Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,477 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 168 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2011-4709 | Multiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in the Search plugin 1.3 for Hotaru CMS allow remote attackers to inject arbitrary web script or HTML via the (1) SITE_NAME parameter to admin_index.php, or the (2) return and (3) search… | EXPLOIT ✓MEDIUM 4.3EPSS 1.98% | 8 December 2011 |
| CVE-2011-2917 | SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the zorder parameter. | EXPLOITHIGH 7.5EPSS 1.19% | 8 December 2011 |
| CVE-2011-2653 | Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote attackers to execute arbitrary code by uploading an executable file. | EXPLOIT ✓HIGH 10.0EPSS 72.5% | 8 December 2011 |
| CVE-2011-4684 | Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases." | EXPLOIT ✓HIGH 10.0EPSS 5.72% | 7 December 2011 |
| CVE-2011-2462 | Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 86.6% | 7 December 2011 |
| CVE-2011-4162 | The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Device Access Manager (PTDAM) before 6.1.0.1 allow remote attackers to execute arbitrary code or cause a… | EXPLOIT ✓HIGH 7.5EPSS 7.65% | 5 December 2011 |
| CVE-2011-4051 | CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and… | EXPLOIT ✓HIGH 10.0EPSS 69.1% | 5 December 2011 |
| CVE-2011-4674 | SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to execute arbitrary SQL commands via the only_hostid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.41% | 2 December 2011 |
| CVE-2011-4673 | SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOITHIGH 7.5EPSS 2.06% | 2 December 2011 |
| CVE-2011-4672 | Multiple SQL injection vulnerabilities in Valid tiny-erp 1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _partner_list.php, (2) proioncategory_list.php, (3)… | EXPLOITHIGH 7.5EPSS 1.04% | 2 December 2011 |
| CVE-2011-4671 | SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL). | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.90% | 2 December 2011 |
| CVE-2011-4670 | Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) viewname parameter in a CalendarAjax action, (2) activity_mode parameter in a DetailView… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.84% | 2 December 2011 |
| CVE-2011-4545 | CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the name parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 3.56% | 2 December 2011 |
| CVE-2011-4544 | Multiple cross-site scripting (XSS) vulnerabilities in Prestashop before 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) address or (2) relativ_base_dir parameter to modules/mondialrelay/googlemap.php; the (3)… | EXPLOIT ×4 ✓MEDIUM 4.3EPSS 3.13% | 1 December 2011 |
| CVE-2011-4540 | Multiple cross-site scripting (XSS) vulnerabilities in AtMail Open (aka AtMail Open-Source edition) 1.04 allow remote attackers to inject arbitrary web script or HTML via the func parameter to (1) ldap.php or (2) search.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.73% | 1 December 2011 |
| CVE-2011-4542 | Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI. | EXPLOIT ✓HIGH 7.5EPSS 24.1% | 30 November 2011 |
| CVE-2011-4317 | The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern… | EXPLOIT ✓MEDIUM 4.3EPSS 59.6% | 30 November 2011 |
| CVE-2011-4191 | Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (abend or NFS outage) via long packets. | EXPLOIT ×3 ✓HIGH 7.5EPSS 10.2% | 30 November 2011 |
| CVE-2011-3639 | The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of… | EXPLOIT ✓MEDIUM 4.3EPSS 50.6% | 30 November 2011 |
| CVE-2011-4572 | Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | EXPLOITMEDIUM 4.3EPSS 1.53% | 29 November 2011 |
| CVE-2011-4571 | SQL injection vulnerability in the Estate Agent (com_estateagent) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showEO action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 29 November 2011 |
| CVE-2011-4570 | SQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a timereturns action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.05% | 29 November 2011 |
| CVE-2011-4569 | SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 29 November 2011 |
| CVE-2011-4567 | Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a gv_send action to… | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 29 November 2011 |
| CVE-2011-4541 | Cross-site scripting (XSS) vulnerability in index.php in Hastymail2 2.1.1 before RC2 allows remote attackers to inject arbitrary web script or HTML via the rs parameter in a mailbox Drafts action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 29 November 2011 |
| CVE-2011-4564 | Cross-site scripting (XSS) vulnerability in the admin script in Active CMS 1.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter in a module action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 28 November 2011 |
| CVE-2011-4561 | Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.54% | 28 November 2011 |
| CVE-2011-4559 | SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.34% | 28 November 2011 |
| CVE-2011-4335 | Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php in a (1) teachers.html or (2) teachers/ action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.54% | 28 November 2011 |
| CVE-2011-4275 | Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted company name, (2) a crafted database server name, (3) a… | EXPLOIT ×6 ✓MEDIUM 4.3EPSS 1.49% | 26 November 2011 |
| CVE-2010-5062 | SQL injection vulnerability in search.php in MH Products kleinanzeigenmarkt allows remote attackers to execute arbitrary SQL commands via the c parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.32% | 23 November 2011 |
| CVE-2010-5060 | SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.09% | 23 November 2011 |
| CVE-2010-5059 | SQL injection vulnerability in index.php in CMScout 2.0.8 allows remote attackers to execute arbitrary SQL commands via the album parameter in a photos action. | EXPLOIT ✓HIGH 7.5EPSS 2.09% | 23 November 2011 |
| CVE-2010-5058 | SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the res_id parameter. | EXPLOITHIGH 7.5EPSS 0.93% | 23 November 2011 |
| CVE-2010-5057 | SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the tipodoc_id parameter. | EXPLOITHIGH 7.5EPSS 2.32% | 23 November 2011 |
| CVE-2010-5056 | SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the face_id parameter in a show_face action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.32% | 23 November 2011 |
| CVE-2010-5055 | SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.37% | 23 November 2011 |
| CVE-2010-5053 | SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a prod_desc action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.09% | 23 November 2011 |
| CVE-2010-5052 | Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the val[] parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.99% | 23 November 2011 |
| CVE-2010-5051 | Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php in razorCMS 1.0 stable allows remote attackers to inject arbitrary web script or HTML via the content parameter in an edit action to admin/index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.53% | 23 November 2011 |
| CVE-2010-5048 | Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.75% | 23 November 2011 |
| CVE-2010-5047 | SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOITHIGH 7.5EPSS 2.29% | 23 November 2011 |
| CVE-2010-5046 | Cross-site scripting (XSS) vulnerability in admin.php in ecoCMS allows remote attackers to inject arbitrary web script or HTML via the p parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.79% | 23 November 2011 |
| CVE-2011-4040 | Buffer overflow in MiniSmtp 3.0.11818 in NJStar Communicator allows remote attackers to execute arbitrary code via a crafted packet. | EXPLOIT ×2 ✓HIGH 10.0EPSS 65.3% | 21 November 2011 |
| CVE-2011-4404 | The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via… | EXPLOITMEDIUM 5.0EPSS 59.7% | 19 November 2011 |
| CVE-2011-4122 | Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. | EXPLOIT ✓MEDIUM 6.9EPSS 0.91% | 17 November 2011 |
| CVE-2011-4107 | The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity… | EXPLOITMEDIUM 6.5EPSS 12.7% | 17 November 2011 |
| CVE-2011-1516 | The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as… | EXPLOIT ✓HIGH 7.6EPSS 3.53% | 15 November 2011 |
| CVE-2011-4431 | Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. | EXPLOIT ✓MEDIUM 6.5EPSS 6.16% | 10 November 2011 |
| CVE-2011-2013 | Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed… | EXPLOIT ✓CRITICAL 9.8EPSS 33.7% | 8 November 2011 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.