SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-23 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,677 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026

25,049 results · page 195 of 501

CVESummaryPriorityPublished
CVE-2010-1737PHP remote file inclusion vulnerability in core/includes/gfw_smarty.php in Gallo 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[gfwroot] parameter.EXPLOITMEDIUM 6.8EPSS 1.97%6 May 2010
CVE-2010-1727SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the iType parameter.EXPLOITHIGH 7.5EPSS 1.00%6 May 2010
CVE-2010-1726SQL injection vulnerability in offers_buy.php in EC21 Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 0.99%6 May 2010
CVE-2010-1725SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 0.99%6 May 2010
CVE-2010-1724Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to…EXPLOIT ×2MEDIUM 4.3EPSS 4.10%6 May 2010
CVE-2010-1735The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage…EXPLOITMEDIUM 4.9EPSS 2.49%6 May 2010
CVE-2010-1734The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function…EXPLOITMEDIUM 4.9EPSS 2.66%6 May 2010
CVE-2010-1681Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.EXPLOIT ×2HIGH 7.6EPSS 67.3%6 May 2010
CVE-2010-1583SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in TaskFreak! before 0.6.3, allows remote attackers to execute arbitrary SQL commands via the username field…EXPLOITHIGH 7.5EPSS 2.04%6 May 2010
CVE-2009-4841Heap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the DiskType method.EXPLOITHIGH 9.3EPSS 7.30%6 May 2010
CVE-2009-4840Heap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the SetIAPlayerName method.EXPLOITHIGH 9.3EPSS 7.98%6 May 2010
CVE-2009-4836Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the anticode parameter.EXPLOITHIGH 7.5EPSS 5.59%6 May 2010
CVE-2010-1686Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC Backup Pro 5.20 and ABC Backup 5.50, allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP archive.EXPLOITHIGH 9.3EPSS 5.29%5 May 2010
CVE-2010-1723Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITMEDIUM 6.8EPSS 8.41%4 May 2010
CVE-2010-1722Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITMEDIUM 6.8EPSS 9.47%4 May 2010
CVE-2010-1721SQL injection vulnerability in the Intellectual Property (aka IProperty or com_iproperty) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an agentproperties action to index.php.EXPLOITHIGH 7.5EPSS 1.20%4 May 2010
CVE-2010-1720SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the katid parameter in a qpListele action to index.php.EXPLOIT ×2HIGH 7.5EPSS 1.16%4 May 2010
CVE-2010-1719Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITMEDIUM 6.8EPSS 9.37%4 May 2010
CVE-2010-1718Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a ..EXPLOITMEDIUM 6.8EPSS 9.46%4 May 2010
CVE-2010-1717Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITHIGH 7.5EPSS 22.3%4 May 2010
CVE-2010-1716SQL injection vulnerability in the Agenda Address Book (com_agenda) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.EXPLOITHIGH 7.5EPSS 1.15%4 May 2010
CVE-2010-1715Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 6.8EPSS 8.18%4 May 2010
CVE-2010-1714Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 18.7%4 May 2010
CVE-2010-1713SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action.EXPLOITHIGH 7.5EPSS 1.99%4 May 2010
CVE-2010-1712Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and possibly (2) message parameters.EXPLOITMEDIUM 4.3EPSS 1.91%4 May 2010
CVE-2010-1711Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the usuario parameter.EXPLOITMEDIUM 4.3EPSS 1.72%4 May 2010
CVE-2010-1710Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOITMEDIUM 6.8EPSS 2.30%4 May 2010
CVE-2010-1708Multiple SQL injection vulnerabilities in agentadmin.php in Free Realty allow remote attackers to execute arbitrary SQL commands via the (1) login field (aka agentname parameter) or (2) password field (aka agentpassword parameter).EXPLOITHIGH 7.5EPSS 0.97%4 May 2010
CVE-2010-1706Multiple SQL injection vulnerabilities in login.php in 2daybiz Auction Script allow remote attackers to execute arbitrary SQL commands via (1) the login field (aka the username parameter), and possibly (2) the password field, to index.php.EXPLOITHIGH 7.5EPSS 1.19%4 May 2010
CVE-2010-1705SQL injection vulnerability in casting_view.php in Modelbook allows remote attackers to execute arbitrary SQL commands via the adnum parameter.EXPLOITHIGH 7.5EPSS 0.96%4 May 2010
CVE-2010-1704Multiple SQL injection vulnerabilities in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to execute arbitrary SQL commands via (1) the password field to login.php, (2) the login field (aka email parameter) to login.php, (3) the password…EXPLOITHIGH 7.5EPSS 1.15%4 May 2010
CVE-2010-1703Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.EXPLOITMEDIUM 4.3EPSS 1.72%4 May 2010
CVE-2010-1702SQL injection vulnerability in submitticket.php in WHMCompleteSolution (WHMCS) 4.2 allows remote attackers to execute arbitrary SQL commands via the deptid parameter.EXPLOITHIGH 7.5EPSS 0.97%4 May 2010
CVE-2010-1701SQL injection vulnerability in browse.html in PHP Video Battle Script allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOITHIGH 7.5EPSS 0.96%4 May 2010
CVE-2010-1687Stack-based buffer overflow in lpd.exe in Mocha W32 LPD 1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted "recieve jobs" request.EXPLOITMEDIUM 5.0EPSS 5.15%4 May 2010
CVE-2010-1685Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename.EXPLOITHIGH 9.3EPSS 8.56%4 May 2010
CVE-2010-1431SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.EXPLOITHIGH 7.5EPSS 3.80%4 May 2010
CVE-2009-4834lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php.EXPLOITMEDIUM 6.8EPSS 4.02%4 May 2010
CVE-2010-1663The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.EXPLOITHIGH 10.0EPSS 54.1%3 May 2010
CVE-2010-1662Cross-site scripting (XSS) vulnerability in acpmoderate.php in PHP-Quick-Arcade (PHPQA) 3.0.21 allows remote attackers to inject arbitrary web script or HTML via the serv parameter.EXPLOITMEDIUM 4.3EPSS 1.50%3 May 2010
CVE-2010-1661Multiple SQL injection vulnerabilities in PHP-Quick-Arcade (PHPQA) 3.0.21 allow remote attackers to execute arbitrary SQL commands via the (1) phpqa_user_c parameter to Arcade.php and the (2) id parameter to acpmoderate.php.EXPLOITHIGH 7.5EPSS 1.00%3 May 2010
CVE-2010-1660SQL injection vulnerability in help-details.php in CLScript Classifieds Script allows remote attackers to execute arbitrary SQL commands via the hpId parameter.EXPLOITHIGH 7.5EPSS 1.15%3 May 2010
CVE-2010-1659Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 14.0%3 May 2010
CVE-2010-1658Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITMEDIUM 5.0EPSS 16.0%3 May 2010
CVE-2010-1657Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 19.2%3 May 2010
CVE-2010-1656SQL injection vulnerability in the Airiny ABC (com_abc) component 1.1.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sectionid parameter in an abc action to index.php.EXPLOITHIGH 7.5EPSS 1.00%3 May 2010
CVE-2010-1654Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters.EXPLOITHIGH 7.5EPSS 1.00%3 May 2010
CVE-2010-1653Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a ..EXPLOITHIGH 7.5EPSS 13.4%3 May 2010
CVE-2010-1652Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOITMEDIUM 5.0EPSS 2.86%3 May 2010
CVE-2010-0817Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via…EXPLOITMEDIUM 4.3EPSS 28.7%29 April 2010

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.