Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,434 CVEs1,723 in CISA KEV17,397 with EPSS ≥ 10%25,049 with a public exploitUpdated 24 September 2026
25,049 results · page 201 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-1055 | Multiple PHP remote file inclusion vulnerabilities in osDate 2.1.9 and 2.5.4, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[forum_installed] parameter to… | EXPLOIT ✓MEDIUM 5.1EPSS 2.60% | 23 March 2010 |
| CVE-2010-1054 | Multiple SQL injection vulnerabilities in ParsCMS allow remote attackers to execute arbitrary SQL commands via the RP parameter to (1) fa_default.asp and (2) en_default.asp. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 23 March 2010 |
| CVE-2010-1053 | Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to (a) userlogin.php and (b)… | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 23 March 2010 |
| CVE-2010-1052 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) mday parameters. | EXPLOITMEDIUM 4.3EPSS 1.20% | 23 March 2010 |
| CVE-2010-1051 | Multiple SQL injection vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) month parameters. | EXPLOITHIGH 7.5EPSS 0.89% | 23 March 2010 |
| CVE-2010-1050 | SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via the mday parameter. | EXPLOITHIGH 7.5EPSS 0.97% | 23 March 2010 |
| CVE-2010-1049 | Multiple SQL injection vulnerabilities in Uiga Business Portal allow remote attackers to execute arbitrary SQL commands via the (1) noentryid parameter to blog/index.php and the (2) p parameter to index2.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 23 March 2010 |
| CVE-2010-1048 | Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga Business Portal allows remote attackers to inject arbitrary web script or HTML via the textcomment parameter (aka the Comment Box) in a noentryid action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 23 March 2010 |
| CVE-2010-1047 | SQL injection vulnerability in index.php in MASA2EL Music City 1.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a singer action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 23 March 2010 |
| CVE-2010-1046 | Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) userid (username) and (2) password parameters. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 23 March 2010 |
| CVE-2010-1045 | SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 23 March 2010 |
| CVE-2010-1044 | SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort parameter. | EXPLOITHIGH 7.5EPSS 0.97% | 23 March 2010 |
| CVE-2010-1043 | Directory traversal vulnerability in index.php in jaxCMS 1.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.36% | 23 March 2010 |
| CVE-2010-1042 | Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file. | EXPLOIT ✓MEDIUM 4.3EPSS 10.3% | 23 March 2010 |
| CVE-2010-1029 | Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 10.4% | 19 March 2010 |
| CVE-2010-1003 | Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 5.06% | 19 March 2010 |
| CVE-2010-0688 | Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a crafted (1) .orb or (2) .ov file. | EXPLOIT ×3 ✓HIGH 9.3EPSS 37.9% | 19 March 2010 |
| CVE-2010-0733 | Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related to… | EXPLOIT ✓LOW 3.5EPSS 6.90% | 19 March 2010 |
| CVE-2009-4735 | SQL injection vulnerability in login.php in Allomani Audio & Video Library (Songs & Clips version) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 18 March 2010 |
| CVE-2009-4734 | SQL injection vulnerability in login.php in Allomani Movies Library (Movies & Clips) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 18 March 2010 |
| CVE-2009-4733 | SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.89% | 18 March 2010 |
| CVE-2009-4732 | SQL injection vulnerability in tt/index.php in TT Web Site Manager 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tt_name parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.95% | 18 March 2010 |
| CVE-2009-4730 | SQL injection vulnerability in report.php in x10 Adult Media Script 1.7 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 18 March 2010 |
| CVE-2009-4729 | Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, (3)… | EXPLOIT ✓MEDIUM 4.3EPSS 3.63% | 18 March 2010 |
| CVE-2009-4728 | SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 18 March 2010 |
| CVE-2009-4727 | SQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 18 March 2010 |
| CVE-2009-4726 | Directory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.92% | 18 March 2010 |
| CVE-2009-4725 | Directory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 1.97% | 18 March 2010 |
| CVE-2009-4724 | SQL injection vulnerability in shop.htm in PaymentProcessorScript.net PPScript allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.94% | 18 March 2010 |
| CVE-2009-4723 | Directory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.37% | 18 March 2010 |
| CVE-2009-4722 | SQL injection vulnerability in the CheckLogin function in includes/functions.php in Limny 1.01, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.96% | 18 March 2010 |
| CVE-2009-4721 | Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 18 March 2010 |
| CVE-2009-4719 | SQL injection vulnerability in index.php in Discloser 0.0.4 rc2 allows remote attackers to execute arbitrary SQL commands via the more parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.05% | 18 March 2010 |
| CVE-2010-0985 | Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 13.1% | 16 March 2010 |
| CVE-2010-0984 | Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for databases/acidcat_3.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.80% | 16 March 2010 |
| CVE-2010-0983 | PHP remote file inclusion vulnerability in include/mail.inc.php in Rezervi 3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root parameter, a different vector than CVE-2007-2156. | EXPLOIT ✓MEDIUM 6.8EPSS 2.39% | 16 March 2010 |
| CVE-2010-0982 | Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 6.88% | 16 March 2010 |
| CVE-2010-0981 | SQL injection vulnerability in the TPJobs (com_tpjobs) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_c[] parameter in a resadvsearch action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 16 March 2010 |
| CVE-2010-0980 | SQL injection vulnerability in player.php in Left 4 Dead (L4D) Stats 1.1 allows remote attackers to execute arbitrary SQL commands via the steamid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 16 March 2010 |
| CVE-2010-0978 | KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.54% | 16 March 2010 |
| CVE-2010-0976 | Acidcat CMS 3.5.x does not prevent access to install.asp after installation finishes, which might allow remote attackers to restart the installation process and have unspecified other impact via requests to install.asp and other install_*.asp scripts. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 16 March 2010 |
| CVE-2010-0397 | The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and… | EXPLOIT ✓MEDIUM 5.0EPSS 11.5% | 16 March 2010 |
| CVE-2010-0975 | PHP remote file inclusion vulnerability in external.php in PHPCityPortal allows remote attackers to execute arbitrary PHP code via a URL in the url parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.99% | 16 March 2010 |
| CVE-2010-0974 | Multiple SQL injection vulnerabilities in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) video_show.php, (2) spotlight_detail.php, (3) real_estate_details.php, and (4) auto_details.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 16 March 2010 |
| CVE-2010-0973 | SQL injection vulnerability in index.php in phppool media Domain Verkaus and Auktions Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 16 March 2010 |
| CVE-2010-0972 | Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 13.3% | 16 March 2010 |
| CVE-2010-0971 | Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and… | EXPLOIT ✓LOW 2.1EPSS 1.67% | 16 March 2010 |
| CVE-2010-0970 | SQL injection vulnerability in phpmylogon.php in PhpMyLogon 2 allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.98% | 16 March 2010 |
| CVE-2010-0968 | SQL injection vulnerability in bannershow.php in Geekhelps ADMP 1.01 allows remote attackers to execute arbitrary SQL commands via the click parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 16 March 2010 |
| CVE-2010-0967 | Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the style parameter to (1)… | EXPLOIT ✓MEDIUM 5.1EPSS 2.74% | 16 March 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.