Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,587 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 187 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-2861 | Adobe ColdFusion Directory Traversal Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 99.7% | 11 August 2010 |
| CVE-2010-2561 | Microsoft XML Core Services (aka MSXML) 3.0 does not properly handle HTTP responses, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted response, aka "Msxml2.XMLHTTP.3.0 Response… | EXPLOIT ✓HIGH 9.3EPSS 24.9% | 11 August 2010 |
| CVE-2010-2554 | The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and… | EXPLOIT ✓HIGH 7.8EPSS 1.92% | 11 August 2010 |
| CVE-2010-2553 | The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decompress media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Cinepak Codec Decompression… | EXPLOIT ×2 ✓HIGH 9.3EPSS 30.9% | 11 August 2010 |
| CVE-2010-2550 | The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute… | EXPLOIT ✓HIGH 10.0EPSS 75.7% | 11 August 2010 |
| CVE-2010-1900 | Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Works 9 do… | EXPLOIT ✓HIGH 9.3EPSS 39.8% | 11 August 2010 |
| CVE-2010-1897 | The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-handle values in callback… | EXPLOIT ✓HIGH 7.2EPSS 3.43% | 11 August 2010 |
| CVE-2010-1894 | The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exceptions, which allows local users to gain privileges via a crafted application, aka "Win32k Exception… | EXPLOIT ×2HIGH 7.2EPSS 2.96% | 11 August 2010 |
| CVE-2010-1890 | The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka… | EXPLOIT ✓MEDIUM 4.6EPSS 2.57% | 11 August 2010 |
| CVE-2010-1889 | Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows… | EXPLOIT ✓HIGH 7.8EPSS 1.97% | 11 August 2010 |
| CVE-2010-1888 | Race condition in the kernel in Microsoft Windows XP SP3 allows local users to gain privileges via vectors involving thread creation, aka "Windows Kernel Data Initialization Vulnerability." | EXPLOIT ✓MEDIUM 6.8EPSS 2.50% | 11 August 2010 |
| CVE-2010-1887 | The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument,… | EXPLOIT ✓MEDIUM 4.4EPSS 1.96% | 11 August 2010 |
| CVE-2010-2973 | Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, as demonstrated by JailbreakMe. | EXPLOIT ✓MEDIUM 6.9EPSS 0.78% | 5 August 2010 |
| CVE-2010-2972 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 5 August 2010 |
| CVE-2010-2862 | Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table. | EXPLOIT ✓HIGH 9.3EPSS 16.3% | 5 August 2010 |
| CVE-2010-2709 | Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long OvJavaLocale value in a cookie. | EXPLOIT ×2 ✓HIGH 9.3EPSS 42.3% | 5 August 2010 |
| CVE-2010-2933 | SQL injection vulnerability in AV Scripts AV Arcade 3 allows remote attackers to execute arbitrary SQL commands via the ava_code cookie to the "main page," related to index.php and the login task. | EXPLOITHIGH 7.5EPSS 0.96% | 5 August 2010 |
| CVE-2010-2932 | Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument to the LoadProperties method. | EXPLOIT ×3 ✓HIGH 9.3EPSS 6.90% | 5 August 2010 |
| CVE-2010-2931 | Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a long eighth argument (HexString) to the LCDWriteString method. | EXPLOIT ✓HIGH 9.3EPSS 9.37% | 5 August 2010 |
| CVE-2010-1871 | Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 83.4% | 5 August 2010 |
| CVE-2010-2860 | The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for an intranet network within the appliance, which allows remote attackers to read, create, or modify arbitrary files in the user data… | EXPLOITHIGH 9.3EPSS 4.27% | 5 August 2010 |
| CVE-2010-2785 | The IRC Protocol component in KVIrc 3.x and 4.x before r4693 does not properly handle \ (backslash) characters, which allows remote authenticated users to execute arbitrary CTCP commands via vectors involving \r and \40 sequences, a different… | EXPLOIT ✓MEDIUM 6.5EPSS 7.57% | 2 August 2010 |
| CVE-2010-2926 | SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 30 July 2010 |
| CVE-2010-2925 | SQL injection vulnerability in index.php in Freeway CMS 1.4.3.210 allows remote attackers to execute arbitrary SQL commands via the ecPath parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 30 July 2010 |
| CVE-2010-2924 | SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the url parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.81% | 30 July 2010 |
| CVE-2010-2923 | SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_cate parameter to index.php. | EXPLOITHIGH 7.5EPSS 0.97% | 30 July 2010 |
| CVE-2010-2922 | SQL injection vulnerability in default.asp in AKY Blog allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 30 July 2010 |
| CVE-2010-2921 | SQL injection vulnerability in the Golf Course Guide (com_golfcourseguide) component 0.9.6.0 beta and 1 beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a golfcourses action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 30 July 2010 |
| CVE-2010-2920 | Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 5.69% | 30 July 2010 |
| CVE-2010-2919 | SQL injection vulnerability in the StaticXT (com_staticxt) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 30 July 2010 |
| CVE-2010-2918 | PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 13.7% | 30 July 2010 |
| CVE-2010-2917 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) emailid, (2) fname, (3) lname, (4) company, (5) address1, (6) address2, (7) city, (8)… | EXPLOITMEDIUM 4.3EPSS 1.72% | 30 July 2010 |
| CVE-2010-2916 | SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 30 July 2010 |
| CVE-2010-2915 | SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 30 July 2010 |
| CVE-2010-2752 | Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many… | EXPLOIT ✓HIGH 9.3EPSS 9.78% | 30 July 2010 |
| CVE-2010-1214 | Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements. | EXPLOIT ×2 ✓HIGH 9.3EPSS 7.58% | 30 July 2010 |
| CVE-2010-2912 | SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97% | 28 July 2010 |
| CVE-2010-2911 | SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01% | 28 July 2010 |
| CVE-2010-2910 | SQL injection vulnerability in the Ozio Gallery (com_oziogallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php. | EXPLOITHIGH 7.5EPSS 0.97% | 28 July 2010 |
| CVE-2010-2909 | SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a video action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.59% | 28 July 2010 |
| CVE-2010-2908 | SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the course_id parameter in a detail action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 28 July 2010 |
| CVE-2010-2907 | SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a detail action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.99% | 28 July 2010 |
| CVE-2010-2906 | SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-2905. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 28 July 2010 |
| CVE-2010-2905 | SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 28 July 2010 |
| CVE-2009-4974 | Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.32% | 28 July 2010 |
| CVE-2009-4973 | SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 28 July 2010 |
| CVE-2009-4964 | Stack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a .M3U playlist file. | EXPLOIT ✓HIGH 9.3EPSS 5.79% | 28 July 2010 |
| CVE-2009-4962 | Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a .wav file. | EXPLOIT ×3 ✓HIGH 9.3EPSS 31.4% | 28 July 2010 |
| CVE-2009-4961 | Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function. | EXPLOIT ✓MEDIUM 5.0EPSS 2.22% | 28 July 2010 |
| CVE-2009-4958 | SQL injection vulnerability in video.php in EMO Breeder Manager (aka EMO Breader Manager) allows remote attackers to execute arbitrary SQL commands via the idd parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 28 July 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.