Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,434 CVEs1,723 in CISA KEV17,397 with EPSS ≥ 10%25,049 with a public exploitUpdated 24 September 2026
25,049 results · page 198 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-1461 | Directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via the view parameter to index.php. | EXPLOIT ✓MEDIUM 5.0EPSS 8.23% | 16 April 2010 |
| CVE-2010-1460 | The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with… | EXPLOIT ✓MEDIUM 5.0EPSS 2.77% | 16 April 2010 |
| CVE-2010-1423 | Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code… | EXPLOIT ✓HIGH 9.3EPSS 55.6% | 15 April 2010 |
| CVE-2010-0432 | Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 22.9% | 15 April 2010 |
| CVE-2010-1316 | Multiple stack-based buffer overflows in Tembria Server Monitor before 5.6.1 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted (1) GET, (2) PUT, or (3) HEAD request, as demonstrated by a… | EXPLOIT ✓MEDIUM 5.0EPSS 9.69% | 14 April 2010 |
| CVE-2010-0480 | Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted… | EXPLOIT ×3 ✓HIGH 9.3EPSS 67.9% | 14 April 2010 |
| CVE-2010-0478 | Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media… | EXPLOIT ✓HIGH 9.3EPSS 60.4% | 14 April 2010 |
| CVE-2010-0477 | The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that… | EXPLOIT ✓HIGH 10.0EPSS 50.2% | 14 April 2010 |
| CVE-2010-0476 | The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and… | EXPLOIT ✓HIGH 10.0EPSS 34.3% | 14 April 2010 |
| CVE-2010-0270 | The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service… | EXPLOIT ✓HIGH 10.0EPSS 48.2% | 14 April 2010 |
| CVE-2010-0269 | The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows… | EXPLOIT ✓HIGH 10.0EPSS 28.4% | 14 April 2010 |
| CVE-2010-1372 | SQL injection vulnerability in the HD FLV Player (com_hdflvplayer) component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 13 April 2010 |
| CVE-2010-1369 | SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter. | EXPLOITHIGH 7.5EPSS 0.97% | 13 April 2010 |
| CVE-2010-1368 | SQL injection vulnerability in index.php in GameScript (GS) 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 13 April 2010 |
| CVE-2010-1366 | Multiple SQL injection vulnerabilities in admin/admin_login.php in Uiga Fan Club 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin_name and (2) admin_password parameters. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 13 April 2010 |
| CVE-2010-1365 | SQL injection vulnerability in index.php in Uiga Fan Club, as downloaded on 20100310, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01% | 13 April 2010 |
| CVE-2010-1364 | SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.98% | 13 April 2010 |
| CVE-2010-1363 | SQL injection vulnerability in the JProjects (com_j-projects) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the project parameter in a projects action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 13 April 2010 |
| CVE-2010-1361 | Cross-site scripting (XSS) vulnerability in shop/USER_ARTIKEL_HANDLING_AUFRUF.php in PHPepperShop 2.5 allows remote attackers to inject arbitrary web script or HTML via the darstellen parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.49% | 13 April 2010 |
| CVE-2010-1360 | Multiple PHP remote file inclusion vulnerabilities in FAQEngine 4.24.00 allow remote attackers to execute arbitrary PHP code via a URL in the path_faqe parameter to (1) attachs.php, (2) backup.php, (3) badwords.php, (4) categories.php, (5) changepw.php,… | EXPLOITHIGH 7.5EPSS 2.29% | 13 April 2010 |
| CVE-2009-4511 | Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.0EPSS 5.48% | 13 April 2010 |
| CVE-2010-1354 | Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 15.9% | 12 April 2010 |
| CVE-2010-1353 | Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 18.7% | 12 April 2010 |
| CVE-2010-1352 | Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 13.6% | 12 April 2010 |
| CVE-2010-1351 | Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _nodesforum_path_from_here_to_nodesforum_folder parameter to… | EXPLOIT ✓MEDIUM 6.8EPSS 1.82% | 12 April 2010 |
| CVE-2010-1350 | SQL injection vulnerability in the JP Jobs (com_jp_jobs) component 1.4.1 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.27% | 12 April 2010 |
| CVE-2010-1349 | Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a heap overflow. | EXPLOITHIGH 10.0EPSS 19.8% | 12 April 2010 |
| CVE-2010-1152 | memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation. | EXPLOIT ✓MEDIUM 5.0EPSS 10.4% | 12 April 2010 |
| CVE-2010-1146 | The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, which allows local users to gain privileges by modifying (1) extended attributes or (2) ACLs, as… | EXPLOIT ✓MEDIUM 6.9EPSS 1.82% | 12 April 2010 |
| CVE-2009-3732 | Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 16.2% | 12 April 2010 |
| CVE-2010-1346 | SQL injection vulnerability in admin/login.php in Mini CMS RibaFS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the login parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.08% | 9 April 2010 |
| CVE-2010-1345 | Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 16.9% | 9 April 2010 |
| CVE-2010-1344 | SQL injection vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter in a detail action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 9 April 2010 |
| CVE-2010-1343 | SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands via the albumid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.98% | 9 April 2010 |
| CVE-2010-1342 | Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter to (1) admin/menu.php and (2) library/lib.menu.php; and… | EXPLOIT ✓MEDIUM 6.8EPSS 1.80% | 9 April 2010 |
| CVE-2010-1341 | SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 9 April 2010 |
| CVE-2010-1340 | Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 13.6% | 9 April 2010 |
| CVE-2010-1338 | SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute arbitrary SQL commands via the userid parameter in a modboard action. | EXPLOIT ✓HIGH 7.5EPSS 1.59% | 9 April 2010 |
| CVE-2010-1337 | Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary PHP code via a URL in the (1) include and (2) Configuration['LANGUAGE']… | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 9 April 2010 |
| CVE-2010-1336 | Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) newlanguage parameters to site.php, (3) search parameter to manuals.php, and (4) unspecified vectors to faq.php. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 9 April 2010 |
| CVE-2010-1335 | Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter to (1) city.get/city.get.php, (2) city.get/index.php, (3)… | EXPLOIT ✓MEDIUM 6.8EPSS 2.90% | 9 April 2010 |
| CVE-2010-1315 | Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 8.23% | 8 April 2010 |
| CVE-2010-1314 | Directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 15.9% | 8 April 2010 |
| CVE-2010-1313 | Directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 8.68% | 8 April 2010 |
| CVE-2010-1312 | Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 13.6% | 8 April 2010 |
| CVE-2010-1309 | Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.73% | 8 April 2010 |
| CVE-2010-1308 | Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 14.0% | 8 April 2010 |
| CVE-2010-1307 | Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 10.2% | 8 April 2010 |
| CVE-2010-1306 | Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 15.7% | 8 April 2010 |
| CVE-2010-1305 | Directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 20.7% | 8 April 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.