SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,633 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 190 of 501

CVESummaryPriorityPublished
CVE-2010-2509Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to category.php and the (2) password parameter to memberlogin.php.EXPLOITMEDIUM 4.3EPSS 1.31%28 June 2010
CVE-2010-2508SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter.EXPLOITHIGH 7.5EPSS 0.96%28 June 2010
CVE-2010-2507Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITMEDIUM 6.8EPSS 9.43%28 June 2010
CVE-2010-2505Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash) via a large number of requests with a long line, as demonstrated using a long GET request.EXPLOITMEDIUM 5.0EPSS 2.69%28 June 2010
CVE-2010-1930Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree parameter in a login request to nps/servlet/webacc.EXPLOITMEDIUM 5.0EPSS 8.32%28 June 2010
CVE-2010-1929Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated users to execute arbitrary code…EXPLOITHIGH 9.0EPSS 16.1%28 June 2010
CVE-2010-2464Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.EXPLOITMEDIUM 4.3EPSS 1.72%25 June 2010
CVE-2010-2463Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.EXPLOITMEDIUM 4.3EPSS 1.45%25 June 2010
CVE-2010-2462SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.EXPLOITHIGH 7.5EPSS 0.97%25 June 2010
CVE-2010-2461SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter.EXPLOITHIGH 7.5EPSS 0.97%25 June 2010
CVE-2010-2460SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.EXPLOITHIGH 7.5EPSS 0.96%25 June 2010
CVE-2010-2459SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter.EXPLOITHIGH 7.5EPSS 1.00%25 June 2010
CVE-2010-2458Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter.EXPLOITMEDIUM 4.3EPSS 1.72%25 June 2010
CVE-2010-2457Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script or HTML via the term parameter.EXPLOITMEDIUM 4.3EPSS 1.45%25 June 2010
CVE-2010-2456Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read and execute arbitrary local files via a URL in the (1) cook_lan cookie parameter ($lan_dir variable) or possibly (2) Sdb_type parameter.EXPLOITMEDIUM 6.8EPSS 2.03%25 June 2010
CVE-2009-4908Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HTML via the (1) commentName, (2) commentEmail, (3) commentWeb, or (4) commentText parameter to article.php; and allow remote…EXPLOITMEDIUM 4.3EPSS 1.65%25 June 2010
CVE-2009-4907Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) force an admin logout, (3) change the visibility of posts, (4)…EXPLOITMEDIUM 6.8EPSS 1.08%25 June 2010
CVE-2009-4906Cross-site request forgery (CSRF) vulnerability in index.php in Acc PHP eMail 1.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords.EXPLOITMEDIUM 6.8EPSS 1.07%25 June 2010
CVE-2009-4905Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Acc Statistics 1.1 allow remote attackers to hijack the authentication of administrators for requests that change (1) passwords, (2) usernames, and (3) e-mail addresses.EXPLOITMEDIUM 6.8EPSS 0.94%25 June 2010
CVE-2010-2440Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to execute arbitrary code via a crafted SRT file with a long line after a time range.EXPLOITHIGH 9.3EPSS 5.59%24 June 2010
CVE-2010-2439Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).EXPLOIT ×3HIGH 9.3EPSS 5.82%24 June 2010
CVE-2010-2438SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php.EXPLOITHIGH 7.5EPSS 0.91%24 June 2010
CVE-2010-2437Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php.EXPLOITMEDIUM 4.3EPSS 1.45%24 June 2010
CVE-2010-2436SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.EXPLOITHIGH 7.5EPSS 0.97%24 June 2010
CVE-2010-2435Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection HTTP header, and possibly other headers.EXPLOITMEDIUM 5.0EPSS 6.47%24 June 2010
CVE-2010-1199Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a…EXPLOIT ×2HIGH 9.3EPSS 11.4%24 June 2010
CVE-2010-2433Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3)…EXPLOITMEDIUM 4.3EPSS 1.47%24 June 2010
CVE-2010-2359SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706.EXPLOITHIGH 7.5EPSS 0.97%21 June 2010
CVE-2010-2358PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the core[system_path]…EXPLOITMEDIUM 5.1EPSS 2.52%21 June 2010
CVE-2010-2357SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter.EXPLOITHIGH 7.5EPSS 1.00%21 June 2010
CVE-2010-2356Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the course_id parameter.EXPLOITMEDIUM 4.3EPSS 1.44%21 June 2010
CVE-2010-2355Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the message parameter.EXPLOITMEDIUM 4.3EPSS 1.46%21 June 2010
CVE-2010-2354SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary SQL commands via the course_id parameter.EXPLOITHIGH 7.5EPSS 1.15%21 June 2010
CVE-2010-2351Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitrary code via a Sessions Setup AndX packet with a long AccountName.EXPLOITHIGH 10.0EPSS 15.7%21 June 2010
CVE-2010-2349H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which triggers a NULL pointer dereference.EXPLOITMEDIUM 5.0EPSS 4.80%21 June 2010
CVE-2010-2348Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute arbitrary code via a long line in a .WAV file.EXPLOITHIGH 9.3EPSS 5.58%21 June 2010
CVE-2010-1622SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar…EXPLOITMEDIUM 6.0EPSS 52.0%21 June 2010
CVE-2010-2343Stack-based buffer overflow in D.R.EXPLOIT ×4HIGH 9.3EPSS 36.7%21 June 2010
CVE-2010-2342SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.EXPLOITHIGH 7.5EPSS 0.91%21 June 2010
CVE-2010-2341PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_dir parameter.EXPLOITHIGH 7.5EPSS 2.49%18 June 2010
CVE-2010-2340SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the by parameter in the msearch action.EXPLOITMEDIUM 6.8EPSS 0.91%18 June 2010
CVE-2010-2338Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.EXPLOITHIGH 7.5EPSS 1.15%18 June 2010
CVE-2010-2336index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the download parameter.EXPLOITMEDIUM 5.0EPSS 2.35%18 June 2010
CVE-2010-2335SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to execute arbitrary SQL commands via the news parameter.EXPLOIT ×2HIGH 7.5EPSS 1.01%18 June 2010
CVE-2010-2334Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to read arbitrary files via a ..EXPLOIT ×2MEDIUM 5.0EPSS 3.18%18 June 2010
CVE-2010-2333LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension.EXPLOITMEDIUM 5.0EPSS 60.2%18 June 2010
CVE-2010-2332Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request.EXPLOITMEDIUM 5.0EPSS 6.00%18 June 2010
CVE-2010-2331Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to execute arbitrary code via a long HEAD request.EXPLOITHIGH 9.3EPSS 5.59%18 June 2010
CVE-2010-2330Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Length header.EXPLOITHIGH 9.3EPSS 27.8%18 June 2010
CVE-2010-2329Buffer overflow in Rosoft Audio Converter 4.4.4 allows remote attackers to execute arbitrary code via a long playlist entry in a .m3u file.EXPLOITHIGH 9.3EPSS 6.77%18 June 2010

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.