Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,516 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 173 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2011-3850 | Cross-site scripting (XSS) vulnerability in the Atahualpa theme before 3.6.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 4.25% | 28 September 2011 |
| CVE-2011-3645 | Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which leads to arbitrary permission changes; or (2) a modified UserIndex parameter to… | EXPLOITHIGH 7.5EPSS 2.62% | 27 September 2011 |
| CVE-2010-4852 | Cross-site scripting (XSS) vulnerability in login.php in Eclime 1.1.2b allows remote attackers to inject arbitrary web script or HTML via the reason parameter in a fail action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 27 September 2011 |
| CVE-2010-4851 | Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the (1) ref or (2) poll_id parameter to index.php, or the (3) country parameter to create_account.php. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 27 September 2011 |
| CVE-2010-4850 | Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03 allow remote attackers to inject arbitrary web script or HTML via the (1) post_content parameter to post/edit/2/p1.html, related to views/post.php; the (2) slogan parameter to… | EXPLOITMEDIUM 4.3EPSS 1.77% | 27 September 2011 |
| CVE-2010-4849 | SQL injection vulnerability in countrydetails.php in Alibaba Clone B2B 3.4 allows remote attackers to execute arbitrary SQL commands via the es_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 27 September 2011 |
| CVE-2010-4847 | SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 27 September 2011 |
| CVE-2010-4846 | SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 27 September 2011 |
| CVE-2010-4845 | Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 27 September 2011 |
| CVE-2010-4844 | SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary SQL commands via the kat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 27 September 2011 |
| CVE-2010-4843 | SQL injection vulnerability in website-page.php in PHP Web Scripts Ad Manager Pro 3.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter. | EXPLOITHIGH 7.5EPSS 1.02% | 27 September 2011 |
| CVE-2010-4842 | SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote attackers to execute arbitrary SQL commands via the Name parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.98% | 27 September 2011 |
| CVE-2011-3713 | cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/session_check.php and certain other files. | EXPLOITMEDIUM 5.0EPSS 6.93% | 23 September 2011 |
| CVE-2011-2544 | Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a crafted Call ID, as demonstrated by resultant… | EXPLOITLOW 3.5EPSS 4.68% | 23 September 2011 |
| CVE-2011-2543 | Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a denial of service (endpoint reboot or process crash) or possibly execute arbitrary code via a long… | EXPLOITHIGH 9.0EPSS 11.5% | 23 September 2011 |
| CVE-2011-2938 | Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT before 1.2.7 allow remote attackers to inject arbitrary web script or HTML via a parameter, as demonstrated by the project_id parameter to search.php. | EXPLOIT ✓MEDIUM 4.3EPSS 4.53% | 21 September 2011 |
| CVE-2011-3483 | Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed capture file that leads to an invalid root tvbuff, related to a "buffer exception handling vulnerability." | EXPLOIT ✓MEDIUM 4.3EPSS 5.57% | 20 September 2011 |
| CVE-2011-3360 | Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain privileges via a Trojan horse Lua script in an unspecified directory. | EXPLOIT ✓HIGH 9.3EPSS 34.9% | 20 September 2011 |
| CVE-2011-3575 | Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino 8.5.2 allows remote authenticated users to execute arbitrary code via a long tHPRAgentName parameter in an fmHttpPostRequest OpenForm action to… | EXPLOIT ✓HIGH 9.0EPSS 10.5% | 19 September 2011 |
| CVE-2011-2841 | Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document. | EXPLOIT ✓MEDIUM 6.8EPSS 3.69% | 19 September 2011 |
| CVE-2011-3502 | The web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to obtain the source code of executable files via a request with a trailing (1) space or (2) %2e (encoded dot). | EXPLOITMEDIUM 5.0EPSS 5.74% | 16 September 2011 |
| CVE-2011-3501 | Integer overflow in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to cause a denial of service (crash) via a negative or large Content-Length value. | EXPLOITMEDIUM 5.0EPSS 2.94% | 16 September 2011 |
| CVE-2011-3499 | Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an EIDP packet with a large size field, which writes a zero byte to an arbitrary… | EXPLOITHIGH 10.0EPSS 15.2% | 16 September 2011 |
| CVE-2011-3498 | Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long request. | EXPLOITHIGH 10.0EPSS 9.78% | 16 September 2011 |
| CVE-2011-3497 | service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method. | EXPLOITHIGH 10.0EPSS 57.1% | 16 September 2011 |
| CVE-2011-3496 | service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2) OF, or (3) EF command. | EXPLOIT ×2 ✓HIGH 10.0EPSS 14.4% | 16 September 2011 |
| CVE-2011-3495 | Multiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or delete arbitrary files via the (1) RF, (2) wF, (3) UF, or (4) NF command. | EXPLOITHIGH 10.0EPSS 10.3% | 16 September 2011 |
| CVE-2011-3494 | WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long StyleTemplate element in a QUO, SUM or POR file, which triggers a stack-based buffer overflow, or… | EXPLOIT ×2 ✓HIGH 10.0EPSS 55.8% | 16 September 2011 |
| CVE-2011-3493 | Multiple stack-based buffer overflows in the DH_OneSecondTick function in Cogent DataHub 7.1.1.63 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) domain, (2) report_domain, (3)… | EXPLOIT ×2 ✓HIGH 10.0EPSS 7.99% | 16 September 2011 |
| CVE-2011-3492 | Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted NETB packet to UDP port 20034. | EXPLOIT ×2 ✓HIGH 10.0EPSS 70.9% | 16 September 2011 |
| CVE-2011-3491 | Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative Content-Length field. | EXPLOITHIGH 10.0EPSS 16.2% | 16 September 2011 |
| CVE-2011-3490 | Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long command to port 11234, as demonstrated with the TF… | EXPLOIT ×2 ✓HIGH 10.0EPSS 36.4% | 16 September 2011 |
| CVE-2011-3489 | RnaUtility.dll in RsvcHost.exe 2.30.0.23 in Rockwell RSLogix 19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted rna packet with a long string to TCP port 4446 that triggers (1) "a memset zero overflow" or (2) an… | EXPLOITMEDIUM 5.0EPSS 8.75% | 16 September 2011 |
| CVE-2011-3488 | Use-after-free vulnerability in Equis MetaStock 11 and earlier allows remote attackers to execute arbitrary code via a malformed (1) mwc chart, (2) mws chart, (3) mwt template, or (4) mwl layout. | EXPLOITHIGH 10.0EPSS 4.50% | 16 September 2011 |
| CVE-2011-3487 | Directory traversal vulnerability in CarelDataServer.exe in Carel PlantVisor 2.4.4 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ×2MEDIUM 5.0EPSS 7.43% | 16 September 2011 |
| CVE-2011-3486 | Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers an out-of-bounds read. | EXPLOIT ✓MEDIUM 5.0EPSS 49.6% | 16 September 2011 |
| CVE-2011-3322 | Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password to the Telnet (TCP/23)… | EXPLOIT ✓HIGH 10.0EPSS 64.7% | 15 September 2011 |
| CVE-2011-3394 | SQL injection vulnerability in findagent.php in MYRE Real Estate Software allows remote attackers to execute arbitrary SQL commands via the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.80% | 15 September 2011 |
| CVE-2011-3393 | Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers to inject arbitrary web script or HTML via the (1) country1, (2) state1, or (3) city1 parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.34% | 15 September 2011 |
| CVE-2011-1984 | WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability." | EXPLOIT ✓HIGH 7.2EPSS 7.46% | 15 September 2011 |
| CVE-2011-1892 | Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management… | EXPLOITMEDIUM 4.0EPSS 37.5% | 15 September 2011 |
| CVE-2011-2595 | Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code via a long id parameter in a (1) String or (2) Int tag in a FotoSlate Project (aka PLP) file. | EXPLOIT ✓HIGH 10.0EPSS 59.7% | 14 September 2011 |
| CVE-2011-2201 | The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input. | EXPLOIT ✓MEDIUM 4.3EPSS 6.90% | 14 September 2011 |
| CVE-2010-4839 | SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.70% | 14 September 2011 |
| CVE-2010-4838 | SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users, with Public Back-end permissions, to execute arbitrary SQL commands via the alpha parameter in a (1) listTickets or (2) listFaqs… | EXPLOIT ✓MEDIUM 6.0EPSS 0.84% | 14 September 2011 |
| CVE-2010-4837 | Cross-site scripting (XSS) vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the subject parameter (title field) in a saveTicket action to index2.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.53% | 14 September 2011 |
| CVE-2010-4836 | Cross-site scripting (XSS) vulnerability in register.html in PHPShop 2.1 EE and earlier allows remote attackers to inject arbitrary web script or HTML via the name_new parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.79% | 14 September 2011 |
| CVE-2010-4835 | Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action. | EXPLOIT ✓MEDIUM 4.0EPSS 2.34% | 14 September 2011 |
| CVE-2010-4834 | Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types… | EXPLOIT ✓MEDIUM 6.5EPSS 0.90% | 14 September 2011 |
| CVE-2009-5098 | The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of service (crash) via a web page containing a long string following a refresh tag, which triggers a… | EXPLOIT ✓MEDIUM 5.4EPSS 3.94% | 13 September 2011 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.