SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,677 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 193 of 501

CVESummaryPriorityPublished
CVE-2010-2032Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1)…EXPLOITMEDIUM 4.3EPSS 3.36%24 May 2010
CVE-2010-2031KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVSafe device.EXPLOITHIGH 7.2EPSS 0.75%24 May 2010
CVE-2010-2028Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long transport mode.EXPLOIT ×2HIGH 10.0EPSS 13.9%24 May 2010
CVE-2010-1688Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attackers to execute arbitrary code via a long filename in a (1) .sps or (2) zip profile.EXPLOITHIGH 9.3EPSS 15.0%24 May 2010
CVE-2010-2018Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 3.26%24 May 2010
CVE-2010-2016SQL injection vulnerability in details.php in Iceberg CMS allows remote attackers to execute arbitrary SQL commands via the p_id parameter.EXPLOITHIGH 7.5EPSS 1.15%24 May 2010
CVE-2010-2015Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a view_inbox action to cp/cp_messages.php or (2) the id parameter to cp/edit_email.php.EXPLOITMEDIUM 6.8EPSS 0.90%24 May 2010
CVE-2010-2006Directory traversal vulnerability in op/op.Login.php in LetoDMS (formerly MyDMS) 1.7.2 and earlier allows remote authenticated users to include and execute arbitrary local files via a ..EXPLOITMEDIUM 6.5EPSS 6.69%20 May 2010
CVE-2010-2005Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the selected_language parameter to engine/inc/include/init.php, (2) the config[langs] parameter to…EXPLOIT ×4HIGH 7.5EPSS 2.81%20 May 2010
CVE-2010-2004Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via the Skin parameter in the Options section of a skins file (.bsi), a different…EXPLOIT ×2HIGH 9.3EPSS 9.32%20 May 2010
CVE-2010-2003Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject arbitrary web script or HTML via the mysql_host parameter.EXPLOITMEDIUM 4.3EPSS 2.00%20 May 2010
CVE-2010-1999Directory traversal vulnerability in scr/soustab.php in OpenMairie Opencatalogue 1.024, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype]…EXPLOITMEDIUM 6.8EPSS 2.23%20 May 2010
CVE-2010-1997Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter.EXPLOITLOW 2.1EPSS 3.38%20 May 2010
CVE-2010-1994SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the q parameter in conjunction with a /news/search PATH_INFO.EXPLOITHIGH 7.5EPSS 1.18%20 May 2010
CVE-2010-1039Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to…EXPLOITHIGH 10.0EPSS 20.2%20 May 2010
CVE-2010-1983Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 18.8%19 May 2010
CVE-2010-1982Directory traversal vulnerability in the JA Voice (com_javoice) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 9.08%19 May 2010
CVE-2010-1981Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 6.8EPSS 11.9%19 May 2010
CVE-2010-1980Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla! allows remote attackers to include and execute arbitrary local files via a ..EXPLOITHIGH 7.5EPSS 18.8%19 May 2010
CVE-2010-1979Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 6.8EPSS 11.2%19 May 2010
CVE-2010-1977Directory traversal vulnerability in the J!WHMCS Integrator (com_jwhmcs) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 7.40%19 May 2010
CVE-2010-1948Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter,…EXPLOITMEDIUM 6.8EPSS 4.16%19 May 2010
CVE-2010-1947Directory traversal vulnerability in scr/soustab.php in openMairie Openregistrecil 1.02, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype]…EXPLOITMEDIUM 6.8EPSS 4.74%19 May 2010
CVE-2010-1946Multiple PHP remote file inclusion vulnerabilities in openMairie Openregistrecil 1.02, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) autorisation_normale.class.php, (2)…EXPLOITMEDIUM 6.8EPSS 5.83%19 May 2010
CVE-2010-1945Multiple PHP remote file inclusion vulnerabilities in openMairie Openfoncier 2.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) action.class.php, (2)…EXPLOITMEDIUM 6.8EPSS 5.18%19 May 2010
CVE-2010-1944Multiple PHP remote file inclusion vulnerabilities in openMairie openCimetiere 2.01, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) autorisation.class.php, (2)…EXPLOITMEDIUM 6.8EPSS 5.83%19 May 2010
CVE-2010-1957Directory traversal vulnerability in the Love Factory (com_lovefactory) component 1.3.4 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 14.8%19 May 2010
CVE-2010-1956Directory traversal vulnerability in the Gadget Factory (com_gadgetfactory) component 1.0.0 and 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 17.0%19 May 2010
CVE-2010-1955Directory traversal vulnerability in the Deluxe Blog Factory (com_blogfactory) component 1.1.2 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 17.9%19 May 2010
CVE-2010-1954Directory traversal vulnerability in the iNetLanka Multiple root (com_multiroot) component 1.0 and 1.1 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 16.2%19 May 2010
CVE-2010-1953Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 16.2%19 May 2010
CVE-2010-1952Directory traversal vulnerability in the BeeHeard (com_beeheard) and BeeHeard Lite (com_beeheardlite) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 13.0%19 May 2010
CVE-2010-1951Multiple directory traversal vulnerabilities in 60cycleCMS allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the DOCUMENT_ROOT parameter to (1) news.php, (2) submitComment.php, and (3) sqlConnect.php.EXPLOITMEDIUM 6.8EPSS 7.48%19 May 2010
CVE-2010-1950SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php.EXPLOITMEDIUM 6.8EPSS 1.60%19 May 2010
CVE-2010-1949SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.EXPLOITHIGH 7.5EPSS 1.83%19 May 2010
CVE-2010-0475Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.EXPLOITMEDIUM 4.3EPSS 3.82%14 May 2010
CVE-2010-1939Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers…EXPLOIT ×2HIGH 7.6EPSS 14.7%13 May 2010
CVE-2010-1555Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid Hostname parameter.EXPLOIT ×2HIGH 10.0EPSS 62.4%13 May 2010
CVE-2010-1554Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid iCount parameter.EXPLOIT ×2HIGH 10.0EPSS 65.9%13 May 2010
CVE-2010-1553Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid MaxAge parameter.EXPLOIT ×2HIGH 10.0EPSS 70.6%13 May 2010
CVE-2010-1552Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the act and app parameters.EXPLOITHIGH 10.0EPSS 67.1%13 May 2010
CVE-2010-1280Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file.EXPLOITHIGH 8.8EPSS 16.6%13 May 2010
CVE-2010-1936Directory traversal vulnerability in scr/soustab.php in openMairie openComInterne 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype]…EXPLOITMEDIUM 6.8EPSS 1.96%12 May 2010
CVE-2010-1935Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a…EXPLOITMEDIUM 6.8EPSS 1.96%12 May 2010
CVE-2010-1934Multiple PHP remote file inclusion vulnerabilities in openMairie openPlanning 1.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) categorie.class.php, (2)…EXPLOITMEDIUM 6.8EPSS 2.90%12 May 2010
CVE-2010-1928Directory traversal vulnerability in scr/soustab.php in openMairie openPlanning 1.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter,…EXPLOITMEDIUM 6.8EPSS 1.96%12 May 2010
CVE-2010-1927Multiple PHP remote file inclusion vulnerabilities in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) bible.class.php, (2)…EXPLOITMEDIUM 6.8EPSS 3.22%12 May 2010
CVE-2010-1926Directory traversal vulnerability in scr/soustab.php in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the…EXPLOITMEDIUM 6.8EPSS 1.97%12 May 2010
CVE-2010-1925SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-2817.EXPLOITHIGH 7.5EPSS 1.00%12 May 2010
CVE-2010-1924SQL injection vulnerability in index.php in Hi Web Wiesbaden Live Shopping Multi Portal System allows remote attackers to execute arbitrary SQL commands via the artikel parameter.EXPLOITHIGH 7.5EPSS 1.00%12 May 2010

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.