SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,425 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 165 of 501

CVESummaryPriorityPublished
CVE-2012-0991Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a ..EXPLOIT ×3LOW 3.5EPSS 9.19%7 February 2012
CVE-2012-0990Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or…EXPLOITLOW 3.5EPSS 0.93%7 February 2012
CVE-2012-1007Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2)…EXPLOITMEDIUM 4.3EPSS 32.9%7 February 2012
CVE-2012-1006Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3)…EXPLOITMEDIUM 4.3EPSS 56.6%7 February 2012
CVE-2012-0830The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.EXPLOITHIGH 7.5EPSS 29.8%6 February 2012
CVE-2011-4041webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.EXPLOITHIGH 10.0EPSS 17.7%6 February 2012
CVE-2011-4879miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and…EXPLOITHIGH 8.5EPSS 12.1%3 February 2012
CVE-2011-4878Directory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels;…EXPLOITHIGH 7.8EPSS 11.1%3 February 2012
CVE-2011-4877HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer…EXPLOITHIGH 7.1EPSS 7.26%3 February 2012
CVE-2011-4876Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and…EXPLOITHIGH 9.3EPSS 9.05%3 February 2012
CVE-2011-4875Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC…EXPLOITHIGH 9.3EPSS 13.8%3 February 2012
CVE-2012-0983SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.EXPLOITHIGH 7.5EPSS 1.05%2 February 2012
CVE-2012-0982SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the price_from parameter.EXPLOITHIGH 7.5EPSS 1.01%2 February 2012
CVE-2012-0981Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a ..EXPLOITMEDIUM 5.0EPSS 9.46%2 February 2012
CVE-2012-0980SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.EXPLOITHIGH 7.5EPSS 1.01%2 February 2012
CVE-2011-3659Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect…EXPLOITHIGH 9.3EPSS 36.8%1 February 2012
CVE-2012-0809Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.EXPLOIT ×2HIGH 7.2EPSS 2.95%1 February 2012
CVE-2012-0937wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attackers to use WordPress as a proxy for brute-force attacks…EXPLOITMEDIUM 5.0EPSS 7.63%30 January 2012
CVE-2012-0782Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname…EXPLOITMEDIUM 4.3EPSS 3.55%30 January 2012
CVE-2011-4899wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname…EXPLOITHIGH 7.5EPSS 8.86%30 January 2012
CVE-2011-4898wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote…EXPLOITMEDIUM 5.0EPSS 9.04%30 January 2012
CVE-2011-5075translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive information via a direct request using the save action, which reveals the installation path.EXPLOITMEDIUM 5.0EPSS 2.58%29 January 2012
CVE-2011-5074Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the authentication of administrators for requests that change administrator email, add a new administrator, or…EXPLOITMEDIUM 6.8EPSS 1.00%29 January 2012
CVE-2011-5073Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbitrary web script or HTML via the (1) mode parameter to contact_support.php; (2) contractid parameter to…EXPLOITMEDIUM 4.3EPSS 1.49%29 January 2012
CVE-2011-5072Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to execute arbitrary SQL commands via the (1) start parameter to portal/kb.php; (2) contractid parameter to contract_add_service.php; (3) id…EXPLOITHIGH 7.5EPSS 1.02%29 January 2012
CVE-2011-4337Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to inject arbitrary PHP code into an executable language file in the i18n directory via the lang variable.EXPLOITHIGH 7.5EPSS 2.39%29 January 2012
CVE-2012-0935SQL injection vulnerability in Default.aspx in Aryadad CMS allows remote attackers to execute arbitrary SQL commands via the PageID parameter.EXPLOITHIGH 7.5EPSS 1.01%29 January 2012
CVE-2012-0933Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS 3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_colors.asp, (2) admin_config.asp, and (3)…EXPLOITLOW 2.6EPSS 3.77%29 January 2012
CVE-2012-0932Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to inject arbitrary web script or HTML via the message parameter.EXPLOITMEDIUM 4.3EPSS 1.49%29 January 2012
CVE-2011-5071Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to report_marketing.php, (2) selected[] parameter to tasks.php, (3) sites[]…EXPLOIT ×4HIGH 7.5EPSS 1.05%29 January 2012
CVE-2011-3833Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in an…EXPLOITMEDIUM 6.0EPSS 19.1%29 January 2012
CVE-2011-3829ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error message.EXPLOITMEDIUM 4.0EPSS 17.3%29 January 2012
CVE-2012-0053protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors…EXPLOITMEDIUM 4.3EPSS 82.2%28 January 2012
CVE-2012-0056The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.EXPLOIT ×2MEDIUM 6.9EPSS 10.8%27 January 2012
CVE-2011-3479Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), uses world-writable permissions for product-installation files, which allows local users to gain privileges by modifying a file.EXPLOITMEDIUM 6.8EPSS 0.95%25 January 2012
CVE-2011-3478The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), does not properly filter login and authentication data, which allows remote attackers to execute…EXPLOIT ×2HIGH 10.0EPSS 39.5%25 January 2012
CVE-2012-0913SQL injection vulnerability in checklogin.aspx in ICloudCenter ICTimeAttendance 1.0 allows remote attackers to execute arbitrary SQL commands via the passw parameter.EXPLOITHIGH 7.5EPSS 1.05%24 January 2012
CVE-2012-0389Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.53, and 6.x before 6.03 allows remote attackers to inject arbitrary web script or HTML via the Username…EXPLOIT ×2MEDIUM 4.3EPSS 8.12%24 January 2012
CVE-2012-0286Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack the authentication of unspecified victims for requests that modify user accounts.EXPLOITMEDIUM 6.8EPSS 0.95%24 January 2012
CVE-2012-0285Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork before 6.0.8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.EXPLOITMEDIUM 4.3EPSS 1.47%24 January 2012
CVE-2012-0906SQL injection vulnerability in the Moviebase addon for deV!L'z Clanportal (DZCP) 1.5.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a showkat action to index.php.EXPLOITHIGH 7.5EPSS 0.95%20 January 2012
CVE-2012-0905SQL injection vulnerability in deV!L'z Clanportal (DZCP) Gamebase addon allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a detail action to index.php.EXPLOITHIGH 7.5EPSS 1.02%20 January 2012
CVE-2012-0904VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file.EXPLOITMEDIUM 4.3EPSS 4.84%20 January 2012
CVE-2012-0902AirTies Air 4450 1.1.2.18 allows remote attackers to cause a denial of service (reboot) via a direct request to cgi-bin/loader.EXPLOITMEDIUM 5.0EPSS 2.71%20 January 2012
CVE-2012-0901Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.EXPLOITMEDIUM 4.3EPSS 6.85%20 January 2012
CVE-2012-0900Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php.EXPLOITMEDIUM 4.3EPSS 1.53%20 January 2012
CVE-2012-0899Cross-site scripting (XSS) vulnerability in referencement/sites_inscription.php in Annuaire PHP allows remote attackers to inject arbitrary web script or HTML via the url parameter and possibly the nom parameter.EXPLOITMEDIUM 4.3EPSS 1.46%20 January 2012
CVE-2012-0897Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.EXPLOITMEDIUM 6.8EPSS 52.2%20 January 2012
CVE-2012-0896Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.EXPLOITMEDIUM 5.0EPSS 22.7%20 January 2012
CVE-2012-0895Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter.EXPLOITMEDIUM 4.3EPSS 5.32%20 January 2012

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.