SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-24 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,434 CVEs1,723 in CISA KEV17,397 with EPSS ≥ 10%25,049 with a public exploitUpdated 24 September 2026

25,049 results · page 198 of 501

CVESummaryPriorityPublished
CVE-2010-1461Directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via the view parameter to index.php.EXPLOIT ✓MEDIUM 5.0EPSS 8.23%16 April 2010
CVE-2010-1460The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with…EXPLOIT ✓MEDIUM 5.0EPSS 2.77%16 April 2010
CVE-2010-1423Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code…EXPLOIT ✓HIGH 9.3EPSS 55.6%15 April 2010
CVE-2010-0432Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 22.9%15 April 2010
CVE-2010-1316Multiple stack-based buffer overflows in Tembria Server Monitor before 5.6.1 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted (1) GET, (2) PUT, or (3) HEAD request, as demonstrated by a…EXPLOIT ✓MEDIUM 5.0EPSS 9.69%14 April 2010
CVE-2010-0480Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted…EXPLOIT ×3 ✓HIGH 9.3EPSS 67.9%14 April 2010
CVE-2010-0478Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media…EXPLOIT ✓HIGH 9.3EPSS 60.4%14 April 2010
CVE-2010-0477The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that…EXPLOIT ✓HIGH 10.0EPSS 50.2%14 April 2010
CVE-2010-0476The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and…EXPLOIT ✓HIGH 10.0EPSS 34.3%14 April 2010
CVE-2010-0270The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service…EXPLOIT ✓HIGH 10.0EPSS 48.2%14 April 2010
CVE-2010-0269The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows…EXPLOIT ✓HIGH 10.0EPSS 28.4%14 April 2010
CVE-2010-1372SQL injection vulnerability in the HD FLV Player (com_hdflvplayer) component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%13 April 2010
CVE-2010-1369SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter.EXPLOITHIGH 7.5EPSS 0.97%13 April 2010
CVE-2010-1368SQL injection vulnerability in index.php in GameScript (GS) 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action.EXPLOIT ✓HIGH 7.5EPSS 0.97%13 April 2010
CVE-2010-1366Multiple SQL injection vulnerabilities in admin/admin_login.php in Uiga Fan Club 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin_name and (2) admin_password parameters.EXPLOIT ✓HIGH 7.5EPSS 0.93%13 April 2010
CVE-2010-1365SQL injection vulnerability in index.php in Uiga Fan Club, as downloaded on 20100310, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01%13 April 2010
CVE-2010-1364SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.98%13 April 2010
CVE-2010-1363SQL injection vulnerability in the JProjects (com_j-projects) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the project parameter in a projects action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%13 April 2010
CVE-2010-1361Cross-site scripting (XSS) vulnerability in shop/USER_ARTIKEL_HANDLING_AUFRUF.php in PHPepperShop 2.5 allows remote attackers to inject arbitrary web script or HTML via the darstellen parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.49%13 April 2010
CVE-2010-1360Multiple PHP remote file inclusion vulnerabilities in FAQEngine 4.24.00 allow remote attackers to execute arbitrary PHP code via a URL in the path_faqe parameter to (1) attachs.php, (2) backup.php, (3) badwords.php, (4) categories.php, (5) changepw.php,…EXPLOITHIGH 7.5EPSS 2.29%13 April 2010
CVE-2009-4511Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.0EPSS 5.48%13 April 2010
CVE-2010-1354Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 15.9%12 April 2010
CVE-2010-1353Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 18.7%12 April 2010
CVE-2010-1352Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 13.6%12 April 2010
CVE-2010-1351Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _nodesforum_path_from_here_to_nodesforum_folder parameter to…EXPLOIT ✓MEDIUM 6.8EPSS 1.82%12 April 2010
CVE-2010-1350SQL injection vulnerability in the JP Jobs (com_jp_jobs) component 1.4.1 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.27%12 April 2010
CVE-2010-1349Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a heap overflow.EXPLOITHIGH 10.0EPSS 19.8%12 April 2010
CVE-2010-1152memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation.EXPLOIT ✓MEDIUM 5.0EPSS 10.4%12 April 2010
CVE-2010-1146The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, which allows local users to gain privileges by modifying (1) extended attributes or (2) ACLs, as…EXPLOIT ✓MEDIUM 6.9EPSS 1.82%12 April 2010
CVE-2009-3732Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.EXPLOIT ✓HIGH 10.0EPSS 16.2%12 April 2010
CVE-2010-1346SQL injection vulnerability in admin/login.php in Mini CMS RibaFS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the login parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.08%9 April 2010
CVE-2010-1345Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ×2 ✓MEDIUM 5.0EPSS 16.9%9 April 2010
CVE-2010-1344SQL injection vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter in a detail action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.22%9 April 2010
CVE-2010-1343SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands via the albumid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.98%9 April 2010
CVE-2010-1342Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter to (1) admin/menu.php and (2) library/lib.menu.php; and…EXPLOIT ✓MEDIUM 6.8EPSS 1.80%9 April 2010
CVE-2010-1341SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%9 April 2010
CVE-2010-1340Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 13.6%9 April 2010
CVE-2010-1338SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute arbitrary SQL commands via the userid parameter in a modboard action.EXPLOIT ✓HIGH 7.5EPSS 1.59%9 April 2010
CVE-2010-1337Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary PHP code via a URL in the (1) include and (2) Configuration['LANGUAGE']…EXPLOIT ✓HIGH 7.5EPSS 2.29%9 April 2010
CVE-2010-1336Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) newlanguage parameters to site.php, (3) search parameter to manuals.php, and (4) unspecified vectors to faq.php.EXPLOIT ✓HIGH 7.5EPSS 1.19%9 April 2010
CVE-2010-1335Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter to (1) city.get/city.get.php, (2) city.get/index.php, (3)…EXPLOIT ✓MEDIUM 6.8EPSS 2.90%9 April 2010
CVE-2010-1315Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 8.23%8 April 2010
CVE-2010-1314Directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 15.9%8 April 2010
CVE-2010-1313Directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 8.68%8 April 2010
CVE-2010-1312Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 13.6%8 April 2010
CVE-2010-1309Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.73%8 April 2010
CVE-2010-1308Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 14.0%8 April 2010
CVE-2010-1307Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 10.2%8 April 2010
CVE-2010-1306Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 15.7%8 April 2010
CVE-2010-1305Directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 20.7%8 April 2010

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.