Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,516 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 174 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-5095 | PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_ordner parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.86% | 12 September 2011 |
| CVE-2009-5094 | SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL commands via the item parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.04% | 12 September 2011 |
| CVE-2009-5093 | Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.81% | 12 September 2011 |
| CVE-2009-5091 | SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 12 September 2011 |
| CVE-2009-5090 | SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter and possibly other unspecified vectors. | EXPLOIT ✓MEDIUM 6.8EPSS 1.97% | 12 September 2011 |
| CVE-2009-5089 | Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 2.24% | 12 September 2011 |
| CVE-2009-5088 | SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL commands via the cID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.98% | 12 September 2011 |
| CVE-2009-5087 | Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.50% | 12 September 2011 |
| CVE-2011-3390 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in IBM OpenAdmin Tool (OAT) before 2.72 for Informix allow remote attackers to inject arbitrary web script or HTML via the (1) informixserver, (2) host, or (3) port parameter in a login… | EXPLOIT ✓MEDIUM 4.3EPSS 3.64% | 6 September 2011 |
| CVE-2011-2763 | The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a modified request to the LSRoom_Remoting.doCommand function in gateway.php. | EXPLOIT ✓HIGH 7.5EPSS 36.1% | 2 September 2011 |
| CVE-2011-1944 | Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that… | EXPLOIT ✓HIGH 9.3EPSS 13.4% | 2 September 2011 |
| CVE-2011-2577 | Unspecified vulnerability in Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs, when using software versions before TC 4.0.0 or F9.1, allows remote attackers to cause a denial of service (crash) via a crafted SIP… | EXPLOITHIGH 7.8EPSS 12.7% | 31 August 2011 |
| CVE-2011-3187 | The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text… | EXPLOIT ✓MEDIUM 4.3EPSS 6.67% | 29 August 2011 |
| CVE-2011-3192 | The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as… | EXPLOIT ×2HIGH 7.8EPSS 98.8% | 29 August 2011 |
| CVE-2011-3182 | PHP before 5.3.7 does not properly check the return values of the malloc, calloc, and realloc library functions, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger a buffer… | EXPLOIT ✓MEDIUM 5.0EPSS 19.2% | 25 August 2011 |
| CVE-2010-4830 | SQL injection vulnerability in Resumes/TD_RESUME_Indlist.asp in Techno Dreams (T-Dreams) Job Career Package 3.0 allows remote attackers to execute arbitrary SQL commands via the z_Residency parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 24 August 2011 |
| CVE-2010-4829 | SQL injection vulnerability in processview.asp in Techno Dreams (T-Dreams) Cars Ads Package 2.0 allows remote attackers to execute arbitrary SQL commands via the key parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 24 August 2011 |
| CVE-2011-2950 | Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted QCP file. | EXPLOIT ✓HIGH 9.3EPSS 28.6% | 18 August 2011 |
| CVE-2011-3142 | Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute arbitrary code via a long second argument to the ValidateUser method. | EXPLOIT ✓HIGH 10.0EPSS 38.4% | 16 August 2011 |
| CVE-2011-0257 | Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcode in a PICT file that triggers a stack-based buffer overflow. | EXPLOIT ✓HIGH 9.3EPSS 60.1% | 15 August 2011 |
| CVE-2011-3011 | BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors. | EXPLOIT ✓MEDIUM 5.0EPSS 71.6% | 15 August 2011 |
| CVE-2011-2357 | Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs… | EXPLOIT ✓MEDIUM 4.3EPSS 4.61% | 12 August 2011 |
| CVE-2011-2404 | A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability… | EXPLOIT ✓HIGH 7.5EPSS 73.7% | 11 August 2011 |
| CVE-2011-2132 | Adobe Flash Media Server (FMS) before 3.5.7, and 4.x before 4.0.3, allows attackers to cause a denial of service (memory corruption) via unspecified vectors. | EXPLOIT ✓MEDIUM 5.0EPSS 8.47% | 11 August 2011 |
| CVE-2011-2131 | Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GIF file. | EXPLOIT ✓HIGH 9.3EPSS 22.2% | 11 August 2011 |
| CVE-2011-2140 | Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code or cause a… | EXPLOIT ×2 ✓HIGH 10.0EPSS 82.3% | 10 August 2011 |
| CVE-2011-1976 | Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer… | EXPLOIT ✓MEDIUM 4.3EPSS 20.8% | 10 August 2011 |
| CVE-2011-1974 | NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka… | EXPLOITHIGH 7.2EPSS 6.98% | 10 August 2011 |
| CVE-2011-1965 | Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka… | EXPLOITHIGH 7.1EPSS 24.9% | 10 August 2011 |
| CVE-2011-2900 | Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows… | EXPLOIT ×2HIGH 7.5EPSS 13.3% | 5 August 2011 |
| CVE-2011-2975 | Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data. | EXPLOIT ✓MEDIUM 6.8EPSS 4.60% | 1 August 2011 |
| CVE-2011-2403 | SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | EXPLOIT ✓MEDIUM 6.5EPSS 1.97% | 1 August 2011 |
| CVE-2011-2522 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start… | EXPLOIT ✓MEDIUM 6.8EPSS 10.0% | 29 July 2011 |
| CVE-2011-2963 | TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service… | EXPLOIT ✓HIGH 10.0EPSS 7.63% | 29 July 2011 |
| CVE-2011-2960 | Heap-based buffer overflow in httpsvr.exe 6.0.5.3 in Sunway ForceControl 6.1 SP1, SP2, and SP3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted URL. | EXPLOIT ✓HIGH 10.0EPSS 17.6% | 29 July 2011 |
| CVE-2011-2956 | AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of service (system reboot or shutdown) via a signal. | EXPLOIT ✓HIGH 7.8EPSS 6.74% | 28 July 2011 |
| CVE-2011-2745 | upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute… | EXPLOIT ✓MEDIUM 6.5EPSS 2.03% | 27 July 2011 |
| CVE-2011-2882 | Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows remote attackers to execute arbitrary code via crafted… | EXPLOIT ✓HIGH 9.3EPSS 56.4% | 21 July 2011 |
| CVE-2011-1774 | WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted web site. | EXPLOIT ✓HIGH 8.8EPSS 43.2% | 21 July 2011 |
| CVE-2011-0222 | WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in… | EXPLOIT ×2HIGH 9.3EPSS 21.6% | 21 July 2011 |
| CVE-2011-2260 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Administration. | EXPLOITMEDIUM 5.8EPSS 3.29% | 20 July 2011 |
| CVE-2011-1511 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 and 3.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to Administration. | EXPLOIT ✓MEDIUM 6.4EPSS 14.6% | 20 July 2011 |
| CVE-2011-2780 | Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 13.0% | 19 July 2011 |
| CVE-2011-2743 | Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the action parameter to (1) the default URI or (2) includes/javascript.php, or the (3) title or (4) body… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.33% | 19 July 2011 |
| CVE-2011-2744 | Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action parameter to the default URI. | EXPLOIT ✓MEDIUM 6.8EPSS 8.96% | 19 July 2011 |
| CVE-2010-3271 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of… | EXPLOIT ✓MEDIUM 6.8EPSS 2.10% | 18 July 2011 |
| CVE-2011-2757 | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ×3 ✓MEDIUM 5.0EPSS 39.4% | 17 July 2011 |
| CVE-2011-2755 | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary files via unspecified vectors. | EXPLOIT ×3 ✓MEDIUM 5.0EPSS 30.9% | 17 July 2011 |
| CVE-2011-2751 | SQL injection vulnerability in Parodia before 6.809 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 17 July 2011 |
| CVE-2011-2506 | setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging… | EXPLOIT ×2 ✓HIGH 7.5EPSS 9.63% | 14 July 2011 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.