Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,425 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 161 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-3577 | Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct… | EXPLOIT ✓HIGH 7.5EPSS 13.6% | 17 June 2012 |
| CVE-2012-1723 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 93.7% | 16 June 2012 |
| CVE-2012-3576 | Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to… | EXPLOIT ✓HIGH 10.0EPSS 18.4% | 16 June 2012 |
| CVE-2012-3575 | Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in… | EXPLOIT ✓HIGH 10.0EPSS 15.4% | 16 June 2012 |
| CVE-2012-3574 | Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it… | EXPLOIT ✓HIGH 7.5EPSS 11.4% | 16 June 2012 |
| CVE-2012-1502 | Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string. | EXPLOITHIGH 7.5EPSS 14.3% | 16 June 2012 |
| CVE-2011-2183 | Race condition in the scan_get_next_rmap_item function in mm/ksm.c in the Linux kernel before 2.6.39.3, when Kernel SamePage Merging (KSM) is enabled, allows local users to cause a denial of service (NULL pointer dereference) or possibly have… | EXPLOIT ✓MEDIUM 4.0EPSS 0.54% | 13 June 2012 |
| CVE-2012-1889 | Microsoft XML Core Services Memory Corruption Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 83.5% | 13 June 2012 |
| CVE-2012-1876 | Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow,… | EXPLOIT ×5 ✓HIGH 9.3EPSS 65.0% | 12 June 2012 |
| CVE-2012-1875 | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability." | EXPLOIT ✓HIGH 9.3EPSS 61.7% | 12 June 2012 |
| CVE-2012-1858 | The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct… | EXPLOIT ✓MEDIUM 4.3EPSS 22.0% | 12 June 2012 |
| CVE-2012-0217 | The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before… | EXPLOIT ×3 ✓HIGH 7.2EPSS 39.8% | 12 June 2012 |
| CVE-2012-0677 | Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .m3u playlist. | EXPLOIT ×2 ✓HIGH 9.3EPSS 15.4% | 12 June 2012 |
| CVE-2012-2959 | Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote attackers to hijack the authentication of administrators for requests that change passwords. | EXPLOIT ✓MEDIUM 5.1EPSS 1.15% | 11 June 2012 |
| CVE-2012-0507 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 98.1% | 7 June 2012 |
| CVE-2012-0985 | Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, and 3.0; SmartWi Connection Utility 4.7, 4.7.4, 4.8, 4.9, 4.10, and 4.11;… | EXPLOITHIGH 9.3EPSS 13.0% | 7 June 2012 |
| CVE-2011-1761 | Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | EXPLOIT ✓MEDIUM 6.8EPSS 11.1% | 7 June 2012 |
| CVE-2010-5099 | The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly filter file types, which allows remote attackers to bypass intended access restrictions… | EXPLOITMEDIUM 6.8EPSS 3.12% | 30 May 2012 |
| CVE-2012-2952 | SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the add_ons parameter. | EXPLOITHIGH 7.5EPSS 2.43% | 29 May 2012 |
| CVE-2012-2941 | Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inject arbitrary web script or HTML via the text parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.64% | 27 May 2012 |
| CVE-2012-2940 | MediaChance Real-DRAW PRO 5.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted (1) PNG, (2) WMF, (3) PSD, (4) TGA, (5) TTF, (6) BMP, (7) TIFF, or (8) PCX file. | EXPLOIT ✓MEDIUM 4.3EPSS 2.48% | 27 May 2012 |
| CVE-2012-2939 | Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) airline-edit.php, (2) hotel-image-add.php, or (3)… | EXPLOIT ✓MEDIUM 6.5EPSS 3.89% | 27 May 2012 |
| CVE-2012-2938 | Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the holiday name field to (1) holiday_add.php or (2) holiday_view.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.81% | 27 May 2012 |
| CVE-2012-2436 | Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter in a move or (2) minimize action to admin/admin_index.php; (3) the karma_username… | EXPLOIT ✓MEDIUM 4.3EPSS 2.53% | 27 May 2012 |
| CVE-2012-2176 | Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote attackers to execute arbitrary code via a long argument to the (1) Attachment_Times or (2) Import_Times… | EXPLOIT ✓HIGH 9.3EPSS 31.2% | 25 May 2012 |
| CVE-2011-2918 | The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK events, which allows local users to cause a denial of service (system hang) via a crafted application. | EXPLOITMEDIUM 5.5EPSS 0.92% | 24 May 2012 |
| CVE-2012-0289 | Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.710x allows local users to gain privileges, and modify data or cause a denial of service, via a crafted… | EXPLOITHIGH 7.2EPSS 1.46% | 23 May 2012 |
| CVE-2012-1990 | Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric Kerweb before 3.0.1 and Kerwin before 6.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the evtvariablename parameter in an evts.xml action to kw.dll,… | EXPLOIT ✓MEDIUM 4.3EPSS 1.63% | 22 May 2012 |
| CVE-2012-2926 | Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before… | EXPLOIT ✓CRITICAL 9.1EPSS 66.6% | 22 May 2012 |
| CVE-2012-2925 | SQL injection vulnerability in engine.php in Simple PHP Agenda 2.2.8 allows remote attackers to execute arbitrary SQL commands via the priority parameter in an addTodo action. | EXPLOIT ✓HIGH 7.5EPSS 1.05% | 21 May 2012 |
| CVE-2012-2924 | PHP remote file inclusion vulnerability in admin/setup.inc.php in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOITHIGH 7.5EPSS 2.56% | 21 May 2012 |
| CVE-2012-2923 | SQL injection vulnerability in news.php4 in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary SQL commands via the nid parameter. | EXPLOITHIGH 7.5EPSS 1.11% | 21 May 2012 |
| CVE-2012-2919 | Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the existence of arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.34% | 21 May 2012 |
| CVE-2012-2918 | Cross-site scripting (XSS) vulnerability in Upload/engine.php in Chevereto 1.91 allows remote attackers to inject arbitrary web script or HTML via the v parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.62% | 21 May 2012 |
| CVE-2012-2344 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 21 May 2012 |
| CVE-2012-2338 | SQL injection vulnerability in includes/picture.class.php in Galette 0.63, 0.63.1, 0.63.2, 0.63.3, and 0.64rc1 allows remote attackers to execute arbitrary SQL commands via the id_adh parameter to picture.php. | EXPLOIT ✓HIGH 7.5EPSS 2.23% | 21 May 2012 |
| CVE-2012-2271 | Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0 allows remote attackers to execute arbitrary code via a long string in the first argument (aka the reg_name argument). | EXPLOIT ×2 ✓HIGH 10.0EPSS 7.83% | 21 May 2012 |
| CVE-2012-0299 | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly execute this code, via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 64.1% | 21 May 2012 |
| CVE-2012-0298 | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrary files via unspecified vectors. | EXPLOIT ✓MEDIUM 6.4EPSS 9.44% | 21 May 2012 |
| CVE-2012-0297 | The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data. | EXPLOIT ×4 ✓HIGH 10.0EPSS 72.6% | 21 May 2012 |
| CVE-2012-2917 | Cross-site scripting (XSS) vulnerability in the Share and Follow plugin 1.80.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the CDN API Key (cnd-key) in a share-and-follow-menu page to wp-admin/admin.php. | EXPLOIT ✓MEDIUM 4.3EPSS 3.73% | 21 May 2012 |
| CVE-2012-2915 | Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary code via a long string in a Value tag in a SymbolicSchematicData definition tag in PAC Design (.pac) file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 29.5% | 21 May 2012 |
| CVE-2012-2914 | Cross-site scripting (XSS) vulnerability in captchademo.php in Unijimpe Captcha allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | EXPLOIT ✓MEDIUM 4.3EPSS 1.64% | 21 May 2012 |
| CVE-2012-2913 | Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) leaflet_layer.php or (2) leaflet_marker.php, as reachable through… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.80% | 21 May 2012 |
| CVE-2012-2911 | Cross-site scripting (XSS) vulnerability in backupDB.php in SiliSoftware backupDB() 1.2.7a allows remote attackers to inject arbitrary web script or HTML via the onlyDB parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.62% | 21 May 2012 |
| CVE-2012-2910 | Multiple cross-site scripting (XSS) vulnerabilities in SiliSoftware phpThumb() 1.7.11 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter to demo/phpThumb.demo.random.php or (2) title parameter to… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.67% | 21 May 2012 |
| CVE-2012-2909 | Multiple cross-site scripting (XSS) vulnerabilities in Viscacha 0.8.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) text field in the Private Messages System, (2) Bad Word field in Zensur, or (3) Portal or (4) Topic field… | EXPLOITMEDIUM 4.3EPSS 1.62% | 21 May 2012 |
| CVE-2012-2908 | Multiple SQL injection vulnerabilities in admin/bbcodes.php in Viscacha 0.8.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) bbcodeexample, (2) buttonimage, or (3) bbcodetag parameter. | EXPLOITHIGH 7.5EPSS 1.11% | 21 May 2012 |
| CVE-2012-2906 | Multiple cross-site scripting (XSS) vulnerabilities in artpublic/recommandation/index.php in Artiphp CMS 5.5.0 Neo (r422) allow remote attackers to inject arbitrary web script or HTML via the (1) add_img_name_post, (2) asciiart_post, (3) expediteur, (4)… | EXPLOIT ✓MEDIUM 4.3EPSS 2.01% | 21 May 2012 |
| CVE-2012-2905 | Artiphp CMS 5.5.0 Neo (r422) stores database backups with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request. | EXPLOIT ✓MEDIUM 5.0EPSS 3.11% | 21 May 2012 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.