SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,516 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 172 of 501

CVESummaryPriorityPublished
CVE-2010-4898SQL injection vulnerability in the Gantry (com_gantry) component 3.0.10 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter to index.php.EXPLOITHIGH 7.5EPSS 1.02%8 October 2011
CVE-2010-4895Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the username field).EXPLOITMEDIUM 4.3EPSS 2.26%8 October 2011
CVE-2010-4894SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL commands via the name parameter.EXPLOITHIGH 7.5EPSS 1.97%8 October 2011
CVE-2010-4893Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary web script or HTML via the category parameter in a details action.EXPLOITMEDIUM 4.3EPSS 1.54%8 October 2011
CVE-2010-4884PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the script_pfad parameter.EXPLOITHIGH 7.5EPSS 5.83%7 October 2011
CVE-2010-4883Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inject arbitrary web script or HTML via the modhash parameter.EXPLOITLOW 2.6EPSS 1.98%7 October 2011
CVE-2010-4882Cross-site scripting (XSS) vulnerability in autocms.php in Auto CMS 1.6 allows remote attackers to inject arbitrary web script or HTML via the sitetitle parameter.EXPLOITMEDIUM 4.3EPSS 1.49%7 October 2011
CVE-2010-4879PHP remote file inclusion vulnerability in dompdf.php in dompdf 0.6.0 beta1 allows remote attackers to execute arbitrary PHP code via a URL in the input_file parameter.EXPLOITHIGH 7.5EPSS 5.23%7 October 2011
CVE-2010-4878PHP remote file inclusion vulnerability in formmailer.php in Kontakt Formular 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the script_pfad parameter.EXPLOITHIGH 7.5EPSS 2.04%7 October 2011
CVE-2010-4877Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the view parameter.EXPLOITMEDIUM 4.3EPSS 1.50%7 October 2011
CVE-2010-4876SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands via the postID parameter.EXPLOITHIGH 7.5EPSS 0.91%7 October 2011
CVE-2010-4875Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gid parameter.EXPLOITMEDIUM 4.3EPSS 3.97%7 October 2011
CVE-2010-4874Multiple cross-site scripting (XSS) vulnerabilities in users.php in NinkoBB 1.3 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, (3) msn, or (4) aim parameter.EXPLOITMEDIUM 4.3EPSS 2.15%7 October 2011
CVE-2010-4873Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOITMEDIUM 4.3EPSS 1.78%7 October 2011
CVE-2010-4872SQL injection vulnerability in newsroom.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the specific parameter.EXPLOITHIGH 7.5EPSS 0.99%7 October 2011
CVE-2010-4870SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.EXPLOITHIGH 7.5EPSS 1.18%7 October 2011
CVE-2011-3368The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which…EXPLOITMEDIUM 5.0EPSS 90.7%5 October 2011
CVE-2010-4869SQL injection vulnerability in index.php in DBHcms 1.1.4 allows remote attackers to execute arbitrary SQL commands via the editmenu parameter.EXPLOITHIGH 7.5EPSS 0.99%5 October 2011
CVE-2010-4868Cross-site scripting (XSS) vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the bn parameter.EXPLOITMEDIUM 4.3EPSS 1.47%5 October 2011
CVE-2010-4867Directory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOITHIGH 7.5EPSS 2.44%5 October 2011
CVE-2010-4866SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands via the forumID parameter.EXPLOITHIGH 7.5EPSS 1.02%5 October 2011
CVE-2010-4865SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the d_itemid parameter in an item_detail action to index.php.EXPLOITHIGH 7.5EPSS 1.59%5 October 2011
CVE-2010-4864SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cm_id parameter in an equip presenta action to index.php.EXPLOITHIGH 7.5EPSS 0.99%5 October 2011
CVE-2010-4863Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the post-title parameter.EXPLOITMEDIUM 4.3EPSS 3.34%5 October 2011
CVE-2010-4862SQL injection vulnerability in the JExtensions JE Directory (com_jedirectory) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.EXPLOITHIGH 7.5EPSS 1.02%5 October 2011
CVE-2010-4861SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.EXPLOITHIGH 7.5EPSS 1.21%5 October 2011
CVE-2010-4860SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 0.99%5 October 2011
CVE-2010-4858Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 2.72%5 October 2011
CVE-2010-4857SQL injection vulnerability in click.php in CAG CMS 0.2 Beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter.EXPLOITHIGH 7.5EPSS 1.02%5 October 2011
CVE-2010-4856SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.EXPLOITHIGH 7.5EPSS 0.90%5 October 2011
CVE-2010-4855SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter.EXPLOITHIGH 7.5EPSS 0.99%5 October 2011
CVE-2010-4853SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php.EXPLOITHIGH 7.5EPSS 0.99%5 October 2011
CVE-2011-1159acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs…EXPLOITLOW 2.1EPSS 1.09%5 October 2011
CVE-2008-7301SQL injection vulnerability in admin/login.php in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOITHIGH 7.5EPSS 0.91%5 October 2011
CVE-2011-2443Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted (1) .grd or (2) .abr file, a related…EXPLOITHIGH 9.3EPSS 13.7%4 October 2011
CVE-2011-3981PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.EXPLOITHIGH 7.5EPSS 10.1%4 October 2011
CVE-2011-3979Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application Framework 1.3.0 build 3168, 1.2.7, and probably other versions allows remote attackers to inject arbitrary web…EXPLOITMEDIUM 4.3EPSS 4.16%4 October 2011
CVE-2011-3976Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST command, as demonstrated using (1) GETLIST or (2) GETFILE in a ScriptFTP script.EXPLOIT ×3MEDIUM 6.8EPSS 30.6%4 October 2011
CVE-2011-3579server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML…EXPLOITMEDIUM 6.4EPSS 4.78%30 September 2011
CVE-2011-3010Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreateNewTopic action, related to the TWiki.WebCreateNewTopicTemplate topic;…EXPLOIT ×2MEDIUM 4.3EPSS 5.48%30 September 2011
CVE-2011-3865Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.EXPLOITMEDIUM 4.3EPSS 3.53%28 September 2011
CVE-2011-3863Cross-site scripting (XSS) vulnerability in the RedLine theme before 1.66 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.EXPLOITMEDIUM 4.3EPSS 3.43%28 September 2011
CVE-2011-3862Cross-site scripting (XSS) vulnerability in the Morning Coffee theme before 3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.EXPLOITMEDIUM 4.3EPSS 3.68%28 September 2011
CVE-2011-3861Cross-site scripting (XSS) vulnerability in the Web Minimalist 200901 theme before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.EXPLOITMEDIUM 4.3EPSS 3.53%28 September 2011
CVE-2011-3860Cross-site scripting (XSS) vulnerability in the Cover WP theme before 1.6.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.EXPLOITMEDIUM 4.3EPSS 3.51%28 September 2011
CVE-2011-3859Cross-site scripting (XSS) vulnerability in the Trending theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.EXPLOITMEDIUM 4.3EPSS 3.43%28 September 2011
CVE-2011-3858Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.EXPLOITMEDIUM 4.3EPSS 3.53%28 September 2011
CVE-2011-3856Cross-site scripting (XSS) vulnerability in the Elegant Grunge theme before 1.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.EXPLOITMEDIUM 4.3EPSS 3.53%28 September 2011
CVE-2011-3855Cross-site scripting (XSS) vulnerability in the F8 Lite theme before 4.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.EXPLOITMEDIUM 4.3EPSS 3.43%28 September 2011
CVE-2011-3852Cross-site scripting (XSS) vulnerability in the EvoLve theme before 1.2.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.EXPLOITMEDIUM 4.3EPSS 3.43%28 September 2011

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.