Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,477 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 169 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2011-4415 | The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a… | EXPLOITLOW 1.2EPSS 3.10% | 8 November 2011 |
| CVE-2011-3607 | Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted… | EXPLOITMEDIUM 4.4EPSS 4.72% | 8 November 2011 |
| CVE-2011-4066 | SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO. | EXPLOITHIGH 7.5EPSS 1.67% | 4 November 2011 |
| CVE-2011-1513 | Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name. | EXPLOIT ✓HIGH 7.5EPSS 5.79% | 4 November 2011 |
| CVE-2011-4273 | Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/AddGroup, related to addgroup.asp; (2) the url parameter to… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 4.77% | 3 November 2011 |
| CVE-2010-5045 | Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 2 November 2011 |
| CVE-2010-5044 | SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to execute arbitrary SQL commands via the search parameter in a log action to… | EXPLOIT ×2MEDIUM 6.0EPSS 0.96% | 2 November 2011 |
| CVE-2010-5043 | SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the cid[] parameter in an editItem action to administrator/index.php. | EXPLOIT ✓MEDIUM 6.0EPSS 0.84% | 2 November 2011 |
| CVE-2010-5042 | Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the cid[] parameter in an editItem action to administrator/index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 2 November 2011 |
| CVE-2010-5041 | SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 2 November 2011 |
| CVE-2010-5040 | PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary PHP code via a URL in the DIR_NUCLEUS parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.00% | 2 November 2011 |
| CVE-2010-5039 | SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 2 November 2011 |
| CVE-2010-5037 | SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter. | EXPLOITHIGH 7.5EPSS 2.04% | 2 November 2011 |
| CVE-2010-5036 | SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 2 November 2011 |
| CVE-2010-5035 | Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the search field). | EXPLOIT ✓MEDIUM 4.3EPSS 1.78% | 2 November 2011 |
| CVE-2010-5034 | SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter. | EXPLOITHIGH 7.5EPSS 1.15% | 2 November 2011 |
| CVE-2010-5033 | SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL commands via the CatDisplay parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 2 November 2011 |
| CVE-2010-5032 | SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.69% | 2 November 2011 |
| CVE-2010-5029 | SQL injection vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the show parameter in a web action. | EXPLOITHIGH 7.5EPSS 1.15% | 2 November 2011 |
| CVE-2010-5028 | SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 9.25% | 2 November 2011 |
| CVE-2010-5027 | Cross-site scripting (XSS) vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.78% | 2 November 2011 |
| CVE-2010-5026 | SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.49% | 2 November 2011 |
| CVE-2010-5025 | Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or HTML via the fld_path parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 2 November 2011 |
| CVE-2010-5024 | SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter. | EXPLOIT ✓MEDIUM 6.0EPSS 0.95% | 2 November 2011 |
| CVE-2010-5023 | SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 2 November 2011 |
| CVE-2010-5022 | SQL injection vulnerability in the JExtensions JE Story Submit (com_jesubmit) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php. | EXPLOITHIGH 7.5EPSS 0.91% | 2 November 2011 |
| CVE-2010-5021 | SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intGroupID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 2 November 2011 |
| CVE-2010-5020 | SQL injection vulnerability in index.php in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.98% | 2 November 2011 |
| CVE-2010-5019 | SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arbitrary SQL commands via the alb parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.04% | 2 November 2011 |
| CVE-2010-5018 | Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 2 November 2011 |
| CVE-2010-5017 | SQL injection vulnerability in stats.php in Elite Gaming Ladders 3.0 allows remote attackers to execute arbitrary SQL commands via the account parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 2 November 2011 |
| CVE-2010-5016 | SQL injection vulnerability in matchdb.php in Elite Gaming Ladders 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the match parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 2 November 2011 |
| CVE-2010-5015 | SQL injection vulnerability in view_photo.php in 2daybiz Network Community Script allows remote attackers to execute arbitrary SQL commands via the alb parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 2 November 2011 |
| CVE-2010-5014 | SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 2 November 2011 |
| CVE-2010-5013 | SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 2 November 2011 |
| CVE-2010-5012 | SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOITHIGH 7.5EPSS 1.19% | 2 November 2011 |
| CVE-2010-5011 | SQL injection vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to execute arbitrary SQL commands via the session parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 2 November 2011 |
| CVE-2010-5010 | Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to inject arbitrary web script or HTML via the session parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.78% | 2 November 2011 |
| CVE-2010-5009 | SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 2 November 2011 |
| CVE-2010-5008 | SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to execute arbitrary SQL commands via the ContactID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 2 November 2011 |
| CVE-2010-5007 | Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web script or HTML via the mid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 2 November 2011 |
| CVE-2010-5004 | SQL injection vulnerability in searchvote.php in 2daybiz Polls (aka Advanced Poll) Script allows remote attackers to execute arbitrary SQL commands via the category parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 2 November 2011 |
| CVE-2010-5000 | SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the myusername parameter (aka Username field) in a do_login action. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 2 November 2011 |
| CVE-2010-4998 | PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the pathForArdeaCore parameter. | EXPLOITHIGH 7.5EPSS 2.93% | 2 November 2011 |
| CVE-2010-4997 | SQL injection vulnerability in index.php in OlyKit Swoopo Clone 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter in a product action. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 2 November 2011 |
| CVE-2010-4971 | Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the r parameter to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.53% | 2 November 2011 |
| CVE-2011-4075 | The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October… | EXPLOIT ×2 ✓HIGH 7.5EPSS 51.9% | 2 November 2011 |
| CVE-2011-4074 | Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command. | EXPLOIT ✓MEDIUM 4.3EPSS 5.39% | 2 November 2011 |
| CVE-2011-3167 | Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210. | EXPLOIT ✓HIGH 10.0EPSS 65.0% | 2 November 2011 |
| CVE-2010-5003 | SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the limit parameter in an autartimonial action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.59% | 1 November 2011 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.