Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,541 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 181 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-3849 | The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL… | EXPLOIT ✓MEDIUM 4.7EPSS 0.71% | 30 December 2010 |
| CVE-2010-3848 | Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to gain privileges by providing a large number of iovec structures. | EXPLOIT ✓MEDIUM 6.9EPSS 0.70% | 30 December 2010 |
| CVE-2010-4619 | SQL injection vulnerability in profil.php in Mafya Oyun Scrpti (aka Mafia Game Script) allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.00% | 29 December 2010 |
| CVE-2010-4617 | Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 8.53% | 29 December 2010 |
| CVE-2010-4615 | Multiple SQL injection vulnerabilities in Oto Galeri Sistemi 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) arac parameter to carsdetail.asp and the (2) marka parameter to twohandscars.asp. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 29 December 2010 |
| CVE-2010-4614 | SQL injection vulnerability in item.php in Ero Auktion 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-0723. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 29 December 2010 |
| CVE-2010-4613 | Multiple directory traversal vulnerabilities in Hycus CMS 1.0.3 allow remote attackers to include and execute arbitrary local files via a .. | EXPLOITHIGH 7.5EPSS 6.05% | 29 December 2010 |
| CVE-2010-4612 | Multiple SQL injection vulnerabilities in index.php in Hycus CMS 1.0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) usr_email parameters to user/1/hregister.html, (3)… | EXPLOITMEDIUM 6.8EPSS 1.70% | 29 December 2010 |
| CVE-2010-4611 | Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_files and (3) extensions/login/frontend/pages/antihacker.php, which reveals the installation path in an… | EXPLOITMEDIUM 5.0EPSS 2.49% | 29 December 2010 |
| CVE-2010-4610 | Cross-site scripting (XSS) vulnerability in index.php in Html-edit CMS 3.1.8 allows remote attackers to inject arbitrary web script or HTML via the error parameter. | EXPLOITMEDIUM 4.3EPSS 1.48% | 29 December 2010 |
| CVE-2010-4609 | SQL injection vulnerability in index.php in Html-edit CMS 3.1.8 allows remote attackers to execute arbitrary SQL commands via the nuser parameter in a registrate action. | EXPLOITHIGH 7.5EPSS 0.99% | 29 December 2010 |
| CVE-2010-4608 | Habari 0.6.5 allows remote attackers to obtain sensitive information via a direct request to (1) header.php and (2) comments_items.php in system/admin/, which reveals the installation path in an error message. | EXPLOITMEDIUM 5.0EPSS 2.49% | 29 December 2010 |
| CVE-2010-4607 | Multiple cross-site scripting (XSS) vulnerabilities in Habari 0.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) additem_form parameter to system/admin/dash_additem.php and the (2)… | EXPLOITLOW 2.6EPSS 1.58% | 29 December 2010 |
| CVE-2010-4604 | Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and… | EXPLOIT ✓HIGH 7.2EPSS 0.94% | 29 December 2010 |
| CVE-2010-4598 | Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 26.5% | 23 December 2010 |
| CVE-2010-4597 | Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Interface (HMI) before 3.5.3900.10 allows remote attackers to execute arbitrary code via a long string in the second… | EXPLOIT ✓HIGH 10.0EPSS 18.8% | 23 December 2010 |
| CVE-2010-4588 | The WBEMSingleView.ocx ActiveX control 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier allows remote attackers to execute arbitrary code via a crafted argument to the ReleaseContext method, a different vector than CVE-2010-3973,… | EXPLOIT ✓HIGH 9.3EPSS 32.8% | 23 December 2010 |
| CVE-2010-3973 | The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef… | EXPLOIT ×2 ✓HIGH 9.3EPSS 71.7% | 23 December 2010 |
| CVE-2010-3972 | Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a denial… | EXPLOIT ✓HIGH 10.0EPSS 94.5% | 23 December 2010 |
| CVE-2010-4347 | The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_init… | EXPLOIT ✓MEDIUM 6.9EPSS 2.20% | 22 December 2010 |
| CVE-2010-4111 | Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOIT ✓MEDIUM 4.3EPSS 1.80% | 22 December 2010 |
| CVE-2010-3971 | Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or… | EXPLOIT ×3 ✓HIGH 9.3EPSS 81.7% | 22 December 2010 |
| CVE-2010-3970 | Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and… | EXPLOIT ✓HIGH 9.3EPSS 67.7% | 22 December 2010 |
| CVE-2010-4333 | Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies. | EXPLOITHIGH 7.5EPSS 7.12% | 22 December 2010 |
| CVE-2010-4332 | Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies. | EXPLOITHIGH 7.5EPSS 6.95% | 22 December 2010 |
| CVE-2010-4275 | Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) name or (2) descr parameter in an (a) update_usergroup or a (b) store_nas action to… | EXPLOIT ×2 ✓LOW 3.5EPSS 1.27% | 22 December 2010 |
| CVE-2010-2590 | Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP3 Fix Pack 3.2 allows remote attackers to execute arbitrary code via a long ServerResourceVersion… | EXPLOIT ×2 ✓HIGH 9.3EPSS 46.8% | 22 December 2010 |
| CVE-2010-4557 | Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series Batch 8.1 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary… | EXPLOITHIGH 10.0EPSS 12.1% | 17 December 2010 |
| CVE-2010-3906 | Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 5.61% | 17 December 2010 |
| CVE-2010-3967 | Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Movie Maker (MSWMM) file, aka… | EXPLOITHIGH 9.3EPSS 20.5% | 16 December 2010 |
| CVE-2010-3964 | Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a… | EXPLOIT ✓HIGH 7.5EPSS 94.2% | 16 December 2010 |
| CVE-2010-3944 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability." | EXPLOIT ✓HIGH 7.2EPSS 3.76% | 16 December 2010 |
| CVE-2010-3338 | The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the security context of scheduled tasks, which allows local users to gain privileges via a crafted… | EXPLOIT ×2 ✓HIGH 7.2EPSS 21.7% | 16 December 2010 |
| CVE-2010-4345 | Exim Privilege Escalation Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 18.0% | 14 December 2010 |
| CVE-2010-4344 | Exim Heap-Based Buffer Overflow Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 71.7% | 14 December 2010 |
| CVE-2010-3770 | Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary web script or HTML via (1) x-mac-arabic, (2)… | EXPLOIT ✓MEDIUM 4.3EPSS 4.45% | 10 December 2010 |
| CVE-2010-4518 | Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the v1 parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.52% | 9 December 2010 |
| CVE-2010-4517 | SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the char parameter in an item action to index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 0.95% | 9 December 2010 |
| CVE-2010-4514 | Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.53% | 9 December 2010 |
| CVE-2010-4513 | Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter in a load action to zimplit.php and (2) client parameter to… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.81% | 9 December 2010 |
| CVE-2010-4503 | SQL injection vulnerability in indexlight.php in Aigaion 1.3.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in an export action. | EXPLOIT ✓HIGH 7.5EPSS 0.98% | 8 December 2010 |
| CVE-2010-4502 | Integer overflow in KmxSbx.sys 6.2.0.22 in CA Internet Security Suite Plus 2010 allows local users to cause a denial of service (pool corruption) and execute arbitrary code via crafted arguments to the 0x88000080 IOCTL, which triggers a buffer overflow. | EXPLOITHIGH 7.2EPSS 1.16% | 8 December 2010 |
| CVE-2010-4480 | error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]". | EXPLOIT ✓MEDIUM 4.3EPSS 5.83% | 8 December 2010 |
| CVE-2010-4170 | The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBE_OPTIONS environment variable to specify a malicious configuration file. | EXPLOIT ×2 ✓HIGH 7.2EPSS 5.35% | 7 December 2010 |
| CVE-2010-4412 | Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in an olsrd.xml action to pkg_edit.php, (2) the xml parameter to pkg.php, or the if parameter… | EXPLOIT ×4 ✓MEDIUM 4.3EPSS 1.52% | 7 December 2010 |
| CVE-2010-4330 | Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOITMEDIUM 6.8EPSS 2.63% | 7 December 2010 |
| CVE-2010-4259 | Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long CHARSET_REGISTRY header in a BDF font file. | EXPLOITMEDIUM 6.8EPSS 10.9% | 7 December 2010 |
| CVE-2010-4246 | Multiple cross-site scripting (XSS) vulnerabilities in graph.php in pfSense 1.2.3 and 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via the (1) ifnum or (2) ifname parameter, a different vulnerability than CVE-2008-1182. | EXPLOIT ✓MEDIUM 4.3EPSS 1.54% | 7 December 2010 |
| CVE-2010-4297 | The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1.x before 3.1.2 build 301548; VMware Server 2.0.2; VMware Fusion 2.x… | EXPLOITHIGH 7.2EPSS 5.17% | 6 December 2010 |
| CVE-2010-4409 | Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument. | EXPLOITMEDIUM 5.0EPSS 18.9% | 6 December 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.