Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,587 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 184 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-3841 | Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the rev parameter to the view script or (2) the query string to the login script. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.05% | 18 October 2010 |
| CVE-2010-0219 | Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by… | EXPLOIT ×3 ✓HIGH 10.0EPSS 90.9% | 18 October 2010 |
| CVE-2010-3585 | Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. | EXPLOIT ✓HIGH 9.0EPSS 52.1% | 14 October 2010 |
| CVE-2010-3581 | Unspecified vulnerability in the BPEL Console component in Oracle Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0 allows remote authenticated users to affect integrity via unknown vectors. | EXPLOIT ✓LOW 3.5EPSS 1.76% | 14 October 2010 |
| CVE-2010-3514 | Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 6.1 and 7.0 allows remote attackers to affect integrity via unknown vectors related to Web Container. | EXPLOITMEDIUM 4.3EPSS 4.49% | 14 October 2010 |
| CVE-2010-3503 | Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect confidentiality and integrity via unknown vectors related to su. | EXPLOIT ✓MEDIUM 6.3EPSS 0.79% | 14 October 2010 |
| CVE-2010-3329 | mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Microsoft Office document that causes the HtmlDlgHelper class destructor to access uninitialized memory, aka "Uninitialized Memory… | EXPLOIT ✓HIGH 9.3EPSS 28.4% | 13 October 2010 |
| CVE-2010-3325 | Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allows remote attackers to obtain sensitive information from a different (1) domain or (2) zone via a… | EXPLOIT ✓MEDIUM 4.3EPSS 22.0% | 13 October 2010 |
| CVE-2010-2746 | Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is… | EXPLOIT ✓HIGH 7.6EPSS 35.7% | 13 October 2010 |
| CVE-2010-2745 | Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which allows user-assisted remote attackers to execute arbitrary code via crafted media content referenced in an HTML document, aka… | EXPLOIT ✓HIGH 9.3EPSS 23.8% | 13 October 2010 |
| CVE-2010-2744 | The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by… | EXPLOIT ✓HIGH 7.2EPSS 4.19% | 13 October 2010 |
| CVE-2010-3888 | Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers. | EXPLOIT ×2 ✓HIGH 7.2EPSS 3.93% | 8 October 2010 |
| CVE-2010-3886 | The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain… | EXPLOIT ✓MEDIUM 4.3EPSS 16.5% | 8 October 2010 |
| CVE-2010-3885 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 8 October 2010 |
| CVE-2010-3884 | Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that reset the administrative password. | EXPLOITMEDIUM 6.8EPSS 0.83% | 8 October 2010 |
| CVE-2010-3631 | Array index error in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ✓HIGH 9.3EPSS 11.7% | 6 October 2010 |
| CVE-2010-3742 | Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) meta or (2) phpincdir parameter, a different issue than CVE-2010-3307. | EXPLOIT ✓HIGH 7.5EPSS 2.53% | 5 October 2010 |
| CVE-2010-3307 | Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) body, (2) footer, (3) header, (4) menu_left, or (5) menu_right… | EXPLOIT ✓HIGH 7.5EPSS 2.52% | 5 October 2010 |
| CVE-2010-3437 | Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer… | EXPLOIT ✓MEDIUM 6.6EPSS 2.40% | 4 October 2010 |
| CVE-2010-2943 | The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned… | EXPLOIT ✓HIGH 8.1EPSS 17.0% | 30 September 2010 |
| CVE-2010-3468 | Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 6.72% | 29 September 2010 |
| CVE-2010-3490 | Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.5EPSS 9.39% | 28 September 2010 |
| CVE-2010-3070 | Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in MantisBT and other products, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to an arbitrary PHP script that uses NuSOAP classes. | EXPLOIT ✓MEDIUM 4.3EPSS 6.16% | 28 September 2010 |
| CVE-2010-3608 | Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) password (pw) parameters to (a) admin.php or (b) user.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 September 2010 |
| CVE-2010-3603 | Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to hijack the authentication of administrators for requests that rename arbitrary files, as… | EXPLOIT ✓MEDIUM 6.8EPSS 2.46% | 24 September 2010 |
| CVE-2010-3602 | Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to inject arbitrary web script or HTML via the User ID parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.77% | 24 September 2010 |
| CVE-2010-3601 | SQL injection vulnerability in index.php in ibPhotohost 1.1.2 allows remote attackers to execute arbitrary SQL commands via the img parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 September 2010 |
| CVE-2010-3081 | The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to… | EXPLOIT ✓HIGH 7.8EPSS 3.53% | 24 September 2010 |
| CVE-2010-3306 | Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI. | EXPLOIT ✓MEDIUM 5.0EPSS 8.56% | 24 September 2010 |
| CVE-2010-3489 | Cross-site scripting (XSS) vulnerability in netautor/napro4/home/login2.php in CMS Digital Workroom (formerly Netautor Professional) 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the goback parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.66% | 22 September 2010 |
| CVE-2010-3486 | Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash), (2) %5C (encoded backslash), or (3) %255c (double-encoded backslash) in the name parameter. | EXPLOIT ×3 ✓MEDIUM 5.0EPSS 3.07% | 22 September 2010 |
| CVE-2010-3485 | SQL injection vulnerability in common.php in LightNEasy 3.2.1 allows remote attackers to execute arbitrary SQL commands via the userhandle cookie to LightNEasy.php, a different vector than CVE-2008-6593. | EXPLOIT ✓HIGH 7.5EPSS 1.27% | 22 September 2010 |
| CVE-2010-3484 | SQL injection vulnerability in common.php in LightNEasy 3.2.1 allows remote attackers to execute arbitrary SQL commands via the handle parameter to LightNEasy.php, a different vector than CVE-2008-6593. | EXPLOIT ✓HIGH 7.5EPSS 1.31% | 22 September 2010 |
| CVE-2010-3483 | cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request. | EXPLOITHIGH 7.5EPSS 2.30% | 22 September 2010 |
| CVE-2010-3482 | Multiple SQL injection vulnerabilities in cms_write.php in Primitive CMS 1.0.9 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) title and (2) menutitle parameters. | EXPLOITMEDIUM 6.5EPSS 0.90% | 22 September 2010 |
| CVE-2010-3481 | Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to… | EXPLOIT ✓MEDIUM 6.8EPSS 1.12% | 22 September 2010 |
| CVE-2010-3480 | Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.37% | 22 September 2010 |
| CVE-2010-3479 | SQL injection vulnerability in list.php in BoutikOne 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 22 September 2010 |
| CVE-2009-5003 | SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbitrary SQL commands via the targetid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 22 September 2010 |
| CVE-2010-3332 | Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and… | EXPLOIT ×3 ✓MEDIUM 6.4EPSS 68.2% | 22 September 2010 |
| CVE-2010-3314 | Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web… | EXPLOIT ✓MEDIUM 4.3EPSS 3.33% | 22 September 2010 |
| CVE-2010-3313 | phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows… | EXPLOIT ✓HIGH 7.5EPSS 8.50% | 22 September 2010 |
| CVE-2010-3301 | The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to… | EXPLOIT ✓HIGH 7.2EPSS 3.82% | 22 September 2010 |
| CVE-2010-3467 | SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial module is enabled, allows remote attackers to execute arbitrary SQL commands via the secid parameter in a listarticles action. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 17 September 2010 |
| CVE-2010-3462 | Cross-site scripting (XSS) vulnerability in backend/plugin/Registration/index.php in Mollify 1.6, 1.6.5.5, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the confirm parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.97% | 17 September 2010 |
| CVE-2010-3461 | SQL injection vulnerability in the Publisher module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printarticle action to mod.php, a different vector than CVE-2007-3394. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 17 September 2010 |
| CVE-2010-3460 | Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL. | EXPLOIT ✓MEDIUM 5.0EPSS 8.36% | 17 September 2010 |
| CVE-2010-3458 | SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/. | EXPLOITHIGH 7.5EPSS 1.00% | 17 September 2010 |
| CVE-2010-3457 | Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) fields[website] parameter in the post comments feature in… | EXPLOITMEDIUM 4.3EPSS 1.50% | 17 September 2010 |
| CVE-2010-3456 | Directory traversal vulnerability in download.php in EnergyScripts (ES) Simple Download 1.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 7.61% | 17 September 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.