SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,587 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 183 of 501

CVESummaryPriorityPublished
CVE-2010-4231Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.8EPSS 16.0%17 November 2010
CVE-2010-4230Stack-based buffer overflow in a certain ActiveX control for the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to execute arbitrary code via a long string in the first…EXPLOITHIGH 9.3EPSS 5.55%17 November 2010
CVE-2010-1840Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via…EXPLOITHIGH 7.5EPSS 8.95%15 November 2010
CVE-2010-2892gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request…EXPLOITHIGH 8.5EPSS 3.51%15 November 2010
CVE-2010-4236Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges via an ES_LIBRARY_PATH environment variable and a modified PATH environment variable, which is used during execution…EXPLOITMEDIUM 6.9EPSS 0.87%12 November 2010
CVE-2010-3899IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via a crafted series of documents.EXPLOITMEDIUM 5.0EPSS 3.15%12 November 2010
CVE-2010-3895esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.EXPLOITHIGH 7.2EPSS 0.77%12 November 2010
CVE-2010-3894Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface in IBM OmniFind Enterprise Edition before 8.5 FP6 allows remote attackers…EXPLOITHIGH 9.3EPSS 12.0%12 November 2010
CVE-2010-3893The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbitrary administrative actions by leveraging cookie…EXPLOITHIGH 7.5EPSS 2.35%12 November 2010
CVE-2010-3891Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijack the authentication of administrators for requests that add an…EXPLOITMEDIUM 6.8EPSS 1.14%12 November 2010
CVE-2010-3870The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection…EXPLOITMEDIUM 6.8EPSS 11.3%12 November 2010
CVE-2010-4156The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).EXPLOITMEDIUM 5.0EPSS 12.8%10 November 2010
CVE-2010-3333Microsoft Office Stack-based Buffer Overflow VulnerabilityKEVEXPLOIT ×4HIGH 7.8EPSS 89.5%10 November 2010
CVE-2010-4221Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.EXPLOIT ×3HIGH 10.0EPSS 91.3%9 November 2010
CVE-2010-3077Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.EXPLOITMEDIUM 4.3EPSS 3.89%9 November 2010
CVE-2010-3039/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in a request to the…EXPLOITMEDIUM 6.8EPSS 8.61%9 November 2010
CVE-2010-3709The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.EXPLOITMEDIUM 4.3EPSS 13.3%9 November 2010
CVE-2010-4091The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF…EXPLOITHIGH 9.3EPSS 18.5%7 November 2010
CVE-2010-3639Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown…EXPLOITHIGH 9.3EPSS 21.6%7 November 2010
CVE-2010-4186SQL injection vulnerability in process.asp in OnlineTechTools Online Work Order System (OWOS) Professional Edition 2.10 allows remote attackers to execute arbitrary SQL commands via the password parameter.EXPLOIT ×2HIGH 7.5EPSS 1.01%5 November 2010
CVE-2010-4185SQL injection vulnerability in index.php in Energine, possibly 2.3.8 and earlier, allows remote attackers to execute arbitrary SQL commands via the NRGNSID cookie.EXPLOITHIGH 7.5EPSS 0.97%5 November 2010
CVE-2010-3962Microsoft Internet Explorer Uninitialized Memory Corruption VulnerabilityKEVEXPLOIT ×3HIGH 8.1EPSS 96.8%5 November 2010
CVE-2010-3863Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the…EXPLOITMEDIUM 5.0EPSS 54.5%5 November 2010
CVE-2010-4181Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequences.EXPLOITMEDIUM 5.0EPSS 8.45%4 November 2010
CVE-2010-4152SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOITHIGH 7.5EPSS 0.97%3 November 2010
CVE-2010-4151SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than…EXPLOITMEDIUM 6.8EPSS 1.18%3 November 2010
CVE-2010-4006Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.EXPLOITHIGH 7.5EPSS 1.15%3 November 2010
CVE-2010-3977Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.EXPLOITMEDIUM 4.3EPSS 4.20%3 November 2010
CVE-2010-4142Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) SCPC_INITIALIZE, (2) SCPC_INITIALIZE_RF, or (3)…EXPLOIT ×5HIGH 10.0EPSS 63.0%2 November 2010
CVE-2010-4145Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for sevvo/eco23.mdb.EXPLOITMEDIUM 5.0EPSS 2.46%2 November 2010
CVE-2010-4144SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter.EXPLOITHIGH 7.5EPSS 1.00%2 November 2010
CVE-2010-4143SQL injection vulnerability in chart.php in phpCheckZ 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITMEDIUM 6.8EPSS 0.83%2 November 2010
CVE-2010-3654Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows…EXPLOIT ×2HIGH 9.3EPSS 69.7%29 October 2010
CVE-2010-4120Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web script or HTML via (1) the parm1 parameter to…EXPLOIT ×11MEDIUM 4.3EPSS 2.94%28 October 2010
CVE-2010-3765Mozilla Multiple Products Remote Code Execution VulnerabilityKEVEXPLOIT ×4CRITICAL 9.8EPSS 83.2%28 October 2010
CVE-2010-2891Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by .EXPLOITHIGH 7.5EPSS 14.0%28 October 2010
CVE-2010-4099ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the Request parameter to ess.EXPLOIT ×2MEDIUM 6.8EPSS 2.63%27 October 2010
CVE-2010-3227Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows…EXPLOITHIGH 9.3EPSS 20.8%26 October 2010
CVE-2010-4094The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role.EXPLOITMEDIUM 5.0EPSS 64.5%26 October 2010
CVE-2010-3653The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted rcsL chunk containing a field whose value…EXPLOIT ×2HIGH 9.3EPSS 74.6%26 October 2010
CVE-2010-3714The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote…EXPLOITHIGH 7.1EPSS 24.1%25 October 2010
CVE-2010-4057solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing many integer fields with two different values, which allows remote attackers to cause a denial of service…EXPLOITMEDIUM 5.0EPSS 7.17%23 October 2010
CVE-2010-4056solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing a single integer field, which allows remote attackers to cause a denial of service (NULL pointer…EXPLOITMEDIUM 5.0EPSS 8.43%23 October 2010
CVE-2010-4055Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denial of service (memory consumption and daemon crash) by connecting to TCP port 1315 and sending a packet with many integer fields,…EXPLOITMEDIUM 5.0EPSS 7.17%23 October 2010
CVE-2010-3179Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code or…EXPLOITHIGH 9.3EPSS 10.1%21 October 2010
CVE-2010-3573Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.EXPLOITMEDIUM 5.1EPSS 10.6%19 October 2010
CVE-2010-3563Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.EXPLOITHIGH 10.0EPSS 84.3%19 October 2010
CVE-2010-3552Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.EXPLOIT ×2HIGH 10.0EPSS 80.7%19 October 2010
CVE-2010-3749The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, which allows remote attackers to download an arbitrary program onto a client…EXPLOITHIGH 9.3EPSS 25.6%19 October 2010
CVE-2010-3747An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly initialize an unspecified object component during parsing of a CDDA URI, which allows remote attackers to…EXPLOITHIGH 9.3EPSS 34.8%19 October 2010

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.