Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,425 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 163 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-0067 | wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file. | EXPLOIT ✓MEDIUM 4.3EPSS 6.52% | 11 April 2012 |
| CVE-2012-1182 | The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute… | EXPLOIT ✓HIGH 10.0EPSS 74.4% | 10 April 2012 |
| CVE-2012-0163 | Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted… | EXPLOITHIGH 9.3EPSS 38.3% | 10 April 2012 |
| CVE-2012-0158 | Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 100.0% | 10 April 2012 |
| CVE-2011-3176 | Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x4c request. | EXPLOIT ×2 ✓HIGH 10.0EPSS 70.1% | 9 April 2012 |
| CVE-2011-3175 | Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x6c request. | EXPLOIT ×2 ✓HIGH 10.0EPSS 66.1% | 9 April 2012 |
| CVE-2012-1239 | The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative… | EXPLOIT ✓HIGH 10.0EPSS 4.67% | 6 April 2012 |
| CVE-2011-4535 | Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 26.7% | 3 April 2012 |
| CVE-2011-4045 | Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of service via a crafted HTML document. | EXPLOIT ✓MEDIUM 4.3EPSS 3.69% | 3 April 2012 |
| CVE-2011-4044 | An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to unknown methods. | EXPLOIT ×2 ✓MEDIUM 5.8EPSS 26.7% | 3 April 2012 |
| CVE-2011-4043 | Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to a buffer… | EXPLOIT ✓HIGH 9.3EPSS 7.42% | 3 April 2012 |
| CVE-2011-4042 | An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer. | EXPLOIT ✓HIGH 9.3EPSS 6.43% | 3 April 2012 |
| CVE-2012-0221 | The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause… | EXPLOIT ✓MEDIUM 5.0EPSS 10.2% | 2 April 2012 |
| CVE-2012-1670 | admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action. | EXPLOIT ✓MEDIUM 5.0EPSS 7.67% | 31 March 2012 |
| CVE-2012-1913 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 28 March 2012 |
| CVE-2012-1904 | mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, allows remote attackers to cause a denial of service (memory corruption and application crash) via a… | EXPLOITMEDIUM 4.3EPSS 4.74% | 28 March 2012 |
| CVE-2007-6752 | Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. | EXPLOITMEDIUM 6.8EPSS 3.71% | 28 March 2012 |
| CVE-2012-1498 | Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via an add action to admin/users/add or (2)… | EXPLOITMEDIUM 6.8EPSS 1.20% | 19 March 2012 |
| CVE-2012-1466 | The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in an HTTP request, as demonstrated using default.nd. | EXPLOIT ✓MEDIUM 5.0EPSS 3.33% | 19 March 2012 |
| CVE-2012-1465 | Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause a denial of service (application crash) via a long URL in an HTTP request. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 27.1% | 19 March 2012 |
| CVE-2012-1464 | Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" character, which causes Dashboard to attempt to access a non-existent resource. | EXPLOIT ✓MEDIUM 5.0EPSS 3.33% | 19 March 2012 |
| CVE-2012-1039 | Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5)… | EXPLOIT ×4 ✓MEDIUM 4.3EPSS 3.98% | 19 March 2012 |
| CVE-2012-1790 | Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php. | EXPLOIT ✓MEDIUM 5.0EPSS 5.13% | 19 March 2012 |
| CVE-2012-1787 | Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) FILE, or (3) DOMAIN parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.79% | 19 March 2012 |
| CVE-2012-1784 | SQL injection vulnerability in MyJobList 0.1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter in a profile action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 19 March 2012 |
| CVE-2012-1783 | Tiny Server 1.1.9 and earlier allows remote attackers to cause a denial of service (crash) via a long string in a GET request without an HTTP version number. | EXPLOIT ✓HIGH 7.8EPSS 2.63% | 19 March 2012 |
| CVE-2012-1782 | Multiple cross-site scripting (XSS) vulnerabilities in questions/ask in OSQA 3b allow remote attackers to inject arbitrary web script or HTML via the (1) url bar or (2) picture bar. | EXPLOIT ✓MEDIUM 4.3EPSS 1.59% | 19 March 2012 |
| CVE-2012-1778 | SQL injection vulnerability in artykul_print.php in CreateVision CMS allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 19 March 2012 |
| CVE-2012-1297 | Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via a delete action in the… | EXPLOITMEDIUM 6.8EPSS 1.06% | 19 March 2012 |
| CVE-2009-5114 | Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 13.3% | 19 March 2012 |
| CVE-2009-5112 | wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request. | EXPLOIT ✓MEDIUM 5.0EPSS 5.34% | 19 March 2012 |
| CVE-2012-1775 | Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS:// stream. | EXPLOIT ✓HIGH 9.3EPSS 44.1% | 19 March 2012 |
| CVE-2012-1774 | Unspecified vulnerability in the Open URL feature in Gretech GOM Media Player before 2.1.39.5101 has unknown impact and attack vectors, a different vulnerability than CVE-2007-5779 and CVE-2012-1264. | EXPLOITHIGH 10.0EPSS 7.23% | 18 March 2012 |
| CVE-2012-0124 | Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors. | EXPLOIT ✓HIGH 10.0EPSS 62.3% | 14 March 2012 |
| CVE-2012-1663 | Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted certificate list. | EXPLOITHIGH 7.5EPSS 5.18% | 13 March 2012 |
| CVE-2012-0016 | Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory… | EXPLOIT ✓HIGH 9.3EPSS 21.9% | 13 March 2012 |
| CVE-2012-0002 | The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which… | EXPLOIT ✓HIGH 9.3EPSS 74.1% | 13 March 2012 |
| CVE-2012-0292 | The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris… | EXPLOITMEDIUM 5.0EPSS 7.09% | 8 March 2012 |
| CVE-2012-0198 | Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allows remote attackers to execute arbitrary code via vectors related to an Asset… | EXPLOIT ✓HIGH 9.3EPSS 37.4% | 6 March 2012 |
| CVE-2011-4189 | The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via a long e-mail address in an Address Book (aka .NAB) file. | EXPLOITHIGH 7.5EPSS 11.6% | 2 March 2012 |
| CVE-2012-0201 | Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote attackers to execute arbitrary code via a long profile string in a WorkStation (aka .ws) file. | EXPLOIT ✓HIGH 9.3EPSS 36.8% | 2 March 2012 |
| CVE-2012-1213 | Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.60% | 24 February 2012 |
| CVE-2012-1211 | Cross-site scripting (XSS) vulnerability in pfile/kommentar.php in Powie pFile 1.02 allows remote attackers to inject arbitrary web script or HTML via the filecat parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.60% | 24 February 2012 |
| CVE-2012-1210 | SQL injection vulnerability in pfile/file.php in Powie pFile 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.10% | 24 February 2012 |
| CVE-2012-1208 | Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) report parameter to blog/settings or… | EXPLOIT ×2MEDIUM 4.3EPSS 4.08% | 24 February 2012 |
| CVE-2012-1205 | PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter. | EXPLOIT ✓HIGH 7.5EPSS 24.9% | 24 February 2012 |
| CVE-2012-0997 | Cross-site request forgery (CSRF) vulnerability in admin/index.php in 11in1 1.2.1 stable 12-31-2011 allows remote attackers to hijack the authentication of administrators for requests that add new topics via an addTopic action. | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 24 February 2012 |
| CVE-2012-0996 | Multiple directory traversal vulnerabilities in 11in1 1.2.1 stable 12-31-2011 allow remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 9.79% | 24 February 2012 |
| CVE-2012-1294 | SQL injection vulnerability in CONTIMEX Impulsio CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.10% | 23 February 2012 |
| CVE-2012-0873 | Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to explanation.php or the (2) photos_only, (3) online_only, or (4) mode… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 4.25% | 23 February 2012 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.