Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,677 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 194 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-1923 | SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 May 2010 |
| CVE-2010-1922 | Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the LibDir parameter to (1) lib/page/pageDescriptionObject.php, and (2) layoutHeaderFuncs.php, (3) layoutManager.php,… | EXPLOITHIGH 7.5EPSS 2.49% | 12 May 2010 |
| CVE-2010-1921 | Multiple PHP remote file inclusion vulnerabilities in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) annuaire.class.php, (2) droit.class.php,… | EXPLOIT ✓MEDIUM 6.8EPSS 3.22% | 12 May 2010 |
| CVE-2010-1920 | Directory traversal vulnerability in scr/soustab.php in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter,… | EXPLOIT ✓MEDIUM 6.8EPSS 2.02% | 12 May 2010 |
| CVE-2010-1457 | Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 allows local users to read arbitrary files via a (1) -c or (2) -a option, which prints file contents in an error message. | EXPLOIT ✓MEDIUM 4.9EPSS 0.86% | 12 May 2010 |
| CVE-2010-0816 | Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and… | EXPLOIT ✓HIGH 9.3EPSS 20.3% | 12 May 2010 |
| CVE-2010-1918 | SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 12 May 2010 |
| CVE-2010-1869 | Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file. | EXPLOIT ✓HIGH 9.3EPSS 9.27% | 12 May 2010 |
| CVE-2010-1905 | Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inject arbitrary web script or HTML via crafted input to ASP pages, as demonstrated using the backurl… | EXPLOIT ✓MEDIUM 4.3EPSS 2.48% | 12 May 2010 |
| CVE-2010-1878 | Directory traversal vulnerability in the OrgChart (com_orgchart) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 11.4% | 12 May 2010 |
| CVE-2010-1877 | SQL injection vulnerability in the JTM Reseller (com_jtm) component 1.9 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the author parameter in a search action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 May 2010 |
| CVE-2010-1876 | SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 May 2010 |
| CVE-2010-1875 | Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 15.7% | 12 May 2010 |
| CVE-2010-1874 | SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. | EXPLOITHIGH 7.5EPSS 2.00% | 12 May 2010 |
| CVE-2010-1873 | SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.05% | 12 May 2010 |
| CVE-2010-1872 | Cross-site scripting (XSS) vulnerability in cPlayer.php in FlashCard 2.6.5 and 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.61% | 12 May 2010 |
| CVE-2009-4872 | Multiple SQL injection vulnerabilities in globepersonnel_login.asp in Logoshows BBS 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 11 May 2010 |
| CVE-2009-4871 | SQL injection vulnerability in globepersonnel_forum.asp in Logoshows BBS 2.0 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 11 May 2010 |
| CVE-2009-4870 | Multiple SQL injection vulnerabilities in login.php in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the (1) req_username (aka Username) and (2) req_password (aka Password) parameters. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 11 May 2010 |
| CVE-2009-4869 | Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 11 May 2010 |
| CVE-2009-4868 | Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id parameter to the answers script (aka answers.php). | EXPLOIT ✓MEDIUM 4.3EPSS 1.27% | 11 May 2010 |
| CVE-2009-4867 | Buffer overflow in Tuniac 090517c allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long URL in a .m3u playlist file. | EXPLOIT ✓MEDIUM 4.3EPSS 4.43% | 11 May 2010 |
| CVE-2009-4864 | Multiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script allow remote attackers to inject arbitrary web script or HTML via the (1) search_name and (2) languages parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.24% | 11 May 2010 |
| CVE-2009-4863 | Stack-based buffer overflow in UltraPlayer Media Player 2.112 allows remote attackers to execute arbitrary code via a long string in a .usk file. | EXPLOIT ✓HIGH 9.3EPSS 5.76% | 11 May 2010 |
| CVE-2009-4862 | Multiple SQL injection vulnerabilities in Alwasel 1.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) show.php and (2) xml.php. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 11 May 2010 |
| CVE-2009-4860 | SQL injection vulnerability in demo.php in Typing Pal 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idTableProduit parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 11 May 2010 |
| CVE-2009-4858 | Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.27% | 11 May 2010 |
| CVE-2009-4857 | Cross-site scripting (XSS) vulnerability in login.php in PHP Photo Vote 1.3F allows remote attackers to inject arbitrary web script or HTML via the page parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 11 May 2010 |
| CVE-2009-4856 | Cross-site scripting (XSS) vulnerability in subitems.php in PHP Easy Shopping Cart 3.1R allows remote attackers to inject arbitrary web script or HTML via the name parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 11 May 2010 |
| CVE-2009-4855 | SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 11 May 2010 |
| CVE-2010-1866 | The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative chunk size, which bypasses a signed… | EXPLOIT ✓CRITICAL 9.8EPSS 6.72% | 7 May 2010 |
| CVE-2010-1859 | SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the membercookie cookie when adding a new thread. | EXPLOIT ✓MEDIUM 6.8EPSS 0.83% | 7 May 2010 |
| CVE-2009-4854 | addons/import.php in TalkBack 2.3.14 allows remote attackers to execute arbitrary commands via the result parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.12% | 7 May 2010 |
| CVE-2010-1858 | Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php. | EXPLOIT ✓MEDIUM 5.0EPSS 13.6% | 7 May 2010 |
| CVE-2010-1856 | Cross-site scripting (XSS) vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the prod parameter in a products.details action. | EXPLOIT ✓LOW 2.6EPSS 1.50% | 7 May 2010 |
| CVE-2010-1855 | SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arbitrary SQL commands via the id_auk parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.59% | 7 May 2010 |
| CVE-2010-1437 | Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via… | EXPLOIT ✓HIGH 7.0EPSS 0.66% | 7 May 2010 |
| CVE-2010-1173 | The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invalid… | EXPLOIT ✓HIGH 7.1EPSS 21.2% | 7 May 2010 |
| CVE-2009-4850 | The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneURL property value with a URL for a .exe file. | EXPLOIT ✓HIGH 9.3EPSS 24.7% | 7 May 2010 |
| CVE-2009-4849 | Multiple cross-site request forgery (CSRF) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new user account via a save… | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 7 May 2010 |
| CVE-2010-1549 | Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors. | EXPLOIT ✓HIGH 10.0EPSS 77.6% | 7 May 2010 |
| CVE-2010-1453 | Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.99% | 7 May 2010 |
| CVE-2010-1143 | Cross-site scripting (XSS) vulnerability in VMware View (formerly Virtual Desktop Manager or VDM) 3.1.x before 3.1.3 build 252693 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.44% | 7 May 2010 |
| CVE-2010-1746 | Multiple cross-site scripting (XSS) vulnerabilities in the Table JX (com_grid) component for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) data_search and (2) rpp parameters to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 6 May 2010 |
| CVE-2010-1744 | SQL injection vulnerability in product.html in B2B Gold Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 6 May 2010 |
| CVE-2010-1743 | SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 6 May 2010 |
| CVE-2010-1742 | Cross-site scripting (XSS) vulnerability in projects.php in Scratcher allows remote attackers to inject arbitrary web script or HTML via the show parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 6 May 2010 |
| CVE-2010-1741 | SQL injection vulnerability in request_account.php in Billwerx RC 5.2.2 PL2 allows remote attackers to execute arbitrary SQL commands via the primary_number parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 6 May 2010 |
| CVE-2010-1740 | SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands via the lng parameter. | EXPLOITHIGH 7.5EPSS 1.99% | 6 May 2010 |
| CVE-2010-1739 | SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the feedid parameter in a categories action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 6 May 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.