SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,477 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 169 of 501

CVESummaryPriorityPublished
CVE-2011-4415The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a…EXPLOITLOW 1.2EPSS 3.10%8 November 2011
CVE-2011-3607Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted…EXPLOITMEDIUM 4.4EPSS 4.72%8 November 2011
CVE-2011-4066SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.EXPLOITHIGH 7.5EPSS 1.67%4 November 2011
CVE-2011-1513Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.EXPLOITHIGH 7.5EPSS 5.79%4 November 2011
CVE-2011-4273Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/AddGroup, related to addgroup.asp; (2) the url parameter to…EXPLOIT ×3MEDIUM 4.3EPSS 4.77%3 November 2011
CVE-2010-5045Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter.EXPLOITMEDIUM 4.3EPSS 1.48%2 November 2011
CVE-2010-5044SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to execute arbitrary SQL commands via the search parameter in a log action to…EXPLOIT ×2MEDIUM 6.0EPSS 0.96%2 November 2011
CVE-2010-5043SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the cid[] parameter in an editItem action to administrator/index.php.EXPLOITMEDIUM 6.0EPSS 0.84%2 November 2011
CVE-2010-5042Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the cid[] parameter in an editItem action to administrator/index.php.EXPLOITMEDIUM 4.3EPSS 1.72%2 November 2011
CVE-2010-5041SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action.EXPLOITHIGH 7.5EPSS 1.15%2 November 2011
CVE-2010-5040PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary PHP code via a URL in the DIR_NUCLEUS parameter.EXPLOITMEDIUM 6.8EPSS 2.00%2 November 2011
CVE-2010-5039SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field).EXPLOITHIGH 7.5EPSS 1.02%2 November 2011
CVE-2010-5037SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter.EXPLOITHIGH 7.5EPSS 2.04%2 November 2011
CVE-2010-5036SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.EXPLOITHIGH 7.5EPSS 1.15%2 November 2011
CVE-2010-5035Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the search field).EXPLOITMEDIUM 4.3EPSS 1.78%2 November 2011
CVE-2010-5034SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter.EXPLOITHIGH 7.5EPSS 1.15%2 November 2011
CVE-2010-5033SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL commands via the CatDisplay parameter.EXPLOITHIGH 7.5EPSS 1.02%2 November 2011
CVE-2010-5032SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php.EXPLOIT ×2HIGH 7.5EPSS 1.69%2 November 2011
CVE-2010-5029SQL injection vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the show parameter in a web action.EXPLOITHIGH 7.5EPSS 1.15%2 November 2011
CVE-2010-5028SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.EXPLOIT ×2HIGH 7.5EPSS 9.25%2 November 2011
CVE-2010-5027Cross-site scripting (XSS) vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter.EXPLOITMEDIUM 4.3EPSS 1.78%2 November 2011
CVE-2010-5026SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.EXPLOITMEDIUM 6.8EPSS 1.49%2 November 2011
CVE-2010-5025Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or HTML via the fld_path parameter.EXPLOITMEDIUM 4.3EPSS 1.72%2 November 2011
CVE-2010-5024SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter.EXPLOITMEDIUM 6.0EPSS 0.95%2 November 2011
CVE-2010-5023SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter.EXPLOITHIGH 7.5EPSS 1.15%2 November 2011
CVE-2010-5022SQL injection vulnerability in the JExtensions JE Story Submit (com_jesubmit) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.EXPLOITHIGH 7.5EPSS 0.91%2 November 2011
CVE-2010-5021SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intGroupID parameter.EXPLOITHIGH 7.5EPSS 1.19%2 November 2011
CVE-2010-5020SQL injection vulnerability in index.php in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.EXPLOITHIGH 7.5EPSS 0.98%2 November 2011
CVE-2010-5019SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.EXPLOITHIGH 7.5EPSS 2.04%2 November 2011
CVE-2010-5018Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter.EXPLOITMEDIUM 4.3EPSS 1.48%2 November 2011
CVE-2010-5017SQL injection vulnerability in stats.php in Elite Gaming Ladders 3.0 allows remote attackers to execute arbitrary SQL commands via the account parameter.EXPLOITHIGH 7.5EPSS 1.02%2 November 2011
CVE-2010-5016SQL injection vulnerability in matchdb.php in Elite Gaming Ladders 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the match parameter.EXPLOITHIGH 7.5EPSS 0.99%2 November 2011
CVE-2010-5015SQL injection vulnerability in view_photo.php in 2daybiz Network Community Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.EXPLOITHIGH 7.5EPSS 1.02%2 November 2011
CVE-2010-5014SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.EXPLOITHIGH 7.5EPSS 0.99%2 November 2011
CVE-2010-5013SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter.EXPLOITHIGH 7.5EPSS 1.19%2 November 2011
CVE-2010-5012SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 1.19%2 November 2011
CVE-2010-5011SQL injection vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to execute arbitrary SQL commands via the session parameter.EXPLOITHIGH 7.5EPSS 1.02%2 November 2011
CVE-2010-5010Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to inject arbitrary web script or HTML via the session parameter.EXPLOITMEDIUM 4.3EPSS 1.78%2 November 2011
CVE-2010-5009SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action.EXPLOITHIGH 7.5EPSS 1.15%2 November 2011
CVE-2010-5008SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to execute arbitrary SQL commands via the ContactID parameter.EXPLOITHIGH 7.5EPSS 1.02%2 November 2011
CVE-2010-5007Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web script or HTML via the mid parameter.EXPLOITMEDIUM 4.3EPSS 1.72%2 November 2011
CVE-2010-5004SQL injection vulnerability in searchvote.php in 2daybiz Polls (aka Advanced Poll) Script allows remote attackers to execute arbitrary SQL commands via the category parameter.EXPLOITHIGH 7.5EPSS 0.91%2 November 2011
CVE-2010-5000SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the myusername parameter (aka Username field) in a do_login action.EXPLOITHIGH 7.5EPSS 1.02%2 November 2011
CVE-2010-4998PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the pathForArdeaCore parameter.EXPLOITHIGH 7.5EPSS 2.93%2 November 2011
CVE-2010-4997SQL injection vulnerability in index.php in OlyKit Swoopo Clone 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter in a product action.EXPLOITHIGH 7.5EPSS 0.91%2 November 2011
CVE-2010-4971Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the r parameter to index.php.EXPLOITMEDIUM 4.3EPSS 1.53%2 November 2011
CVE-2011-4075The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October…EXPLOIT ×2HIGH 7.5EPSS 51.9%2 November 2011
CVE-2011-4074Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.EXPLOITMEDIUM 4.3EPSS 5.39%2 November 2011
CVE-2011-3167Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210.EXPLOITHIGH 10.0EPSS 65.0%2 November 2011
CVE-2010-5003SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the limit parameter in an autartimonial action to index.php.EXPLOITHIGH 7.5EPSS 1.59%1 November 2011

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.