Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,633 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 191 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-2321 | Buffer overflow in Adobe InDesign CS3 10.0 allows user-assisted remote attackers to execute arbitrary code via a crafted .indd file. | EXPLOIT ✓HIGH 9.3EPSS 20.7% | 18 June 2010 |
| CVE-2010-2319 | SQL injection vulnerability in index.php in IDevSpot TextAds 2.08 allows remote attackers to execute arbitrary SQL commands via the page parameter. | EXPLOITHIGH 7.5EPSS 2.03% | 17 June 2010 |
| CVE-2010-2317 | Multiple SQL injection vulnerabilities in WmsCms 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) search, (2) sbr, (3) pid, (4) sbl, and (5) FilePath parameters to default.asp; and the (6) sbr, (7) pr, and (8) psPrice… | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 17 June 2010 |
| CVE-2010-2316 | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) sbr, (3) p, and (4) sbl parameters, different vectors than CVE-2007-3137. | EXPLOIT ✓MEDIUM 4.3EPSS 2.96% | 17 June 2010 |
| CVE-2010-2315 | PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cat parameter. | EXPLOITHIGH 7.5EPSS 5.82% | 17 June 2010 |
| CVE-2010-2314 | PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PLUGINS parameter. | EXPLOITMEDIUM 6.8EPSS 4.69% | 17 June 2010 |
| CVE-2010-2313 | Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 5.12% | 17 June 2010 |
| CVE-2010-2063 | Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute… | EXPLOIT ✓HIGH 7.5EPSS 78.6% | 17 June 2010 |
| CVE-2010-1964 | Buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified parameters to jovgraph.exe, aka ZDI-CAN-683. | EXPLOIT ×2 ✓HIGH 7.5EPSS 66.1% | 17 June 2010 |
| CVE-2010-1748 | The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent)… | EXPLOIT ✓MEDIUM 4.3EPSS 6.47% | 17 June 2010 |
| CVE-2010-2312 | SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to execute arbitrary SQL commands via the state parameter in a listings action. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 16 June 2010 |
| CVE-2010-2311 | Stack-based buffer overflow in Power Tab Editor 1.7 build 80 allows user-assisted remote attackers to execute arbitrary code via a .ptb file with a long font name. | EXPLOIT ✓HIGH 9.3EPSS 5.76% | 16 June 2010 |
| CVE-2010-2310 | SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request. | EXPLOIT ✓MEDIUM 5.0EPSS 11.0% | 16 June 2010 |
| CVE-2010-2309 | Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary code via a long GET request. | EXPLOIT ×4 ✓HIGH 7.5EPSS 50.8% | 16 June 2010 |
| CVE-2010-2307 | Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot… | EXPLOITMEDIUM 5.0EPSS 8.60% | 16 June 2010 |
| CVE-2010-2305 | Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitrary code via a long third argument to the SetRegString method. | EXPLOIT ✓HIGH 9.3EPSS 20.0% | 16 June 2010 |
| CVE-2010-1932 | Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) file with a Paint Data Section that contains a malformed Encoding field. | EXPLOIT ✓HIGH 9.3EPSS 10.8% | 16 June 2010 |
| CVE-2010-2300 | Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via… | EXPLOITHIGH 10.0EPSS 8.92% | 15 June 2010 |
| CVE-2010-2282 | Cross-site request forgery (CSRF) vulnerability in TomatoCMS 2.0.6 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password. | EXPLOITMEDIUM 5.1EPSS 0.79% | 15 June 2010 |
| CVE-2010-2275 | Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against… | EXPLOIT ✓MEDIUM 4.3EPSS 2.90% | 15 June 2010 |
| CVE-2010-2273 | Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors,… | EXPLOIT ✓MEDIUM 4.3EPSS 4.54% | 15 June 2010 |
| CVE-2010-2075 | UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands. | EXPLOIT ×2 ✓HIGH 7.5EPSS 83.5% | 15 June 2010 |
| CVE-2010-2266 | nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence. | EXPLOIT ✓MEDIUM 5.0EPSS 21.5% | 15 June 2010 |
| CVE-2010-2265 | Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the… | EXPLOIT ✓MEDIUM 4.3EPSS 21.0% | 15 June 2010 |
| CVE-2010-2263 | nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 71.9% | 15 June 2010 |
| CVE-2010-1885 | The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist… | EXPLOIT ×2 ✓HIGH 9.3EPSS 71.2% | 15 June 2010 |
| CVE-2010-1759 | Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors… | EXPLOITHIGH 9.3EPSS 15.7% | 11 June 2010 |
| CVE-2009-4892 | SQL injection vulnerability in Content Management System WEBjump! allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) portfolio_genre.php and (2) news_id.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 11 June 2010 |
| CVE-2009-4889 | SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the bookid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 11 June 2010 |
| CVE-2009-4888 | Cross-site scripting (XSS) vulnerability in poster.php in PHortail 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) ti, and (4) txt parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.76% | 11 June 2010 |
| CVE-2009-4886 | Multiple directory traversal vulnerabilities in phpCommunity 2 2.1.8 allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.91% | 11 June 2010 |
| CVE-2009-4883 | SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL commands via the (1) base_id or (2) course_id parameter in a search action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.00% | 11 June 2010 |
| CVE-2010-1961 | Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the… | EXPLOIT ✓HIGH 10.0EPSS 67.3% | 10 June 2010 |
| CVE-2010-1960 | Buffer overflow in the error handling functionality in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long, invalid option to jovgraph.exe. | EXPLOIT ✓HIGH 10.0EPSS 67.3% | 10 June 2010 |
| CVE-2010-1931 | SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shipKey parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.26% | 10 June 2010 |
| CVE-2010-2259 | Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 18.1% | 9 June 2010 |
| CVE-2010-2257 | SQL injection vulnerability in index_ie.php in Pay Per Minute Video Chat Script 2.0 and 2.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 9 June 2010 |
| CVE-2010-2256 | Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to… | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 9 June 2010 |
| CVE-2010-2255 | SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL… | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 9 June 2010 |
| CVE-2010-2254 | SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php. | EXPLOITHIGH 7.5EPSS 0.97% | 9 June 2010 |
| CVE-2010-1248 | Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability." | EXPLOIT ×2 ✓HIGH 9.3EPSS 27.2% | 8 June 2010 |
| CVE-2010-1247 | Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different… | EXPLOIT ✓HIGH 9.3EPSS 22.4% | 8 June 2010 |
| CVE-2010-1246 | Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability." | EXPLOIT ✓HIGH 9.3EPSS 24.7% | 8 June 2010 |
| CVE-2010-1245 | Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record,… | EXPLOIT ✓HIGH 9.3EPSS 22.4% | 8 June 2010 |
| CVE-2010-0824 | Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a… | EXPLOIT ✓HIGH 9.3EPSS 22.4% | 8 June 2010 |
| CVE-2010-0822 | Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record,… | EXPLOIT ×3 ✓HIGH 9.3EPSS 70.1% | 8 June 2010 |
| CVE-2010-1297 | Adobe Flash Player Memory Corruption Vulnerability | KEVEXPLOIT ×4 ✓HIGH 7.8EPSS 82.2% | 8 June 2010 |
| CVE-2010-2159 | Dameng DM Database Server allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors related to the SP_DEL_BAK_EXPIRED procedure in wdm_dll.dll, which triggers memory corruption. | EXPLOIT ✓MEDIUM 6.5EPSS 3.11% | 8 June 2010 |
| CVE-2010-1636 | The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to… | EXPLOIT ✓LOW 2.1EPSS 0.83% | 8 June 2010 |
| CVE-2010-2156 | ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID. | EXPLOITMEDIUM 5.0EPSS 76.4% | 7 June 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.