Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,434 CVEs1,723 in CISA KEV17,397 with EPSS ≥ 10%25,049 with a public exploitUpdated 24 September 2026
25,049 results · page 196 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-1611 | Cross-site request forgery (CSRF) vulnerability in AlegroCart 1.1 allows remote attackers to hijack the authentication of the administrator for requests that reset the administrator password via a POST to admin/ with an update action. | EXPLOITMEDIUM 6.8EPSS 1.02% | 29 April 2010 |
| CVE-2009-4832 | The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80012010 request to the DLPCryptCore device. | EXPLOIT ✓HIGH 7.2EPSS 0.83% | 29 April 2010 |
| CVE-2010-1607 | Directory traversal vulnerability in wmi.php in the Webmoney Web Merchant Interface (aka WMI or com_wmi) component 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 8.18% | 29 April 2010 |
| CVE-2010-1606 | Multiple cross-site scripting (XSS) vulnerabilities in NCT Jobs Portal Script allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) Keywords, (3) Tags, or (4) Desired City field. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 29 April 2010 |
| CVE-2010-1604 | Multiple SQL injection vulnerabilities in admin_login.php in NCT Jobs Portal Script allow remote attackers to execute arbitrary SQL commands via the (1) user parameter (aka login field) and (2) passwd parameter (aka password field). | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 29 April 2010 |
| CVE-2010-1603 | Directory traversal vulnerability in the ZiMB Core (aka ZiMBCore or com_zimbcore) component 0.1 in the ZiMB Manager collection for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 7.40% | 29 April 2010 |
| CVE-2010-1602 | Directory traversal vulnerability in the ZiMB Comment (com_zimbcomment) component 0.8.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 15.7% | 29 April 2010 |
| CVE-2010-1601 | Directory traversal vulnerability in the JA Comment (com_jacomment) component for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 15.6% | 29 April 2010 |
| CVE-2010-1600 | SQL injection vulnerability in the Media Mall Factory (com_mediamall) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 29 April 2010 |
| CVE-2010-1599 | SQL injection vulnerability in loadorder.php in NKInFoWeb 2.5 and 5.2.2.0 allows remote attackers to execute arbitrary SQL commands via the id_sp parameter. | EXPLOITHIGH 7.5EPSS 0.97% | 29 April 2010 |
| CVE-2010-1597 | Stack-based buffer overflow in zgtips.dll in ZipGenius 6.3.1.2552 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing an entry with a long filename. | EXPLOIT ✓HIGH 9.3EPSS 11.9% | 29 April 2010 |
| CVE-2010-1591 | Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allows local users to gain privileges via crafted IOCTL requests to the (1) HookCont.sys, (2) HookNtos.sys,… | EXPLOITHIGH 7.2EPSS 1.62% | 28 April 2010 |
| CVE-2010-1587 | The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp. | EXPLOIT ✓MEDIUM 5.0EPSS 78.0% | 28 April 2010 |
| CVE-2010-1586 | Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the RedirectUrl parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 10.3% | 28 April 2010 |
| CVE-2010-0738 | Red Hat JBoss Authentication Bypass Vulnerability | KEVEXPLOIT ×4 ✓MEDIUM 5.3EPSS 79.4% | 28 April 2010 |
| CVE-2010-1559 | SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a speakerpopup action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 27 April 2010 |
| CVE-2010-0105 | The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption)… | EXPLOIT ✓MEDIUM 4.9EPSS 0.84% | 27 April 2010 |
| CVE-2009-4828 | Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an… | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 27 April 2010 |
| CVE-2009-4827 | Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a change action. | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 27 April 2010 |
| CVE-2009-4826 | Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for requests that alter administrative settings via a cp action. | EXPLOITMEDIUM 6.8EPSS 0.94% | 27 April 2010 |
| CVE-2009-4825 | 8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for App_Data/sb.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.46% | 27 April 2010 |
| CVE-2009-4823 | Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.73% | 27 April 2010 |
| CVE-2009-4822 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) uname parameters. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.46% | 27 April 2010 |
| CVE-2009-4820 | Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for veribaze/angelo.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.46% | 27 April 2010 |
| CVE-2009-4819 | Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file with a (1) .php.pgif or (2) .php.pjpeg double extension, then accessing it via a direct request to the… | EXPLOIT ✓MEDIUM 6.8EPSS 3.34% | 27 April 2010 |
| CVE-2009-4818 | Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. | EXPLOIT ✓MEDIUM 6.8EPSS 4.21% | 27 April 2010 |
| CVE-2009-4817 | Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/. | EXPLOIT ✓MEDIUM 6.8EPSS 3.37% | 27 April 2010 |
| CVE-2009-4816 | Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.72% | 27 April 2010 |
| CVE-2009-4814 | Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary web script or HTML via the URI to the MSP script. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 27 April 2010 |
| CVE-2009-4813 | Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a donate action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 27 April 2010 |
| CVE-2010-1544 | micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80. | EXPLOITMEDIUM 5.0EPSS 2.62% | 26 April 2010 |
| CVE-2010-1540 | Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 8.23% | 26 April 2010 |
| CVE-2010-1538 | SQL injection vulnerability in print_raincheck.php in phpRAINCHECK 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOITHIGH 7.5EPSS 0.97% | 26 April 2010 |
| CVE-2010-1537 | Multiple directory traversal vulnerabilities in phpCDB 1.0 and earlier allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 26 April 2010 |
| CVE-2010-1535 | Directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 15.3% | 26 April 2010 |
| CVE-2010-1534 | Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 13.6% | 26 April 2010 |
| CVE-2010-1533 | Directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 15.1% | 26 April 2010 |
| CVE-2010-1532 | Directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 16.3% | 26 April 2010 |
| CVE-2010-1531 | Directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 16.9% | 26 April 2010 |
| CVE-2010-1529 | SQL injection vulnerability in the Freestyle FAQs Lite (com_fsf) component, possibly 1.3, for Joomla! allows remote attackers to execute arbitrary SQL commands via the faqid parameter in an faq action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 26 April 2010 |
| CVE-2010-1528 | PHP remote file inclusion vulnerability in include/template.php in Uiga Proxy, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.96% | 26 April 2010 |
| CVE-2010-1499 | SQL injection vulnerability in genre_artists.php in MusicBox 3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOITHIGH 7.5EPSS 1.31% | 23 April 2010 |
| CVE-2010-1498 | Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) download.php and (2) view_file.php. | EXPLOIT ✓HIGH 7.5EPSS 2.17% | 23 April 2010 |
| CVE-2010-1497 | Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.38% | 23 April 2010 |
| CVE-2010-1496 | SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cardID parameter in a view action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.36% | 23 April 2010 |
| CVE-2010-1495 | Directory traversal vulnerability in the Matamko (com_matamko) component 1.01 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 18.9% | 23 April 2010 |
| CVE-2010-1494 | Directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 16.7% | 23 April 2010 |
| CVE-2010-1493 | SQL injection vulnerability in the AWDwall (com_awdwall) component before 1.5.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cbuser parameter in an awdwall action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 23 April 2010 |
| CVE-2010-1491 | Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 13.6% | 23 April 2010 |
| CVE-2010-1157 | Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm… | EXPLOIT ✓LOW 2.6EPSS 52.5% | 23 April 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.