Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,677 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 192 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-2154 | Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the search parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.00% | 3 June 2010 |
| CVE-2010-2153 | Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct… | EXPLOIT ✓MEDIUM 6.8EPSS 7.47% | 3 June 2010 |
| CVE-2010-2148 | SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pagina parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.40% | 3 June 2010 |
| CVE-2010-2147 | Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the modveh parameter to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 3.48% | 3 June 2010 |
| CVE-2010-2146 | PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP code via a URL in the VL_include_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 5.85% | 3 June 2010 |
| CVE-2010-2144 | Cross-site scripting (XSS) vulnerability in signinform.php in Zeeways eBay Clone Auction Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.37% | 3 June 2010 |
| CVE-2010-2143 | Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 7.27% | 3 June 2010 |
| CVE-2010-2142 | SQL injection vulnerability in default.asp in Cyberhost allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.03% | 2 June 2010 |
| CVE-2010-2141 | SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands via the PictureId parameter in an open action. | EXPLOIT ✓HIGH 7.5EPSS 2.04% | 2 June 2010 |
| CVE-2010-2138 | Multiple directory traversal vulnerabilities in ProMan 0.1.1 and earlier allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SESSION[userLang] parameter to (1) elisttasks.php, (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 4.07% | 2 June 2010 |
| CVE-2010-2137 | PHP remote file inclusion vulnerability in _center.php in ProMan 0.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 5.88% | 2 June 2010 |
| CVE-2010-2135 | Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) password fields. | EXPLOIT ✓HIGH 7.5EPSS 1.99% | 2 June 2010 |
| CVE-2010-2134 | Multiple SQL injection vulnerabilities in login.php in Project Man 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.85% | 2 June 2010 |
| CVE-2010-2133 | SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942. | EXPLOIT ✓HIGH 7.5EPSS 2.04% | 2 June 2010 |
| CVE-2010-2130 | Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.36% | 2 June 2010 |
| CVE-2010-2129 | Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 4.97% | 1 June 2010 |
| CVE-2010-2128 | Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 15.8% | 1 June 2010 |
| CVE-2010-2127 | PHP remote file inclusion vulnerability in gallery.php in JV2 Folder Gallery 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter. | EXPLOITHIGH 7.5EPSS 5.88% | 1 June 2010 |
| CVE-2010-2126 | Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_admin_path parameter to (1) index.php, (2) view.php, (3) image.php, (4) search.php, (5) admin/index.php,… | EXPLOIT ×2 ✓HIGH 7.5EPSS 8.29% | 1 June 2010 |
| CVE-2010-2124 | SQL injection vulnerability in firma.php in Bartels Schone ConPresso 4.0.7 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.99% | 1 June 2010 |
| CVE-2010-2122 | Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 11.7% | 1 June 2010 |
| CVE-2009-4880 | Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string,… | EXPLOIT ✓MEDIUM 5.0EPSS 11.2% | 1 June 2010 |
| CVE-2010-2115 | SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted read request. | EXPLOIT ✓MEDIUM 5.0EPSS 56.0% | 28 May 2010 |
| CVE-2010-2020 | sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount… | EXPLOIT ×2 ✓MEDIUM 6.9EPSS 0.87% | 28 May 2010 |
| CVE-2010-1938 | Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly… | EXPLOIT ✓HIGH 9.3EPSS 21.9% | 28 May 2010 |
| CVE-2010-2103 | Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products,… | EXPLOITMEDIUM 4.3EPSS 34.9% | 27 May 2010 |
| CVE-2010-2102 | Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request. | EXPLOIT ✓HIGH 10.0EPSS 6.62% | 27 May 2010 |
| CVE-2010-2099 | bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php,… | EXPLOIT ✓HIGH 7.5EPSS 4.87% | 27 May 2010 |
| CVE-2010-2094 | Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly… | EXPLOIT ✓MEDIUM 6.8EPSS 12.7% | 27 May 2010 |
| CVE-2010-2091 | Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive… | EXPLOITMEDIUM 4.3EPSS 17.9% | 27 May 2010 |
| CVE-2010-2089 | The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted… | EXPLOIT ✓MEDIUM 5.0EPSS 14.6% | 27 May 2010 |
| CVE-2010-1296 | Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) .ASL, (2) .ABR, or (3) .GRD file. | EXPLOIT ×3 ✓HIGH 9.3EPSS 19.6% | 27 May 2010 |
| CVE-2010-2025 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allow remote attackers to hijack the authentication of administrators for… | EXPLOIT ✓MEDIUM 6.8EPSS 2.08% | 26 May 2010 |
| CVE-2009-4876 | admin/cikkform.php in Netrix CMS 1.0 allows remote attackers to modify arbitrary pages via a direct request using the cid parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 1.97% | 26 May 2010 |
| CVE-2009-4874 | TalkBack 2.3.14 does not properly restrict access to the edit comment feature (comments.php), which allows remote attackers to modify comments. | EXPLOIT ✓MEDIUM 6.4EPSS 2.60% | 26 May 2010 |
| CVE-2009-4873 | Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie. | EXPLOIT ×2 ✓HIGH 10.0EPSS 20.6% | 26 May 2010 |
| CVE-2010-2051 | SQL injection vulnerability in article.php in Debliteck DBCart allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOITHIGH 7.5EPSS 0.97% | 25 May 2010 |
| CVE-2010-2050 | Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 13.1% | 25 May 2010 |
| CVE-2010-2047 | SQL injection vulnerability in index.php in JE CMS 1.0.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewcategory action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 25 May 2010 |
| CVE-2010-2045 | Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 8.93% | 25 May 2010 |
| CVE-2010-2044 | SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in a detail action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 25 May 2010 |
| CVE-2010-2042 | SQL injection vulnerability in search.php in ECShop 2.7.2 allows remote attackers to execute arbitrary SQL commands via the encode parameter. | EXPLOITHIGH 7.5EPSS 0.97% | 25 May 2010 |
| CVE-2010-2040 | Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers to inject arbitrary web script or HTML via the s parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 25 May 2010 |
| CVE-2010-2039 | Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin_Users action to index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.15% | 25 May 2010 |
| CVE-2010-2038 | Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticated users, with Edit privileges, to inject arbitrary web script or HTML via the gpcontent parameter to index.php. | EXPLOIT ✓LOW 2.1EPSS 1.34% | 25 May 2010 |
| CVE-2010-2037 | Directory traversal vulnerability in the Percha Downloads Attach (com_perchadownloadsattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 11.1% | 25 May 2010 |
| CVE-2010-2036 | Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 13.2% | 25 May 2010 |
| CVE-2010-2035 | Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 15.8% | 25 May 2010 |
| CVE-2010-2034 | Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 11.1% | 25 May 2010 |
| CVE-2010-2033 | Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 15.8% | 25 May 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.