SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,477 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 170 of 501

CVESummaryPriorityPublished
CVE-2010-5002Cross-site scripting (XSS) vulnerability in modules/slideshowmodule/slideshow.js.php in Exponent CMS 0.97.0 allows remote attackers to inject arbitrary web script or HTML via the u parameter.EXPLOITMEDIUM 4.3EPSS 1.73%1 November 2011
CVE-2010-5001SQL injection vulnerability in view.php in esoftpro Online Contact Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 0.99%1 November 2011
CVE-2010-4999SQL injection vulnerability in index.php in esoftpro Online Photo Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the section parameter.EXPLOITHIGH 7.5EPSS 0.99%1 November 2011
CVE-2010-4996SQL injection vulnerability in ogp_show.php in esoftpro Online Guestbook Pro 5.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.EXPLOIT ×2HIGH 7.5EPSS 1.00%1 November 2011
CVE-2010-4995SQL injection vulnerability in the NeoRecruit (com_neorecruit) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in an offer_view action to index.php, a different vector than CVE-2007-4506.EXPLOITHIGH 7.5EPSS 1.15%1 November 2011
CVE-2010-4993SQL injection vulnerability in the eventcal (com_eventcal) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.EXPLOITHIGH 7.5EPSS 1.02%1 November 2011
CVE-2010-4992SQL injection vulnerability in the Payments Plus component 2.1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the type parameter to add.html.EXPLOITHIGH 7.5EPSS 1.02%1 November 2011
CVE-2010-4991SQL injection vulnerability in the NinjaMonials (com_ninjamonials) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a display action to index.php.EXPLOITHIGH 7.5EPSS 0.98%1 November 2011
CVE-2010-4990SQL injection vulnerability in the Front-edit Address Book (com_addressbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a contact action to index.php.EXPLOITHIGH 7.5EPSS 0.99%1 November 2011
CVE-2010-4989SQL injection vulnerability in main.asp in Ziggurat Farsi CMS allows remote attackers to execute arbitrary SQL commands via the grp parameter.EXPLOITHIGH 7.5EPSS 0.98%1 November 2011
CVE-2010-4988PHP remote file inclusion vulnerability in mod_chatting/themes/default/header.php in Family Connections Who is Chatting 2.2.3 allows remote attackers to execute arbitrary PHP code via a URL in the TMPL[path] parameter.EXPLOITHIGH 7.5EPSS 2.35%1 November 2011
CVE-2010-4987SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary SQL commands via the p parameter.EXPLOITHIGH 7.5EPSS 0.99%1 November 2011
CVE-2010-4986SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter.EXPLOITHIGH 7.5EPSS 0.91%1 November 2011
CVE-2010-4985Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to inject arbitrary web script or HTML via vectors involving the "Enter Reference Number Below" text box.EXPLOITMEDIUM 4.3EPSS 1.52%1 November 2011
CVE-2010-4984SQL injection vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to execute arbitrary SQL commands via vectors involving the "Enter Reference Number Below" text box.EXPLOITHIGH 7.5EPSS 1.02%1 November 2011
CVE-2010-4983SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 1.19%1 November 2011
CVE-2010-4982SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attackers to execute arbitrary SQL commands via the var1 parameter.EXPLOITHIGH 7.5EPSS 0.99%1 November 2011
CVE-2010-4981SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 1.02%1 November 2011
CVE-2010-4980SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.EXPLOIT ×2HIGH 7.5EPSS 2.36%1 November 2011
CVE-2010-4979SQL injection vulnerability in image/view.php in CANDID allows remote attackers to execute arbitrary SQL commands via the image_id parameter.EXPLOITHIGH 7.5EPSS 0.99%1 November 2011
CVE-2010-4978Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter.EXPLOITMEDIUM 4.3EPSS 1.47%1 November 2011
CVE-2010-4977SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the mealid parameter to index.php.EXPLOITHIGH 7.5EPSS 15.3%1 November 2011
CVE-2010-4976Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter (aka Search Box field).EXPLOITMEDIUM 4.3EPSS 1.74%1 November 2011
CVE-2010-4975SQL injection vulnerability in the Techjoomla SocialAds For JomSocial (com_socialads) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the ads description field in a showad action to index.php.EXPLOITHIGH 7.5EPSS 0.98%1 November 2011
CVE-2010-4974SQL injection vulnerability in info.php in BrotherScripts (BS) and ScriptsFeed Auto Dealer allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 1.19%1 November 2011
CVE-2010-4972SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands via the ypncat_id parameter.EXPLOITHIGH 7.5EPSS 1.19%1 November 2011
CVE-2010-4970SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 1.02%1 November 2011
CVE-2010-4969SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 0.93%1 November 2011
CVE-2010-4968SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.EXPLOITHIGH 7.5EPSS 0.99%1 November 2011
CVE-2011-4222Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.EXPLOIT ×3HIGH 9.3EPSS 7.48%1 November 2011
CVE-2011-4221Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.EXPLOIT ×3HIGH 9.3EPSS 7.48%1 November 2011
CVE-2011-4220Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.EXPLOIT ×3HIGH 9.3EPSS 7.38%1 November 2011
CVE-2011-3315Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP…EXPLOITHIGH 7.8EPSS 25.7%27 October 2011
CVE-2011-4026SQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 2.03%21 October 2011
CVE-2011-4024Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.EXPLOITMEDIUM 4.3EPSS 5.14%21 October 2011
CVE-2011-3340SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.EXPLOITHIGH 7.5EPSS 1.99%21 October 2011
CVE-2010-4967SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artID parameter.EXPLOITHIGH 7.5EPSS 2.04%21 October 2011
CVE-2009-5103Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email variable.EXPLOITMEDIUM 4.3EPSS 2.56%21 October 2011
CVE-2009-5102SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpe_nid parameter.EXPLOITHIGH 7.5EPSS 2.22%21 October 2011
CVE-2011-3556Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect…EXPLOITHIGH 7.5EPSS 76.4%19 October 2011
CVE-2011-3544Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 96.7%19 October 2011
CVE-2011-4062Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or possibly gain privileges via a bind system call with a long pathname for a UNIX socket.EXPLOITHIGH 7.2EPSS 0.91%18 October 2011
CVE-2011-3230Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via a crafted web site.EXPLOITMEDIUM 6.8EPSS 49.3%14 October 2011
CVE-2011-2007Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."EXPLOITMEDIUM 5.0EPSS 23.0%12 October 2011
CVE-2011-2005Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 31.5%12 October 2011
CVE-2011-2003Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary…EXPLOITHIGH 9.3EPSS 26.6%12 October 2011
CVE-2011-1999Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arbitrary code via vectors involving a "dereferenced memory address," aka "Select Element Remote Code Execution Vulnerability."EXPLOITHIGH 9.3EPSS 26.7%12 October 2011
CVE-2011-1996Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."EXPLOITHIGH 9.3EPSS 58.8%12 October 2011
CVE-2011-1985win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local…EXPLOITHIGH 7.1EPSS 2.27%12 October 2011
CVE-2011-3587Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.EXPLOITHIGH 9.3EPSS 78.1%10 October 2011

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.