Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,434 CVEs1,723 in CISA KEV17,397 with EPSS ≥ 10%25,049 with a public exploitUpdated 24 September 2026
25,049 results · page 199 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-1304 | Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 14.0% | 8 April 2010 |
| CVE-2010-1302 | Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php. | EXPLOIT ✓MEDIUM 5.0EPSS 8.48% | 7 April 2010 |
| CVE-2010-1301 | SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.63% | 7 April 2010 |
| CVE-2010-1300 | SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbitrary SQL commands via the calbums parameter. | EXPLOIT ×4 ✓HIGH 7.5EPSS 1.91% | 7 April 2010 |
| CVE-2010-1299 | Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) DefineRootToTool… | EXPLOIT ×2MEDIUM 5.1EPSS 10.7% | 7 April 2010 |
| CVE-2008-7254 | Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, when register_globals is enabled, allows remote attackers to include and execute arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.86% | 7 April 2010 |
| CVE-2010-1186 | Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 4.73% | 7 April 2010 |
| CVE-2010-1272 | PHP remote file inclusion vulnerability in includes/tgpinc.php in Gnat-TGP 1.2.20 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. | EXPLOITHIGH 7.5EPSS 2.29% | 6 April 2010 |
| CVE-2010-1271 | SQL injection vulnerability in showplugs.php in smartplugs 1.3 allows remote attackers to execute arbitrary SQL commands via the domain parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 6 April 2010 |
| CVE-2010-1147 | Stack-based buffer overflow in Open Direct Connect Hub (aka Open DC Hub or OpenDCHub) 0.8.1 allows remote authenticated users to execute arbitrary code via a long MyINFO message. | EXPLOITMEDIUM 6.0EPSS 8.17% | 6 April 2010 |
| CVE-2010-1270 | SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitrary SQL commands via the id_auk parameter. | EXPLOIT ×3 ✓HIGH 7.5EPSS 1.20% | 6 April 2010 |
| CVE-2010-1269 | SQL injection vulnerability in auktion.php in phpscripte24 Niedrig Gebote Pro Auktions System II allows remote attackers to execute arbitrary SQL commands via the id_auk parameter. | EXPLOIT ×3 ✓HIGH 7.5EPSS 1.01% | 6 April 2010 |
| CVE-2010-1268 | Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files directory traversal sequences in the p parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.30% | 6 April 2010 |
| CVE-2010-1267 | Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the com parameter to (1) cContactus.php, (2) cGuestbook.php, and (3) cArticle.php. | EXPLOIT ✓MEDIUM 5.0EPSS 2.77% | 6 April 2010 |
| CVE-2010-1266 | Multiple PHP remote file inclusion vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) template, (2) menu, (3) events, and (4) SITEROOT parameters to template/babyweb/index.php;… | EXPLOIT ✓HIGH 7.5EPSS 2.93% | 6 April 2010 |
| CVE-2010-1265 | SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 6 April 2010 |
| CVE-2009-2936 | The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to… | EXPLOITHIGH 7.5EPSS 63.8% | 5 April 2010 |
| CVE-2010-1240 | Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an… | EXPLOIT ×3 ✓HIGH 9.3EPSS 73.6% | 5 April 2010 |
| CVE-2010-1239 | Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs embedded in a PDF document via an unspecified "/Launch /Action"… | EXPLOIT ✓HIGH 9.3EPSS 7.53% | 5 April 2010 |
| CVE-2010-1226 | The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of service (Safari, Mail, or Springboard crash) via a crafted innerHTML property of a DIV element, related to a… | EXPLOIT ✓MEDIUM 5.0EPSS 5.00% | 1 April 2010 |
| CVE-2010-1225 | The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to… | EXPLOIT ✓HIGH 9.3EPSS 28.2% | 1 April 2010 |
| CVE-2010-0842 | Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ✓HIGH 7.5EPSS 77.7% | 1 April 2010 |
| CVE-2010-0840 | Oracle JRE Unspecified Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 96.3% | 1 April 2010 |
| CVE-2010-0838 | Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ✓HIGH 7.5EPSS 14.9% | 1 April 2010 |
| CVE-2010-0094 | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ✓HIGH 7.5EPSS 80.8% | 1 April 2010 |
| CVE-2010-0805 | The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the… | EXPLOIT ×2 ✓HIGH 9.3EPSS 80.7% | 31 March 2010 |
| CVE-2010-1219 | Directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 8.23% | 30 March 2010 |
| CVE-2010-1217 | Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 6.43% | 30 March 2010 |
| CVE-2010-1216 | PHP remote file inclusion vulnerability in templates/template.php in notsoPureEdit 1.4.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.38% | 30 March 2010 |
| CVE-2010-0520 | Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC file, related to crafted DELTA_FLI… | EXPLOIT ✓MEDIUM 6.8EPSS 18.6% | 30 March 2010 |
| CVE-2010-0519 | Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles… | EXPLOIT ✓MEDIUM 6.8EPSS 9.34% | 30 March 2010 |
| CVE-2010-1185 | Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to execute arbitrary code via an invalid length parameter in a handshake packet to TCP port 7210. | EXPLOIT ✓HIGH 10.0EPSS 15.2% | 29 March 2010 |
| CVE-2010-1183 | Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink attack on the /tmp/CLEANUP temporary file, related to use of Update Manager. | EXPLOIT ×3 ✓LOW 3.3EPSS 0.49% | 29 March 2010 |
| CVE-2010-1180 | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long exception string in a throw statement, possibly a related issue to CVE-2009-1514. | EXPLOIT ✓HIGH 9.3EPSS 8.30% | 29 March 2010 |
| CVE-2010-1179 | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large integer in the numcolors attribute of a recolorinfo element in a VML file, possibly a… | EXPLOIT ✓HIGH 9.3EPSS 8.95% | 29 March 2010 |
| CVE-2010-1177 | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings. | EXPLOIT ✓HIGH 9.3EPSS 7.23% | 29 March 2010 |
| CVE-2010-1176 | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings in… | EXPLOIT ✓HIGH 9.3EPSS 8.60% | 29 March 2010 |
| CVE-2010-1175 | Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day… | EXPLOIT ✓HIGH 9.3EPSS 14.2% | 29 March 2010 |
| CVE-2010-1174 | Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RRQ) or (2) write (aka WRQ) request, or other TFTP packet. | EXPLOIT ✓MEDIUM 5.0EPSS 5.08% | 29 March 2010 |
| CVE-2009-4761 | Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long string in a .smi file. | EXPLOIT ✓HIGH 9.3EPSS 5.63% | 29 March 2010 |
| CVE-2009-4760 | Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/guestbook.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.61% | 29 March 2010 |
| CVE-2009-4759 | Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .BMX file. | EXPLOIT ✓HIGH 9.3EPSS 4.85% | 29 March 2010 |
| CVE-2009-4758 | Stack-based buffer overflow in dicas Mpegable Player 2.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .YUV file. | EXPLOIT ✓HIGH 9.3EPSS 5.60% | 29 March 2010 |
| CVE-2009-4757 | Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a malformed playlist (.m3u) file. | EXPLOIT ✓HIGH 9.3EPSS 4.87% | 29 March 2010 |
| CVE-2009-4756 | Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. | EXPLOIT ×4 ✓HIGH 9.3EPSS 6.91% | 29 March 2010 |
| CVE-2009-4755 | Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .b4s or (2) .pls playlist file. | EXPLOIT ✓HIGH 9.3EPSS 6.82% | 29 March 2010 |
| CVE-2009-4754 | Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 6.08% | 29 March 2010 |
| CVE-2009-4753 | Multiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attackers to cause a denial of service (TCP/IP outage) via long arguments to the (1) XRMD, (2) delete, (3) RNFR, or (4) RNTO command. | EXPLOIT ✓HIGH 7.1EPSS 3.00% | 29 March 2010 |
| CVE-2010-1132 | The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message. | EXPLOIT ✓HIGH 9.3EPSS 8.58% | 27 March 2010 |
| CVE-2010-1131 | JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of service (application crash) via an HTML document composed of many successive occurrences of the <object> substring. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.84% | 27 March 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.