SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,677 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 192 of 501

CVESummaryPriorityPublished
CVE-2010-2154Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the search parameter.EXPLOITMEDIUM 4.3EPSS 3.00%3 June 2010
CVE-2010-2153Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct…EXPLOITMEDIUM 6.8EPSS 7.47%3 June 2010
CVE-2010-2148SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pagina parameter to index.php.EXPLOITHIGH 7.5EPSS 2.40%3 June 2010
CVE-2010-2147Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the modveh parameter to index.php.EXPLOITMEDIUM 4.3EPSS 3.48%3 June 2010
CVE-2010-2146PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP code via a URL in the VL_include_path parameter.EXPLOITHIGH 7.5EPSS 5.85%3 June 2010
CVE-2010-2144Cross-site scripting (XSS) vulnerability in signinform.php in Zeeways eBay Clone Auction Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter.EXPLOITMEDIUM 4.3EPSS 3.37%3 June 2010
CVE-2010-2143Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITHIGH 7.5EPSS 7.27%3 June 2010
CVE-2010-2142SQL injection vulnerability in default.asp in Cyberhost allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 2.03%2 June 2010
CVE-2010-2141SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands via the PictureId parameter in an open action.EXPLOITHIGH 7.5EPSS 2.04%2 June 2010
CVE-2010-2138Multiple directory traversal vulnerabilities in ProMan 0.1.1 and earlier allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SESSION[userLang] parameter to (1) elisttasks.php, (2)…EXPLOITMEDIUM 6.8EPSS 4.07%2 June 2010
CVE-2010-2137PHP remote file inclusion vulnerability in _center.php in ProMan 0.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.EXPLOITHIGH 7.5EPSS 5.88%2 June 2010
CVE-2010-2135Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) password fields.EXPLOITHIGH 7.5EPSS 1.99%2 June 2010
CVE-2010-2134Multiple SQL injection vulnerabilities in login.php in Project Man 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.EXPLOITHIGH 7.5EPSS 1.85%2 June 2010
CVE-2010-2133SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942.EXPLOITHIGH 7.5EPSS 2.04%2 June 2010
CVE-2010-2130Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.EXPLOITMEDIUM 4.3EPSS 3.36%2 June 2010
CVE-2010-2129Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 6.8EPSS 4.97%1 June 2010
CVE-2010-2128Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITHIGH 7.5EPSS 15.8%1 June 2010
CVE-2010-2127PHP remote file inclusion vulnerability in gallery.php in JV2 Folder Gallery 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.EXPLOITHIGH 7.5EPSS 5.88%1 June 2010
CVE-2010-2126Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_admin_path parameter to (1) index.php, (2) view.php, (3) image.php, (4) search.php, (5) admin/index.php,…EXPLOIT ×2HIGH 7.5EPSS 8.29%1 June 2010
CVE-2010-2124SQL injection vulnerability in firma.php in Bartels Schone ConPresso 4.0.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 1.99%1 June 2010
CVE-2010-2122Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ×2MEDIUM 6.8EPSS 11.7%1 June 2010
CVE-2009-4880Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string,…EXPLOITMEDIUM 5.0EPSS 11.2%1 June 2010
CVE-2010-2115SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted read request.EXPLOITMEDIUM 5.0EPSS 56.0%28 May 2010
CVE-2010-2020sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount…EXPLOIT ×2MEDIUM 6.9EPSS 0.87%28 May 2010
CVE-2010-1938Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly…EXPLOITHIGH 9.3EPSS 21.9%28 May 2010
CVE-2010-2103Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products,…EXPLOITMEDIUM 4.3EPSS 34.9%27 May 2010
CVE-2010-2102Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.EXPLOITHIGH 10.0EPSS 6.62%27 May 2010
CVE-2010-2099bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php,…EXPLOITHIGH 7.5EPSS 4.87%27 May 2010
CVE-2010-2094Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly…EXPLOITMEDIUM 6.8EPSS 12.7%27 May 2010
CVE-2010-2091Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive…EXPLOITMEDIUM 4.3EPSS 17.9%27 May 2010
CVE-2010-2089The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted…EXPLOITMEDIUM 5.0EPSS 14.6%27 May 2010
CVE-2010-1296Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) .ASL, (2) .ABR, or (3) .GRD file.EXPLOIT ×3HIGH 9.3EPSS 19.6%27 May 2010
CVE-2010-2025Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allow remote attackers to hijack the authentication of administrators for…EXPLOITMEDIUM 6.8EPSS 2.08%26 May 2010
CVE-2009-4876admin/cikkform.php in Netrix CMS 1.0 allows remote attackers to modify arbitrary pages via a direct request using the cid parameter.EXPLOITMEDIUM 5.0EPSS 1.97%26 May 2010
CVE-2009-4874TalkBack 2.3.14 does not properly restrict access to the edit comment feature (comments.php), which allows remote attackers to modify comments.EXPLOITMEDIUM 6.4EPSS 2.60%26 May 2010
CVE-2009-4873Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie.EXPLOIT ×2HIGH 10.0EPSS 20.6%26 May 2010
CVE-2010-2051SQL injection vulnerability in article.php in Debliteck DBCart allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 0.97%25 May 2010
CVE-2010-2050Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 13.1%25 May 2010
CVE-2010-2047SQL injection vulnerability in index.php in JE CMS 1.0.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewcategory action.EXPLOITHIGH 7.5EPSS 1.00%25 May 2010
CVE-2010-2045Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.EXPLOITHIGH 7.5EPSS 8.93%25 May 2010
CVE-2010-2044SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in a detail action to index.php.EXPLOITHIGH 7.5EPSS 1.15%25 May 2010
CVE-2010-2042SQL injection vulnerability in search.php in ECShop 2.7.2 allows remote attackers to execute arbitrary SQL commands via the encode parameter.EXPLOITHIGH 7.5EPSS 0.97%25 May 2010
CVE-2010-2040Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers to inject arbitrary web script or HTML via the s parameter.EXPLOITMEDIUM 4.3EPSS 1.50%25 May 2010
CVE-2010-2039Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin_Users action to index.php.EXPLOITMEDIUM 6.8EPSS 1.15%25 May 2010
CVE-2010-2038Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticated users, with Edit privileges, to inject arbitrary web script or HTML via the gpcontent parameter to index.php.EXPLOITLOW 2.1EPSS 1.34%25 May 2010
CVE-2010-2037Directory traversal vulnerability in the Percha Downloads Attach (com_perchadownloadsattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITHIGH 7.5EPSS 11.1%25 May 2010
CVE-2010-2036Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITHIGH 7.5EPSS 13.2%25 May 2010
CVE-2010-2035Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITHIGH 7.5EPSS 15.8%25 May 2010
CVE-2010-2034Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITHIGH 7.5EPSS 11.1%25 May 2010
CVE-2010-2033Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITHIGH 7.5EPSS 15.8%25 May 2010

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.