Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,516 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 176 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2011-0065 | Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel. | EXPLOIT ×4 ✓HIGH 10.0EPSS 73.8% | 7 May 2011 |
| CVE-2011-0340 | Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client… | EXPLOIT ✓HIGH 9.3EPSS 32.3% | 4 May 2011 |
| CVE-2011-1613 | Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 6.0 before 6.0.200.0, 7.0 before 7.0.98.216, and 7.0.1xx before 7.0.112.0 allows remote attackers to cause a denial of service (device reload) via a sequence of ICMP packets, aka… | EXPLOITHIGH 7.8EPSS 10.4% | 3 May 2011 |
| CVE-2011-1609 | SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote authenticated users to execute arbitrary SQL commands… | EXPLOIT ✓HIGH 8.5EPSS 19.8% | 3 May 2011 |
| CVE-2009-5022 | Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file. | EXPLOIT ✓MEDIUM 6.8EPSS 10.8% | 3 May 2011 |
| CVE-2011-1591 | Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allows remote attackers to execute arbitrary code via a crafted .pcap file. | EXPLOIT ×4 ✓HIGH 9.3EPSS 41.7% | 29 April 2011 |
| CVE-2010-4801 | Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.0EPSS 2.00% | 27 April 2011 |
| CVE-2010-4800 | SQL injection vulnerability in doadd.php in BaconMap 1.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 27 April 2011 |
| CVE-2010-4799 | Multiple SQL injection vulnerabilities in Chipmunk Pwngame 1.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to authenticate.php and the (3) ID parameter to… | EXPLOIT ✓MEDIUM 6.8EPSS 1.08% | 27 April 2011 |
| CVE-2010-4798 | Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the uri parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.33% | 27 April 2011 |
| CVE-2010-4797 | Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 27 April 2011 |
| CVE-2010-4795 | SQL injection vulnerability in the JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ev_id parameter in a details action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 27 April 2011 |
| CVE-2010-4794 | Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in a… | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 27 April 2011 |
| CVE-2010-4793 | SQL injection vulnerability in detail.asp in Site2Nite Auto e-Manager allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 27 April 2011 |
| CVE-2010-4792 | Cross-site scripting (XSS) vulnerability in title.php in OPEN IT OverLook 5.0 allows remote attackers to inject arbitrary web script or HTML via the frame parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 27 April 2011 |
| CVE-2010-4791 | SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 27 April 2011 |
| CVE-2011-1206 | Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before… | EXPLOIT ✓HIGH 10.0EPSS 15.7% | 21 April 2011 |
| CVE-2011-0836 | Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote authenticated users to affect integrity, related to Web Runtime SEC. | EXPLOIT ×5 ✓LOW 3.5EPSS 3.40% | 20 April 2011 |
| CVE-2011-0807 | Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Server 9.1, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to… | EXPLOIT ✓HIGH 10.0EPSS 60.9% | 20 April 2011 |
| CVE-2011-1723 | Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to projects/hg-helloworld/news/. | EXPLOIT ✓MEDIUM 4.3EPSS 4.46% | 19 April 2011 |
| CVE-2011-1715 | Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to read arbitrary files via ..%2f… | EXPLOITMEDIUM 5.0EPSS 8.88% | 18 April 2011 |
| CVE-2011-1714 | Cross-site scripting (XSS) vulnerability in framework/source/resource/qx/test/jsonp_primitive.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to inject arbitrary web… | EXPLOITMEDIUM 4.3EPSS 2.61% | 18 April 2011 |
| CVE-2011-1496 | tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a filename to the -S command-line option. | EXPLOITMEDIUM 4.6EPSS 0.95% | 18 April 2011 |
| CVE-2011-1653 | Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands via vectors involving the (1) UnAssignFunctionalRoles, (2)… | EXPLOIT ✓HIGH 10.0EPSS 88.7% | 18 April 2011 |
| CVE-2011-0285 | The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service… | EXPLOIT ✓HIGH 10.0EPSS 20.8% | 15 April 2011 |
| CVE-2011-0105 | Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code… | EXPLOIT ✓HIGH 9.3EPSS 70.2% | 13 April 2011 |
| CVE-2011-0104 | Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel… | EXPLOIT ✓HIGH 9.3EPSS 53.4% | 13 April 2011 |
| CVE-2011-0041 | Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF… | EXPLOIT ✓HIGH 9.3EPSS 28.2% | 13 April 2011 |
| CVE-2011-1682 | Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. | EXPLOIT ✓MEDIUM 4.3EPSS 0.76% | 13 April 2011 |
| CVE-2011-0748 | Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) edit administrator accounts. | EXPLOIT ✓MEDIUM 6.8EPSS 1.47% | 13 April 2011 |
| CVE-2011-0611 | Adobe Flash Player Remote Code Execution Vulnerability | KEVEXPLOIT ×2 ✓HIGH 8.8EPSS 99.4% | 13 April 2011 |
| CVE-2011-1487 | The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow… | EXPLOIT ✓MEDIUM 5.0EPSS 10.6% | 11 April 2011 |
| CVE-2009-5065 | Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via vectors involving nested CDATA stanzas. | EXPLOIT ✓MEDIUM 4.3EPSS 4.53% | 11 April 2011 |
| CVE-2011-1671 | Cross-site scripting (XSS) vulnerability in app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and 2.0devel allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to todos/tag/. | EXPLOIT ✓MEDIUM 4.3EPSS 1.97% | 10 April 2011 |
| CVE-2011-1670 | Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the subject parameter to post_url/edit. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.74% | 10 April 2011 |
| CVE-2011-1669 | Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter. | EXPLOITMEDIUM 5.0EPSS 22.2% | 10 April 2011 |
| CVE-2011-1668 | Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the search parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.68% | 10 April 2011 |
| CVE-2011-1667 | SQL injection vulnerability in index.php in Anzeigenmarkt 2011 allows remote attackers to execute arbitrary SQL commands via the q parameter in a list action. | EXPLOIT ✓HIGH 7.5EPSS 1.36% | 10 April 2011 |
| CVE-2011-1665 | PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain backup SQL files via a direct request for predictable filenames in cache/backup/. | EXPLOITMEDIUM 5.0EPSS 2.54% | 10 April 2011 |
| CVE-2011-1071 | The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a… | EXPLOITMEDIUM 5.1EPSS 14.3% | 8 April 2011 |
| CVE-2011-0536 | Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain… | EXPLOIT ✓MEDIUM 6.9EPSS 0.79% | 8 April 2011 |
| CVE-2010-4784 | Multiple SQL injection vulnerabilities in member.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 1.12% | 7 April 2011 |
| CVE-2010-4783 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) siteurl and (2) urlbanner… | EXPLOIT ✓LOW 2.6EPSS 1.78% | 7 April 2011 |
| CVE-2010-4782 | Multiple SQL injection vulnerabilities in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) city, (2) state, (3) country, (4) minprice, (5) maxprice, (6) bed,… | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.03% | 7 April 2011 |
| CVE-2010-4781 | index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation path in an error message. | EXPLOIT ✓MEDIUM 5.0EPSS 3.02% | 7 April 2011 |
| CVE-2010-4780 | SQL injection vulnerability in the check_banlist function in includes/sessions.php in Enano CMS 1.1.7pl1; 1.0.6pl2; and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2 allows remote attackers to execute arbitrary SQL commands via the email… | EXPLOIT ✓HIGH 7.5EPSS 1.59% | 7 April 2011 |
| CVE-2011-1525 | Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted frame in an Internet Video Recording… | EXPLOITHIGH 9.3EPSS 11.9% | 6 April 2011 |
| CVE-2011-1569 | download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web root via (1) a trailing ".", (2) a trailing space, or (3) mixed case in the FileNameAttach parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 3.52% | 5 April 2011 |
| CVE-2011-1568 | Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to cause a denial of service and… | EXPLOITHIGH 10.0EPSS 19.4% | 5 April 2011 |
| CVE-2011-1567 | Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted… | EXPLOIT ×3 ✓HIGH 10.0EPSS 69.6% | 5 April 2011 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.