SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,425 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 164 of 501

CVESummaryPriorityPublished
CVE-2012-0242Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.EXPLOITHIGH 10.0EPSS 7.17%21 February 2012
CVE-2012-0241Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.EXPLOIT ×2MEDIUM 5.0EPSS 4.91%21 February 2012
CVE-2012-0200The server in IBM solidDB 6.5 before Interim Fix 6 does not properly initialize data structures, which allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a redundant WHERE condition.EXPLOITMEDIUM 4.0EPSS 5.73%21 February 2012
CVE-2012-1226Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a ..EXPLOIT ×2HIGH 7.5EPSS 25.1%21 February 2012
CVE-2012-1225Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) memberslist parameter (aka Member List) in list.php or (2) rowid parameter to…EXPLOITHIGH 7.5EPSS 2.55%21 February 2012
CVE-2012-1224Cross-site scripting (XSS) vulnerability in system/classes/login.php in ContentLion Alpha 1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.EXPLOITMEDIUM 4.3EPSS 1.33%21 February 2012
CVE-2012-1221Directory traversal vulnerability in the telnet server in RabidHamster R2/Extreme 1.65 and earlier allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 3.26%21 February 2012
CVE-2012-1220Cross-site request forgery (CSRF) vulnerability in modules/config/admin_utente.php in GAzie 5.20 and earlier allows remote attackers to hijack the authentication of administrators for requests that change account information via an update action, as…EXPLOITMEDIUM 6.8EPSS 1.06%21 February 2012
CVE-2012-0865Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php.EXPLOIT ×3MEDIUM 5.8EPSS 2.93%21 February 2012
CVE-2012-1217Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects.php, (2) prospect.php, or (3) team.php.EXPLOIT ×3MEDIUM 4.3EPSS 1.64%21 February 2012
CVE-2012-1200Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType parameter to optimizer/index.php, (2) id parameter to administrator/modules/moduleslist.php, (3) filename…EXPLOIT ×4HIGH 7.5EPSS 2.75%18 February 2012
CVE-2012-1199Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) BASE_path parameter to base_ag_main.php, (2) base_db_setup.php, (3)…EXPLOIT ×38HIGH 7.5EPSS 3.44%18 February 2012
CVE-2012-1198base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents of the file with an executable extension via a create action, then accessing it via a view action.EXPLOITHIGH 7.5EPSS 5.26%18 February 2012
CVE-2012-1196Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a ..EXPLOIT ×2MEDIUM 5.0EPSS 55.5%18 February 2012
CVE-2012-1195Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an…EXPLOIT ×2HIGH 7.5EPSS 68.4%18 February 2012
CVE-2011-4614PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4.6.x before 4.6.2, and development versions of 4.7 allows remote attackers to execute arbitrary PHP…EXPLOITMEDIUM 6.8EPSS 5.63%18 February 2012
CVE-2012-0754Adobe Flash Player Memory Corruption VulnerabilityKEVEXPLOITHIGH 8.1EPSS 92.0%16 February 2012
CVE-2012-0500Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to…EXPLOITHIGH 10.0EPSS 59.2%15 February 2012
CVE-2010-5083SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php.EXPLOITHIGH 7.5EPSS 1.10%14 February 2012
CVE-2012-1069Cross-site scripting (XSS) vulnerability in module/kb/search_word in the search module in lknSupport allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.EXPLOITMEDIUM 4.3EPSS 1.59%14 February 2012
CVE-2012-1065Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to create or overwrite arbitrary files via the ExportSettings method.EXPLOITMEDIUM 4.3EPSS 3.98%14 February 2012
CVE-2012-1009NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186 allow remote attackers to cause a denial of service (daemon crash) via a malformed LPD request.EXPLOITMEDIUM 5.0EPSS 2.97%14 February 2012
CVE-2012-0789Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering many strtotime function calls, which are not properly handled by the php_date_parse_tzfile cache.EXPLOITMEDIUM 5.0EPSS 8.26%14 February 2012
CVE-2012-0788The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls…EXPLOITMEDIUM 5.0EPSS 8.95%14 February 2012
CVE-2012-1059Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated…EXPLOITMEDIUM 4.3EPSS 3.53%14 February 2012
CVE-2012-1058Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an admin.newuser action to index.php.EXPLOITMEDIUM 6.0EPSS 0.92%14 February 2012
CVE-2012-1049Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to…EXPLOIT ×2MEDIUM 4.3EPSS 1.64%13 February 2012
CVE-2012-1048Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.EXPLOITMEDIUM 4.3EPSS 1.61%12 February 2012
CVE-2012-1047Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary local files via a ..EXPLOITHIGH 7.5EPSS 2.74%12 February 2012
CVE-2011-4341Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author permissions to execute arbitrary SQL commands via the filter…EXPLOITMEDIUM 4.3EPSS 2.88%12 February 2012
CVE-2011-4340Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author privileges to inject arbitrary web script or HTML via (1) the profile parameter to…EXPLOITLOW 3.5EPSS 1.87%12 February 2012
CVE-2012-0834Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.EXPLOITMEDIUM 4.3EPSS 4.97%11 February 2012
CVE-2012-0840tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU…EXPLOITMEDIUM 5.0EPSS 43.3%10 February 2012
CVE-2012-1008OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SIP INVITE message.EXPLOITMEDIUM 5.0EPSS 11.8%8 February 2012
CVE-2012-1002SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.EXPLOITHIGH 10.0EPSS 4.74%8 February 2012
CVE-2012-1029SQL injection vulnerability in mobile/search/index.php in Tube Ace (Adult PHP Tube Script) 1.6 allows remote attackers to execute arbitrary SQL commands via the q parameter.EXPLOIT ×2HIGH 7.5EPSS 1.27%8 February 2012
CVE-2012-1028Cross-site scripting (XSS) vulnerability in bin/index.php in SimpleGroupware 0.742 and other versions before 0.743 allows remote attackers to inject arbitrary web script or HTML via the export parameter.EXPLOITMEDIUM 4.3EPSS 1.61%8 February 2012
CVE-2012-1027Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the message parameter to register/account-closed.EXPLOITMEDIUM 4.3EPSS 2.41%8 February 2012
CVE-2012-1026Multiple SQL injection vulnerabilities in login2.php in XRay CMS 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.EXPLOITHIGH 7.5EPSS 1.10%8 February 2012
CVE-2012-1025Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remote attackers to read arbitrary files via a full pathname in the file parameter.EXPLOITMEDIUM 5.0EPSS 6.21%8 February 2012
CVE-2012-1024Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 3.64%8 February 2012
CVE-2012-1023Open redirect vulnerability in admin/index.php in 4images 1.7.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter.EXPLOITMEDIUM 5.8EPSS 2.00%8 February 2012
CVE-2012-1022SQL injection vulnerability in admin/categories.php in 4images 1.7.10 remote attackers to execute arbitrary SQL commands via the cat_parent_id parameter in an addcat action.EXPLOITHIGH 7.5EPSS 1.10%8 February 2012
CVE-2012-1021Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter in an addcat action.EXPLOITMEDIUM 4.3EPSS 1.61%8 February 2012
CVE-2012-1018Cross-site scripting (XSS) vulnerability in includes/convert.php in D-Mack Media Currency Converter (mod_currencyconverter) module 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the from parameter.EXPLOITMEDIUM 4.3EPSS 1.60%8 February 2012
CVE-2012-1017Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary SQL commands via the (1) ip_addr[0][1], (2) ip_addr[0][2], or (3) ip_addr[0][9] parameters.EXPLOITHIGH 7.5EPSS 1.44%8 February 2012
CVE-2012-1011actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitrary PHP code by setting the HTTP_REFERER to a certain value, then uploading a ZIP file containing a PHP…EXPLOITHIGH 7.5EPSS 9.04%7 February 2012
CVE-2012-1010Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a ZIP file containing a PHP file, then accessing it via a direct request to the…EXPLOITHIGH 7.5EPSS 8.94%7 February 2012
CVE-2012-1005Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary web script or HTML via the comment parameter to a blog, as demonstrated using (1) Blog/MyFirstBlog.txt or (2)…EXPLOITMEDIUM 4.3EPSS 1.49%7 February 2012
CVE-2012-0992interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file parameter.EXPLOITHIGH 8.5EPSS 3.66%7 February 2012

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.