Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,633 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 189 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-2681 | PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig.absolute.path parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.28% | 12 July 2010 |
| CVE-2010-2680 | Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the view parameter to… | EXPLOIT ✓MEDIUM 6.8EPSS 4.85% | 12 July 2010 |
| CVE-2009-4935 | SQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL commands via the display parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.92% | 12 July 2010 |
| CVE-2009-4934 | Cross-site scripting (XSS) vulnerability in index.php in Online Photo Pro 2.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 12 July 2010 |
| CVE-2009-4933 | Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 12 July 2010 |
| CVE-2009-4932 | Stack-based buffer overflow in 1by1 1.67 (aka 1.6.7.0) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file. | EXPLOIT ✓MEDIUM 6.8EPSS 3.73% | 12 July 2010 |
| CVE-2009-4929 | admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.46% | 12 July 2010 |
| CVE-2009-4927 | WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by setting this cookie to 1. | EXPLOIT ✓HIGH 7.5EPSS 2.48% | 12 July 2010 |
| CVE-2009-4926 | Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) showGroup parameter to (a) index.php and the (2) id parameter to (b)… | EXPLOIT ×5 ✓MEDIUM 4.3EPSS 1.64% | 12 July 2010 |
| CVE-2009-4925 | Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the username parameter to (1)… | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 12 July 2010 |
| CVE-2010-2679 | SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 8 July 2010 |
| CVE-2010-2677 | PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.69% | 8 July 2010 |
| CVE-2010-2676 | Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers to read arbitrary files via directory traversal sequences in the (1) owa_action and (2) owa_do parameters. | EXPLOIT ✓MEDIUM 5.0EPSS 2.86% | 8 July 2010 |
| CVE-2010-2675 | Cross-site scripting (XSS) vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an articolo action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.21% | 8 July 2010 |
| CVE-2010-2674 | SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an articolo action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 8 July 2010 |
| CVE-2010-2673 | SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 8 July 2010 |
| CVE-2010-2670 | SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 8 July 2010 |
| CVE-2010-2669 | Cross-site scripting (XSS) vulnerability in admin/editors/text/editor-body.php in Orbis CMS 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 8 July 2010 |
| CVE-2010-2656 | The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to… | EXPLOIT ✓MEDIUM 5.0EPSS 2.46% | 8 July 2010 |
| CVE-2010-2655 | Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allows remote authenticated users to list arbitrary… | EXPLOIT ✓MEDIUM 4.0EPSS 2.29% | 8 July 2010 |
| CVE-2010-2654 | Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allow remote attackers to inject arbitrary web script or HTML via… | EXPLOIT ✓MEDIUM 4.3EPSS 2.28% | 8 July 2010 |
| CVE-2010-2631 | LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second stage, which allows remote attackers to cause a denial of service (application crash) via a crafted file,… | EXPLOIT ✓MEDIUM 4.3EPSS 2.88% | 6 July 2010 |
| CVE-2010-2630 | The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a… | EXPLOIT ✓MEDIUM 4.3EPSS 4.95% | 6 July 2010 |
| CVE-2010-2482 | LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than… | EXPLOIT ✓MEDIUM 4.3EPSS 8.77% | 6 July 2010 |
| CVE-2010-1327 | Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 6 July 2010 |
| CVE-2010-2627 | Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, allow remote servers to overwrite arbitrary files on the client via "..\"… | EXPLOIT ✓MEDIUM 6.8EPSS 3.66% | 2 July 2010 |
| CVE-2010-2626 | index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. | EXPLOIT ✓HIGH 7.5EPSS 12.9% | 2 July 2010 |
| CVE-2010-2624 | Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tags_details.php, or (3) begin parameter to greetings.php. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 2 July 2010 |
| CVE-2010-2623 | SQL injection vulnerability in pages.php in Internet DM Specialist Bed and Breakfast allows remote attackers to execute arbitrary SQL commands via the pp_id parameter. | EXPLOITHIGH 7.5EPSS 0.97% | 2 July 2010 |
| CVE-2010-2622 | SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 2 July 2010 |
| CVE-2010-2621 | The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request. | EXPLOIT ✓MEDIUM 5.0EPSS 10.5% | 2 July 2010 |
| CVE-2010-2620 | Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or other commands without performing the required login steps first. | EXPLOIT ×3 ✓HIGH 9.3EPSS 29.6% | 2 July 2010 |
| CVE-2010-2549 | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges or cause a denial of service (system crash) by using a large number of calls to the… | EXPLOIT ✓HIGH 7.2EPSS 5.15% | 2 July 2010 |
| CVE-2010-2618 | PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.09% | 2 July 2010 |
| CVE-2010-2617 | Cross-site scripting (XSS) vulnerability in bible.php in PHP Bible Search allows remote attackers to inject arbitrary web script or HTML via the chapter parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 2 July 2010 |
| CVE-2010-2616 | SQL injection vulnerability in bible.php in PHP Bible Search, probably 0.99, allows remote attackers to execute arbitrary SQL commands via the chapter parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 July 2010 |
| CVE-2010-2615 | Multiple cross-site scripting (XSS) vulnerabilities in admin/admin.php in Grafik CMS 1.1.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) page_menu and (2) description parameters in an edit_page action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 2 July 2010 |
| CVE-2010-2613 | Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd Song (com_awd_song) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the song review field, which is not properly handled in a view action to… | EXPLOIT ✓MEDIUM 4.3EPSS 1.60% | 2 July 2010 |
| CVE-2010-2611 | SQL injection vulnerability in show_search_result.php in i-netsolution Job Search Engine allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 2 July 2010 |
| CVE-2010-2610 | Multiple SQL injection vulnerabilities in 2daybiz Job Site Script allow remote attackers to execute arbitrary SQL commands via the (1) jid parameter to view_current_job.php, (2) job_iid parameter to show_search_more.php, and (3) left_cat parameter to… | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 2 July 2010 |
| CVE-2010-2609 | SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.36% | 2 July 2010 |
| CVE-2010-2204 | Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors. | EXPLOIT ✓HIGH 9.3EPSS 13.0% | 30 June 2010 |
| CVE-2010-2201 | Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content involving the (1) pushstring (0x2C) operator, (2) debugfile (0xF1) operator, and… | EXPLOIT ✓HIGH 9.3EPSS 14.3% | 30 June 2010 |
| CVE-2010-2168 | Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content, involving the newfunction (0x44) operator and an "invalid pointer… | EXPLOIT ✓HIGH 9.3EPSS 14.3% | 30 June 2010 |
| CVE-2010-1205 | Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row. | EXPLOIT ✓CRITICAL 9.8EPSS 43.4% | 30 June 2010 |
| CVE-2008-7257 | CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary HTTP headers as demonstrated by a redirect attack… | EXPLOIT ✓MEDIUM 4.3EPSS 11.6% | 29 June 2010 |
| CVE-2010-2513 | SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php. | EXPLOIT ×2HIGH 7.5EPSS 1.11% | 28 June 2010 |
| CVE-2010-2512 | SQL injection vulnerability in customprofile.php in 2daybiz Matrimonial Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 28 June 2010 |
| CVE-2010-2511 | SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 28 June 2010 |
| CVE-2010-2510 | SQL injection vulnerability in customize.php in 2daybiz Web Template Software allows remote attackers to execute arbitrary SQL commands via the tid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 28 June 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.