Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,677 CVEs1,721 in CISA KEV17,395 with EPSS ≥ 10%25,049 with a public exploitUpdated 23 September 2026
25,049 results · page 195 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-1737 | PHP remote file inclusion vulnerability in core/includes/gfw_smarty.php in Gallo 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[gfwroot] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.97% | 6 May 2010 |
| CVE-2010-1727 | SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the iType parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 6 May 2010 |
| CVE-2010-1726 | SQL injection vulnerability in offers_buy.php in EC21 Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 6 May 2010 |
| CVE-2010-1725 | SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 6 May 2010 |
| CVE-2010-1724 | Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 4.10% | 6 May 2010 |
| CVE-2010-1735 | The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage… | EXPLOITMEDIUM 4.9EPSS 2.49% | 6 May 2010 |
| CVE-2010-1734 | The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function… | EXPLOITMEDIUM 4.9EPSS 2.66% | 6 May 2010 |
| CVE-2010-1681 | Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256. | EXPLOIT ×2 ✓HIGH 7.6EPSS 67.3% | 6 May 2010 |
| CVE-2010-1583 | SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in TaskFreak! before 0.6.3, allows remote attackers to execute arbitrary SQL commands via the username field… | EXPLOIT ✓HIGH 7.5EPSS 2.04% | 6 May 2010 |
| CVE-2009-4841 | Heap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the DiskType method. | EXPLOIT ✓HIGH 9.3EPSS 7.30% | 6 May 2010 |
| CVE-2009-4840 | Heap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the SetIAPlayerName method. | EXPLOIT ✓HIGH 9.3EPSS 7.98% | 6 May 2010 |
| CVE-2009-4836 | Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the anticode parameter. | EXPLOIT ✓HIGH 7.5EPSS 5.59% | 6 May 2010 |
| CVE-2010-1686 | Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC Backup Pro 5.20 and ABC Backup 5.50, allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP archive. | EXPLOIT ✓HIGH 9.3EPSS 5.29% | 5 May 2010 |
| CVE-2010-1723 | Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 8.41% | 4 May 2010 |
| CVE-2010-1722 | Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 9.47% | 4 May 2010 |
| CVE-2010-1721 | SQL injection vulnerability in the Intellectual Property (aka IProperty or com_iproperty) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an agentproperties action to index.php. | EXPLOITHIGH 7.5EPSS 1.20% | 4 May 2010 |
| CVE-2010-1720 | SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the katid parameter in a qpListele action to index.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.16% | 4 May 2010 |
| CVE-2010-1719 | Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 9.37% | 4 May 2010 |
| CVE-2010-1718 | Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 9.46% | 4 May 2010 |
| CVE-2010-1717 | Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 22.3% | 4 May 2010 |
| CVE-2010-1716 | SQL injection vulnerability in the Agenda Address Book (com_agenda) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. | EXPLOITHIGH 7.5EPSS 1.15% | 4 May 2010 |
| CVE-2010-1715 | Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 8.18% | 4 May 2010 |
| CVE-2010-1714 | Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 18.7% | 4 May 2010 |
| CVE-2010-1713 | SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action. | EXPLOIT ✓HIGH 7.5EPSS 1.99% | 4 May 2010 |
| CVE-2010-1712 | Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and possibly (2) message parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.91% | 4 May 2010 |
| CVE-2010-1711 | Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the usuario parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 4 May 2010 |
| CVE-2010-1710 | Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.30% | 4 May 2010 |
| CVE-2010-1708 | Multiple SQL injection vulnerabilities in agentadmin.php in Free Realty allow remote attackers to execute arbitrary SQL commands via the (1) login field (aka agentname parameter) or (2) password field (aka agentpassword parameter). | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 4 May 2010 |
| CVE-2010-1706 | Multiple SQL injection vulnerabilities in login.php in 2daybiz Auction Script allow remote attackers to execute arbitrary SQL commands via (1) the login field (aka the username parameter), and possibly (2) the password field, to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 4 May 2010 |
| CVE-2010-1705 | SQL injection vulnerability in casting_view.php in Modelbook allows remote attackers to execute arbitrary SQL commands via the adnum parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 4 May 2010 |
| CVE-2010-1704 | Multiple SQL injection vulnerabilities in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to execute arbitrary SQL commands via (1) the password field to login.php, (2) the login field (aka email parameter) to login.php, (3) the password… | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 4 May 2010 |
| CVE-2010-1703 | Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 4 May 2010 |
| CVE-2010-1702 | SQL injection vulnerability in submitticket.php in WHMCompleteSolution (WHMCS) 4.2 allows remote attackers to execute arbitrary SQL commands via the deptid parameter. | EXPLOITHIGH 7.5EPSS 0.97% | 4 May 2010 |
| CVE-2010-1701 | SQL injection vulnerability in browse.html in PHP Video Battle Script allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 4 May 2010 |
| CVE-2010-1687 | Stack-based buffer overflow in lpd.exe in Mocha W32 LPD 1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted "recieve jobs" request. | EXPLOIT ✓MEDIUM 5.0EPSS 5.15% | 4 May 2010 |
| CVE-2010-1685 | Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename. | EXPLOIT ✓HIGH 9.3EPSS 8.56% | 4 May 2010 |
| CVE-2010-1431 | SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.80% | 4 May 2010 |
| CVE-2009-4834 | lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php. | EXPLOIT ✓MEDIUM 6.8EPSS 4.02% | 4 May 2010 |
| CVE-2010-1663 | The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 54.1% | 3 May 2010 |
| CVE-2010-1662 | Cross-site scripting (XSS) vulnerability in acpmoderate.php in PHP-Quick-Arcade (PHPQA) 3.0.21 allows remote attackers to inject arbitrary web script or HTML via the serv parameter. | EXPLOITMEDIUM 4.3EPSS 1.50% | 3 May 2010 |
| CVE-2010-1661 | Multiple SQL injection vulnerabilities in PHP-Quick-Arcade (PHPQA) 3.0.21 allow remote attackers to execute arbitrary SQL commands via the (1) phpqa_user_c parameter to Arcade.php and the (2) id parameter to acpmoderate.php. | EXPLOITHIGH 7.5EPSS 1.00% | 3 May 2010 |
| CVE-2010-1660 | SQL injection vulnerability in help-details.php in CLScript Classifieds Script allows remote attackers to execute arbitrary SQL commands via the hpId parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 3 May 2010 |
| CVE-2010-1659 | Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 14.0% | 3 May 2010 |
| CVE-2010-1658 | Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 16.0% | 3 May 2010 |
| CVE-2010-1657 | Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 19.2% | 3 May 2010 |
| CVE-2010-1656 | SQL injection vulnerability in the Airiny ABC (com_abc) component 1.1.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sectionid parameter in an abc action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 3 May 2010 |
| CVE-2010-1654 | Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 3 May 2010 |
| CVE-2010-1653 | Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. | EXPLOITHIGH 7.5EPSS 13.4% | 3 May 2010 |
| CVE-2010-1652 | Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.86% | 3 May 2010 |
| CVE-2010-0817 | Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via… | EXPLOIT ✓MEDIUM 4.3EPSS 28.7% | 29 April 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.