Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,677 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 193 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-2032 | Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1)… | EXPLOIT ✓MEDIUM 4.3EPSS 3.36% | 24 May 2010 |
| CVE-2010-2031 | KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVSafe device. | EXPLOITHIGH 7.2EPSS 0.75% | 24 May 2010 |
| CVE-2010-2028 | Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long transport mode. | EXPLOIT ×2 ✓HIGH 10.0EPSS 13.9% | 24 May 2010 |
| CVE-2010-1688 | Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attackers to execute arbitrary code via a long filename in a (1) .sps or (2) zip profile. | EXPLOIT ✓HIGH 9.3EPSS 15.0% | 24 May 2010 |
| CVE-2010-2018 | Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.26% | 24 May 2010 |
| CVE-2010-2016 | SQL injection vulnerability in details.php in Iceberg CMS allows remote attackers to execute arbitrary SQL commands via the p_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 24 May 2010 |
| CVE-2010-2015 | Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a view_inbox action to cp/cp_messages.php or (2) the id parameter to cp/edit_email.php. | EXPLOITMEDIUM 6.8EPSS 0.90% | 24 May 2010 |
| CVE-2010-2006 | Directory traversal vulnerability in op/op.Login.php in LetoDMS (formerly MyDMS) 1.7.2 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.5EPSS 6.69% | 20 May 2010 |
| CVE-2010-2005 | Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the selected_language parameter to engine/inc/include/init.php, (2) the config[langs] parameter to… | EXPLOIT ×4 ✓HIGH 7.5EPSS 2.81% | 20 May 2010 |
| CVE-2010-2004 | Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via the Skin parameter in the Options section of a skins file (.bsi), a different… | EXPLOIT ×2 ✓HIGH 9.3EPSS 9.32% | 20 May 2010 |
| CVE-2010-2003 | Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject arbitrary web script or HTML via the mysql_host parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.00% | 20 May 2010 |
| CVE-2010-1999 | Directory traversal vulnerability in scr/soustab.php in OpenMairie Opencatalogue 1.024, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype]… | EXPLOIT ✓MEDIUM 6.8EPSS 2.23% | 20 May 2010 |
| CVE-2010-1997 | Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter. | EXPLOIT ✓LOW 2.1EPSS 3.38% | 20 May 2010 |
| CVE-2010-1994 | SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the q parameter in conjunction with a /news/search PATH_INFO. | EXPLOIT ✓HIGH 7.5EPSS 1.18% | 20 May 2010 |
| CVE-2010-1039 | Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to… | EXPLOIT ✓HIGH 10.0EPSS 20.2% | 20 May 2010 |
| CVE-2010-1983 | Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 18.8% | 19 May 2010 |
| CVE-2010-1982 | Directory traversal vulnerability in the JA Voice (com_javoice) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 9.08% | 19 May 2010 |
| CVE-2010-1981 | Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 11.9% | 19 May 2010 |
| CVE-2010-1980 | Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 18.8% | 19 May 2010 |
| CVE-2010-1979 | Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 11.2% | 19 May 2010 |
| CVE-2010-1977 | Directory traversal vulnerability in the J!WHMCS Integrator (com_jwhmcs) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 7.40% | 19 May 2010 |
| CVE-2010-1948 | Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter,… | EXPLOIT ✓MEDIUM 6.8EPSS 4.16% | 19 May 2010 |
| CVE-2010-1947 | Directory traversal vulnerability in scr/soustab.php in openMairie Openregistrecil 1.02, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype]… | EXPLOIT ✓MEDIUM 6.8EPSS 4.74% | 19 May 2010 |
| CVE-2010-1946 | Multiple PHP remote file inclusion vulnerabilities in openMairie Openregistrecil 1.02, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) autorisation_normale.class.php, (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 5.83% | 19 May 2010 |
| CVE-2010-1945 | Multiple PHP remote file inclusion vulnerabilities in openMairie Openfoncier 2.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) action.class.php, (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 5.18% | 19 May 2010 |
| CVE-2010-1944 | Multiple PHP remote file inclusion vulnerabilities in openMairie openCimetiere 2.01, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) autorisation.class.php, (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 5.83% | 19 May 2010 |
| CVE-2010-1957 | Directory traversal vulnerability in the Love Factory (com_lovefactory) component 1.3.4 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 14.8% | 19 May 2010 |
| CVE-2010-1956 | Directory traversal vulnerability in the Gadget Factory (com_gadgetfactory) component 1.0.0 and 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 17.0% | 19 May 2010 |
| CVE-2010-1955 | Directory traversal vulnerability in the Deluxe Blog Factory (com_blogfactory) component 1.1.2 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 17.9% | 19 May 2010 |
| CVE-2010-1954 | Directory traversal vulnerability in the iNetLanka Multiple root (com_multiroot) component 1.0 and 1.1 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 16.2% | 19 May 2010 |
| CVE-2010-1953 | Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 16.2% | 19 May 2010 |
| CVE-2010-1952 | Directory traversal vulnerability in the BeeHeard (com_beeheard) and BeeHeard Lite (com_beeheardlite) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 13.0% | 19 May 2010 |
| CVE-2010-1951 | Multiple directory traversal vulnerabilities in 60cycleCMS allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the DOCUMENT_ROOT parameter to (1) news.php, (2) submitComment.php, and (3) sqlConnect.php. | EXPLOIT ✓MEDIUM 6.8EPSS 7.48% | 19 May 2010 |
| CVE-2010-1950 | SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.60% | 19 May 2010 |
| CVE-2010-1949 | SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.83% | 19 May 2010 |
| CVE-2010-0475 | Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.82% | 14 May 2010 |
| CVE-2010-1939 | Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers… | EXPLOIT ×2 ✓HIGH 7.6EPSS 14.7% | 13 May 2010 |
| CVE-2010-1555 | Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid Hostname parameter. | EXPLOIT ×2 ✓HIGH 10.0EPSS 62.4% | 13 May 2010 |
| CVE-2010-1554 | Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid iCount parameter. | EXPLOIT ×2 ✓HIGH 10.0EPSS 65.9% | 13 May 2010 |
| CVE-2010-1553 | Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid MaxAge parameter. | EXPLOIT ×2 ✓HIGH 10.0EPSS 70.6% | 13 May 2010 |
| CVE-2010-1552 | Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the act and app parameters. | EXPLOIT ✓HIGH 10.0EPSS 67.1% | 13 May 2010 |
| CVE-2010-1280 | Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file. | EXPLOIT ✓HIGH 8.8EPSS 16.6% | 13 May 2010 |
| CVE-2010-1936 | Directory traversal vulnerability in scr/soustab.php in openMairie openComInterne 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype]… | EXPLOIT ✓MEDIUM 6.8EPSS 1.96% | 12 May 2010 |
| CVE-2010-1935 | Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a… | EXPLOIT ✓MEDIUM 6.8EPSS 1.96% | 12 May 2010 |
| CVE-2010-1934 | Multiple PHP remote file inclusion vulnerabilities in openMairie openPlanning 1.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) categorie.class.php, (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 2.90% | 12 May 2010 |
| CVE-2010-1928 | Directory traversal vulnerability in scr/soustab.php in openMairie openPlanning 1.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter,… | EXPLOIT ✓MEDIUM 6.8EPSS 1.96% | 12 May 2010 |
| CVE-2010-1927 | Multiple PHP remote file inclusion vulnerabilities in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) bible.class.php, (2)… | EXPLOITMEDIUM 6.8EPSS 3.22% | 12 May 2010 |
| CVE-2010-1926 | Directory traversal vulnerability in scr/soustab.php in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the… | EXPLOITMEDIUM 6.8EPSS 1.97% | 12 May 2010 |
| CVE-2010-1925 | SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-2817. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 12 May 2010 |
| CVE-2010-1924 | SQL injection vulnerability in index.php in Hi Web Wiesbaden Live Shopping Multi Portal System allows remote attackers to execute arbitrary SQL commands via the artikel parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 12 May 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.