SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-24 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,434 CVEs1,723 in CISA KEV17,397 with EPSS ≥ 10%25,049 with a public exploitUpdated 24 September 2026

25,049 results · page 196 of 501

CVESummaryPriorityPublished
CVE-2010-1611Cross-site request forgery (CSRF) vulnerability in AlegroCart 1.1 allows remote attackers to hijack the authentication of the administrator for requests that reset the administrator password via a POST to admin/ with an update action.EXPLOITMEDIUM 6.8EPSS 1.02%29 April 2010
CVE-2009-4832The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80012010 request to the DLPCryptCore device.EXPLOIT ✓HIGH 7.2EPSS 0.83%29 April 2010
CVE-2010-1607Directory traversal vulnerability in wmi.php in the Webmoney Web Merchant Interface (aka WMI or com_wmi) component 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 8.18%29 April 2010
CVE-2010-1606Multiple cross-site scripting (XSS) vulnerabilities in NCT Jobs Portal Script allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) Keywords, (3) Tags, or (4) Desired City field.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%29 April 2010
CVE-2010-1604Multiple SQL injection vulnerabilities in admin_login.php in NCT Jobs Portal Script allow remote attackers to execute arbitrary SQL commands via the (1) user parameter (aka login field) and (2) passwd parameter (aka password field).EXPLOIT ✓MEDIUM 6.8EPSS 0.91%29 April 2010
CVE-2010-1603Directory traversal vulnerability in the ZiMB Core (aka ZiMBCore or com_zimbcore) component 0.1 in the ZiMB Manager collection for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOIT ✓HIGH 7.5EPSS 7.40%29 April 2010
CVE-2010-1602Directory traversal vulnerability in the ZiMB Comment (com_zimbcomment) component 0.8.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOIT ✓HIGH 7.5EPSS 15.7%29 April 2010
CVE-2010-1601Directory traversal vulnerability in the JA Comment (com_jacomment) component for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 15.6%29 April 2010
CVE-2010-1600SQL injection vulnerability in the Media Mall Factory (com_mediamall) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.19%29 April 2010
CVE-2010-1599SQL injection vulnerability in loadorder.php in NKInFoWeb 2.5 and 5.2.2.0 allows remote attackers to execute arbitrary SQL commands via the id_sp parameter.EXPLOITHIGH 7.5EPSS 0.97%29 April 2010
CVE-2010-1597Stack-based buffer overflow in zgtips.dll in ZipGenius 6.3.1.2552 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing an entry with a long filename.EXPLOIT ✓HIGH 9.3EPSS 11.9%29 April 2010
CVE-2010-1591Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allows local users to gain privileges via crafted IOCTL requests to the (1) HookCont.sys, (2) HookNtos.sys,…EXPLOITHIGH 7.2EPSS 1.62%28 April 2010
CVE-2010-1587The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.EXPLOIT ✓MEDIUM 5.0EPSS 78.0%28 April 2010
CVE-2010-1586Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the RedirectUrl parameter.EXPLOIT ✓MEDIUM 4.3EPSS 10.3%28 April 2010
CVE-2010-0738Red Hat JBoss Authentication Bypass VulnerabilityKEVEXPLOIT ×4 ✓MEDIUM 5.3EPSS 79.4%28 April 2010
CVE-2010-1559SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a speakerpopup action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.95%27 April 2010
CVE-2010-0105The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption)…EXPLOIT ✓MEDIUM 4.9EPSS 0.84%27 April 2010
CVE-2009-4828Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an…EXPLOIT ✓MEDIUM 6.8EPSS 0.94%27 April 2010
CVE-2009-4827Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a change action.EXPLOIT ✓MEDIUM 6.8EPSS 0.94%27 April 2010
CVE-2009-4826Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for requests that alter administrative settings via a cp action.EXPLOITMEDIUM 6.8EPSS 0.94%27 April 2010
CVE-2009-48258pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for App_Data/sb.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.46%27 April 2010
CVE-2009-4823Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.73%27 April 2010
CVE-2009-4822Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) uname parameters.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.46%27 April 2010
CVE-2009-4820Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for veribaze/angelo.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.46%27 April 2010
CVE-2009-4819Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file with a (1) .php.pgif or (2) .php.pjpeg double extension, then accessing it via a direct request to the…EXPLOIT ✓MEDIUM 6.8EPSS 3.34%27 April 2010
CVE-2009-4818Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif.EXPLOIT ✓MEDIUM 6.8EPSS 4.21%27 April 2010
CVE-2009-4817Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/.EXPLOIT ✓MEDIUM 6.8EPSS 3.37%27 April 2010
CVE-2009-4816Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.72%27 April 2010
CVE-2009-4814Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary web script or HTML via the URI to the MSP script.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%27 April 2010
CVE-2009-4813Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a donate action.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%27 April 2010
CVE-2010-1544micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80.EXPLOITMEDIUM 5.0EPSS 2.62%26 April 2010
CVE-2010-1540Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 8.23%26 April 2010
CVE-2010-1538SQL injection vulnerability in print_raincheck.php in phpRAINCHECK 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 0.97%26 April 2010
CVE-2010-1537Multiple directory traversal vulnerabilities in phpCDB 1.0 and earlier allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.29%26 April 2010
CVE-2010-1535Directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOIT ✓HIGH 7.5EPSS 15.3%26 April 2010
CVE-2010-1534Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 13.6%26 April 2010
CVE-2010-1533Directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.5EPSS 15.1%26 April 2010
CVE-2010-1532Directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOIT ✓MEDIUM 5.0EPSS 16.3%26 April 2010
CVE-2010-1531Directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.5EPSS 16.9%26 April 2010
CVE-2010-1529SQL injection vulnerability in the Freestyle FAQs Lite (com_fsf) component, possibly 1.3, for Joomla! allows remote attackers to execute arbitrary SQL commands via the faqid parameter in an faq action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.14%26 April 2010
CVE-2010-1528PHP remote file inclusion vulnerability in include/template.php in Uiga Proxy, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.96%26 April 2010
CVE-2010-1499SQL injection vulnerability in genre_artists.php in MusicBox 3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOITHIGH 7.5EPSS 1.31%23 April 2010
CVE-2010-1498Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) download.php and (2) view_file.php.EXPLOIT ✓HIGH 7.5EPSS 2.17%23 April 2010
CVE-2010-1497Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOIT ✓MEDIUM 4.3EPSS 2.38%23 April 2010
CVE-2010-1496SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cardID parameter in a view action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.36%23 April 2010
CVE-2010-1495Directory traversal vulnerability in the Matamko (com_matamko) component 1.01 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.5EPSS 18.9%23 April 2010
CVE-2010-1494Directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 16.7%23 April 2010
CVE-2010-1493SQL injection vulnerability in the AWDwall (com_awdwall) component before 1.5.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cbuser parameter in an awdwall action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.19%23 April 2010
CVE-2010-1491Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..EXPLOIT ✓MEDIUM 5.0EPSS 13.6%23 April 2010
CVE-2010-1157Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm…EXPLOIT ✓LOW 2.6EPSS 52.5%23 April 2010

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.