM 4.3EPSS 3.23% | 12 August 2012 |
| CVE-2012-2602 | Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via… | EXPLOIT ✓MEDIUM 6.8EPSS 5.98% | 12 August 2012 |
| CVE-2012-2577 | Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an… | EXPLOIT ✓MEDIUM 4.3EPSS 10.2% | 12 August 2012 |
| CVE-2012-4247 | Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) remote_user, (2) remote_database, (3) remote_userprefix, (4)… | EXPLOIT ✓MEDIUM 4.3EPSS 2.06% | 12 August 2012 |
| CVE-2012-4246 | Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter; or the (2) footer, (3) status, or (4) testtarget parameter… | EXPLOIT ✓MEDIUM 4.3EPSS 1.86% | 12 August 2012 |
| CVE-2012-4035 | The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password parameters to index.php. | EXPLOIT ✓HIGH 7.5EPSS 3.08% | 12 August 2012 |
| CVE-2012-4034 | Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to the send page, (2) email parameter to the forget page, (3) password parameter to the forum_archive page,… | EXPLOIT ✓HIGH 7.5EPSS 2.51% | 12 August 2012 |
| CVE-2012-3953 | SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete parameter to the editattributes page. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 12 August 2012 |
| CVE-2012-3952 | Cross-site scripting (XSS) vulnerability in admin/index.php in phpList before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the unconfirmed parameter to the user page. | EXPLOIT ✓LOW 2.6EPSS 1.93% | 12 August 2012 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.