Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,633 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 190 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-2509 | Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to category.php and the (2) password parameter to memberlogin.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.31% | 28 June 2010 |
| CVE-2010-2508 | SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 28 June 2010 |
| CVE-2010-2507 | Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 9.43% | 28 June 2010 |
| CVE-2010-2505 | Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash) via a large number of requests with a long line, as demonstrated using a long GET request. | EXPLOIT ✓MEDIUM 5.0EPSS 2.69% | 28 June 2010 |
| CVE-2010-1930 | Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree parameter in a login request to nps/servlet/webacc. | EXPLOIT ✓MEDIUM 5.0EPSS 8.32% | 28 June 2010 |
| CVE-2010-1929 | Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated users to execute arbitrary code… | EXPLOIT ✓HIGH 9.0EPSS 16.1% | 28 June 2010 |
| CVE-2010-2464 | Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 25 June 2010 |
| CVE-2010-2463 | Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 25 June 2010 |
| CVE-2010-2462 | SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 25 June 2010 |
| CVE-2010-2461 | SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 25 June 2010 |
| CVE-2010-2460 | SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 25 June 2010 |
| CVE-2010-2459 | SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 25 June 2010 |
| CVE-2010-2458 | Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 25 June 2010 |
| CVE-2010-2457 | Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script or HTML via the term parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 25 June 2010 |
| CVE-2010-2456 | Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read and execute arbitrary local files via a URL in the (1) cook_lan cookie parameter ($lan_dir variable) or possibly (2) Sdb_type parameter. | EXPLOITMEDIUM 6.8EPSS 2.03% | 25 June 2010 |
| CVE-2009-4908 | Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HTML via the (1) commentName, (2) commentEmail, (3) commentWeb, or (4) commentText parameter to article.php; and allow remote… | EXPLOIT ✓MEDIUM 4.3EPSS 1.65% | 25 June 2010 |
| CVE-2009-4907 | Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) force an admin logout, (3) change the visibility of posts, (4)… | EXPLOIT ✓MEDIUM 6.8EPSS 1.08% | 25 June 2010 |
| CVE-2009-4906 | Cross-site request forgery (CSRF) vulnerability in index.php in Acc PHP eMail 1.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords. | EXPLOITMEDIUM 6.8EPSS 1.07% | 25 June 2010 |
| CVE-2009-4905 | Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Acc Statistics 1.1 allow remote attackers to hijack the authentication of administrators for requests that change (1) passwords, (2) usernames, and (3) e-mail addresses. | EXPLOITMEDIUM 6.8EPSS 0.94% | 25 June 2010 |
| CVE-2010-2440 | Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to execute arbitrary code via a crafted SRT file with a long line after a time range. | EXPLOIT ✓HIGH 9.3EPSS 5.59% | 24 June 2010 |
| CVE-2010-2439 | Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file). | EXPLOIT ×3 ✓HIGH 9.3EPSS 5.82% | 24 June 2010 |
| CVE-2010-2438 | SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 24 June 2010 |
| CVE-2010-2437 | Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 24 June 2010 |
| CVE-2010-2436 | SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 June 2010 |
| CVE-2010-2435 | Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection HTTP header, and possibly other headers. | EXPLOIT ✓MEDIUM 5.0EPSS 6.47% | 24 June 2010 |
| CVE-2010-1199 | Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a… | EXPLOIT ×2 ✓HIGH 9.3EPSS 11.4% | 24 June 2010 |
| CVE-2010-2433 | Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 24 June 2010 |
| CVE-2010-2359 | SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 21 June 2010 |
| CVE-2010-2358 | PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the core[system_path]… | EXPLOITMEDIUM 5.1EPSS 2.52% | 21 June 2010 |
| CVE-2010-2357 | SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 21 June 2010 |
| CVE-2010-2356 | Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the course_id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 21 June 2010 |
| CVE-2010-2355 | Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the message parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.46% | 21 June 2010 |
| CVE-2010-2354 | SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary SQL commands via the course_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 21 June 2010 |
| CVE-2010-2351 | Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitrary code via a Sessions Setup AndX packet with a long AccountName. | EXPLOIT ✓HIGH 10.0EPSS 15.7% | 21 June 2010 |
| CVE-2010-2349 | H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which triggers a NULL pointer dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 4.80% | 21 June 2010 |
| CVE-2010-2348 | Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute arbitrary code via a long line in a .WAV file. | EXPLOIT ✓HIGH 9.3EPSS 5.58% | 21 June 2010 |
| CVE-2010-1622 | SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar… | EXPLOIT ✓MEDIUM 6.0EPSS 52.0% | 21 June 2010 |
| CVE-2010-2343 | Stack-based buffer overflow in D.R. | EXPLOIT ×4 ✓HIGH 9.3EPSS 36.7% | 21 June 2010 |
| CVE-2010-2342 | SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 21 June 2010 |
| CVE-2010-2341 | PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_dir parameter. | EXPLOITHIGH 7.5EPSS 2.49% | 18 June 2010 |
| CVE-2010-2340 | SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the by parameter in the msearch action. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 18 June 2010 |
| CVE-2010-2338 | Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 18 June 2010 |
| CVE-2010-2336 | index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the download parameter. | EXPLOITMEDIUM 5.0EPSS 2.35% | 18 June 2010 |
| CVE-2010-2335 | SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to execute arbitrary SQL commands via the news parameter. | EXPLOIT ×2HIGH 7.5EPSS 1.01% | 18 June 2010 |
| CVE-2010-2334 | Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.18% | 18 June 2010 |
| CVE-2010-2333 | LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension. | EXPLOIT ✓MEDIUM 5.0EPSS 60.2% | 18 June 2010 |
| CVE-2010-2332 | Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request. | EXPLOITMEDIUM 5.0EPSS 6.00% | 18 June 2010 |
| CVE-2010-2331 | Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to execute arbitrary code via a long HEAD request. | EXPLOIT ✓HIGH 9.3EPSS 5.59% | 18 June 2010 |
| CVE-2010-2330 | Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Length header. | EXPLOIT ✓HIGH 9.3EPSS 27.8% | 18 June 2010 |
| CVE-2010-2329 | Buffer overflow in Rosoft Audio Converter 4.4.4 allows remote attackers to execute arbitrary code via a long playlist entry in a .m3u file. | EXPLOIT ✓HIGH 9.3EPSS 6.77% | 18 June 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.