Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,516 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 177 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2011-1566 | Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to execute arbitrary programs via ..\ (dot dot backslash) sequences in opcodes (1) 0xa and (2) 0x17… | EXPLOIT ×2 ✓HIGH 10.0EPSS 67.0% | 5 April 2011 |
| CVE-2011-1565 | Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to (1) read (opcode 0x3) or (2) create or write (opcode 0x2) arbitrary files via ..\… | EXPLOITHIGH 10.0EPSS 64.1% | 5 April 2011 |
| CVE-2011-1564 | Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via crafted (1) On_FC_MISC_FCS_MSGBROADCAST and (2) On_FC_MISC_FCS_MSGSEND packets, which… | EXPLOITHIGH 10.0EPSS 18.6% | 5 April 2011 |
| CVE-2011-1563 | Multiple stack-based buffer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via (1) a long username in an On_FC_CONNECT_FCS_LOGIN packet, and crafted (2)… | EXPLOITHIGH 10.0EPSS 74.6% | 5 April 2011 |
| CVE-2011-1425 | xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform… | EXPLOIT ✓MEDIUM 5.1EPSS 8.06% | 4 April 2011 |
| CVE-2011-1083 | The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and… | EXPLOIT ✓MEDIUM 4.9EPSS 0.80% | 4 April 2011 |
| CVE-2011-1082 | fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack… | EXPLOIT ✓MEDIUM 4.9EPSS 0.78% | 4 April 2011 |
| CVE-2011-1557 | SQL injection vulnerability in ICloudCenter ICJobSite 1.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter to an unspecified component, a different vulnerability than CVE-2011-1546. | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 4 April 2011 |
| CVE-2011-1556 | SQL injection vulnerability in plugins/pdfClasses/pdfgen.php in Andy's PHP Knowledgebase (Aphpkb) 0.95.4 allows remote attackers to execute arbitrary SQL commands via the pdfa parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.08% | 4 April 2011 |
| CVE-2011-1546 | Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to execute arbitrary SQL commands via the s parameter to (1) a_viewusers.php or (2) keysearch.php; and allow remote authenticated… | EXPLOIT ✓HIGH 7.5EPSS 1.99% | 4 April 2011 |
| CVE-2010-3695 | Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via the fm_id parameter in a fetchmail_prefs_save… | EXPLOIT ✓MEDIUM 4.3EPSS 4.98% | 31 March 2011 |
| CVE-2011-1524 | Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to inject arbitrary web script or HTML via the username field, as demonstrated by injecting an IFRAME… | EXPLOITMEDIUM 4.3EPSS 4.21% | 28 March 2011 |
| CVE-2011-0545 | Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts, and possibly… | EXPLOITMEDIUM 6.8EPSS 2.94% | 28 March 2011 |
| CVE-2010-3275 | libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file, related to a "dangling pointer vulnerability." | EXPLOIT ✓HIGH 9.3EPSS 75.5% | 28 March 2011 |
| CVE-2011-1519 | The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute… | EXPLOIT ✓HIGH 10.0EPSS 9.20% | 25 March 2011 |
| CVE-2010-4776 | SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary SQL commands via the tid2 parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 23 March 2011 |
| CVE-2010-4774 | SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-4804 and CVE-2007-4171. | EXPLOITHIGH 7.5EPSS 0.93% | 23 March 2011 |
| CVE-2010-4772 | Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter to viewforum.php. | EXPLOITMEDIUM 4.3EPSS 1.46% | 23 March 2011 |
| CVE-2010-4771 | SQL injection vulnerability to viewforum.php in S-CMS 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOITHIGH 7.5EPSS 0.98% | 23 March 2011 |
| CVE-2010-4770 | SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action. | EXPLOITHIGH 7.5EPSS 1.04% | 23 March 2011 |
| CVE-2010-4769 | Directory traversal vulnerability in the Jimtawl (com_jimtawl) component 1.0.2 Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 7.59% | 23 March 2011 |
| CVE-2011-0182 | The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry. | EXPLOITHIGH 7.2EPSS 1.69% | 23 March 2011 |
| CVE-2011-0180 | Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call. | EXPLOIT ✓LOW 2.1EPSS 0.68% | 23 March 2011 |
| CVE-2010-4228 | Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary code or cause a denial of service (abend) via a long DELE command, a different vulnerability than… | EXPLOIT ✓HIGH 9.0EPSS 14.7% | 22 March 2011 |
| CVE-2011-1471 | Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls. | EXPLOIT ✓MEDIUM 4.3EPSS 13.2% | 20 March 2011 |
| CVE-2011-1470 | The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a ziparchive stream that is not properly handled by the stream_get_contents function. | EXPLOIT ✓MEDIUM 4.3EPSS 9.52% | 20 March 2011 |
| CVE-2011-1468 | Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of service (memory consumption) via (1) plaintext data to the openssl_encrypt function or (2) ciphertext data to the openssl_decrypt… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 13.3% | 20 March 2011 |
| CVE-2011-1467 | Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument, a related… | EXPLOIT ✓MEDIUM 5.0EPSS 12.7% | 20 March 2011 |
| CVE-2011-1081 | modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an empty value for the OldDN field. | EXPLOIT ✓MEDIUM 5.0EPSS 14.5% | 20 March 2011 |
| CVE-2011-0708 | exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) via an image with a crafted Image File Directory (IFD) that triggers a buffer… | EXPLOIT ✓MEDIUM 4.3EPSS 9.83% | 20 March 2011 |
| CVE-2011-0421 | The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer… | EXPLOITMEDIUM 4.3EPSS 13.5% | 20 March 2011 |
| CVE-2011-0751 | Directory traversal vulnerability in nhttpd (aka Nostromo webserver) before 1.9.4 allows remote attackers to execute arbitrary programs or read arbitrary files via a ..%2f (encoded dot dot slash) in a URI. | EXPLOIT ✓HIGH 7.5EPSS 3.66% | 16 March 2011 |
| CVE-2011-0745 | SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain duplicate check, which allows remote authenticated users to discover (1) the names of customers via a ShowDuplicates action to the… | EXPLOIT ✓MEDIUM 4.0EPSS 6.26% | 16 March 2011 |
| CVE-2011-1427 | Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 5.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Language parameter to Pages/login.aspx, (2) HeaderWarning parameter to… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.57% | 15 March 2011 |
| CVE-2011-1092 | Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function. | EXPLOIT ✓HIGH 7.5EPSS 17.9% | 15 March 2011 |
| CVE-2011-0609 | Adobe Flash Player Unspecified Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 66.8% | 15 March 2011 |
| CVE-2011-0063 | The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ./.../ sequence in the "extra" parameter to the help command, which causes… | EXPLOIT ✓MEDIUM 5.0EPSS 85.5% | 15 March 2011 |
| CVE-2011-0167 | The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site. | EXPLOIT ✓MEDIUM 4.3EPSS 3.34% | 11 March 2011 |
| CVE-2011-1137 | Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH message. | EXPLOITMEDIUM 5.0EPSS 28.1% | 11 March 2011 |
| CVE-2010-3609 | The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, allows remote attackers to cause a denial of… | EXPLOITMEDIUM 5.0EPSS 17.2% | 11 March 2011 |
| CVE-2011-1099 | Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attackers to (1) read arbitrary files via a .. | EXPLOITMEDIUM 5.8EPSS 3.17% | 9 March 2011 |
| CVE-2009-3028 | The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to… | EXPLOIT ✓MEDIUM 6.8EPSS 42.6% | 7 March 2011 |
| CVE-2011-1143 | epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file. | EXPLOIT ✓MEDIUM 4.3EPSS 8.59% | 3 March 2011 |
| CVE-2011-0762 | The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a… | EXPLOIT ✓MEDIUM 4.0EPSS 73.9% | 2 March 2011 |
| CVE-2011-1106 | Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script or HTML via the authReasonCode parameter in an OpenDatabase action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 1 March 2011 |
| CVE-2010-4752 | SQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter, a different vector than CVE-2008-6593, CVE-2010-3484, and… | EXPLOIT ✓MEDIUM 6.8EPSS 0.90% | 1 March 2011 |
| CVE-2010-4751 | SQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the id parameter in an edituser action, a different vector than CVE-2008-6593,… | EXPLOIT ✓MEDIUM 6.0EPSS 0.82% | 1 March 2011 |
| CVE-2010-4750 | Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allows remote attackers to hijack the authentication of administrators. | EXPLOITMEDIUM 6.8EPSS 1.02% | 1 March 2011 |
| CVE-2010-4749 | Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) body parameter to action.php and the (2) amount and (3) action parameters to… | EXPLOITMEDIUM 4.3EPSS 2.02% | 1 March 2011 |
| CVE-2010-4747 | Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pluginurl parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.51% | 1 March 2011 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.