Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,441 CVEs1,723 in CISA KEV17,397 with EPSS ≥ 10%25,049 with a public exploitUpdated 24 September 2026
25,049 results · page 204 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-0714 | Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0… | EXPLOIT ✓MEDIUM 4.3EPSS 3.53% | 26 February 2010 |
| CVE-2009-4655 | The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie. | EXPLOIT ✓HIGH 7.5EPSS 49.9% | 26 February 2010 |
| CVE-2009-4654 | Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code via long sadminpwd and verifypwd parameters in a submit action to /dhost/httpstk. | EXPLOIT ✓HIGH 9.0EPSS 6.76% | 26 February 2010 |
| CVE-2009-4653 | Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a denial of service (dhost.exe crash) and possibly execute arbitrary code via a long string to /dhost/modules?I:. | EXPLOIT ✓HIGH 9.0EPSS 12.7% | 26 February 2010 |
| CVE-2010-0713 | Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authentication of an administrator for (1) requests that reset user passwords via zport/dmd/ZenUsers/admin,… | EXPLOIT ✓MEDIUM 6.8EPSS 1.95% | 26 February 2010 |
| CVE-2010-0712 | Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticated users to execute arbitrary SQL commands via the (1) severity, (2) state, (3) filter, (4) offset, and… | EXPLOIT ✓MEDIUM 6.5EPSS 1.98% | 26 February 2010 |
| CVE-2010-0711 | Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to hijack the authentication of an administrator for requests that (1) delete users via the delete… | EXPLOITMEDIUM 6.8EPSS 0.95% | 25 February 2010 |
| CVE-2010-0709 | Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administrators for requests that change the email address or password via the user action to index.php, and (2)… | EXPLOIT ×2MEDIUM 6.8EPSS 1.23% | 25 February 2010 |
| CVE-2010-0707 | Cross-site request forgery (CSRF) vulnerability in add_user.php in Employee Timeclock Software 0.99 allows remote attackers to hijack the authentication of an administrator for requests that create new administrative users. | EXPLOIT ✓MEDIUM 6.8EPSS 0.95% | 25 February 2010 |
| CVE-2010-0706 | Cross-site scripting (XSS) vulnerability in the login/prompt component in Subex Nikira Fraud Management System allows remote attackers to inject arbitrary web script or HTML via the message parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 25 February 2010 |
| CVE-2010-0705 | 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via… | EXPLOIT ✓HIGH 7.2EPSS 0.93% | 25 February 2010 |
| CVE-2010-0620 | Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. | EXPLOIT ✓HIGH 9.3EPSS 19.5% | 25 February 2010 |
| CVE-2010-0703 | Cross-site scripting (XSS) vulnerability in wa/auth in PortWise SSL VPN 4.6 allows remote attackers to inject arbitrary web script or HTML via the reloadFrame parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.79% | 23 February 2010 |
| CVE-2010-0702 | SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOITHIGH 7.5EPSS 4.09% | 23 February 2010 |
| CVE-2010-0701 | SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | EXPLOITHIGH 7.5EPSS 1.16% | 23 February 2010 |
| CVE-2010-0700 | Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.73% | 23 February 2010 |
| CVE-2010-0698 | SQL injection vulnerability in backoffice/login.asp in Dynamicsoft WSC CMS 2.2 allows remote attackers to execute arbitrary SQL commands via the Password parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 23 February 2010 |
| CVE-2010-0682 | WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter. | EXPLOIT ✓MEDIUM 4.0EPSS 9.86% | 23 February 2010 |
| CVE-2010-0696 | Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter. | EXPLOITMEDIUM 5.0EPSS 28.2% | 23 February 2010 |
| CVE-2010-0695 | Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.34% | 23 February 2010 |
| CVE-2010-0694 | SQL injection vulnerability in the PerchaGallery (com_perchagallery) component before 1.5b for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an editunidad action to index.php. | EXPLOITHIGH 7.5EPSS 1.00% | 23 February 2010 |
| CVE-2010-0693 | SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 23 February 2010 |
| CVE-2010-0691 | SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands via the s parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 23 February 2010 |
| CVE-2010-0690 | SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 23 February 2010 |
| CVE-2010-0681 | ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for admin/backup.sql. | EXPLOIT ✓MEDIUM 5.0EPSS 2.17% | 22 February 2010 |
| CVE-2010-0680 | Directory traversal vulnerability in index.php in ZeusCMS 0.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.32% | 22 February 2010 |
| CVE-2010-0679 | Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote attackers to execute arbitrary code via a large number of white space characters in the filename argument… | EXPLOIT ×2 ✓HIGH 9.3EPSS 35.1% | 22 February 2010 |
| CVE-2010-0678 | PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the includes_directory… | EXPLOIT ✓MEDIUM 6.8EPSS 1.82% | 22 February 2010 |
| CVE-2010-0677 | SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the get parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 22 February 2010 |
| CVE-2009-4651 | Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) color, (2) img, or (3) url BBCode tags in… | EXPLOIT ✓MEDIUM 4.3EPSS 1.18% | 22 February 2010 |
| CVE-2009-4650 | SQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a default action to index2.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 22 February 2010 |
| CVE-2010-0675 | Cross-site scripting (XSS) vulnerability in index.php in BGSvetionik BGS CMS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 22 February 2010 |
| CVE-2010-0674 | StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for path/stats.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.44% | 22 February 2010 |
| CVE-2010-0673 | SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.82% | 22 February 2010 |
| CVE-2010-0672 | SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via the orderlinks parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 22 February 2010 |
| CVE-2010-0671 | SQL injection vulnerability in index.php in KR MEDIA Pogodny CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a niusy action. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 22 February 2010 |
| CVE-2010-0188 | Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability | KEVEXPLOIT ×4 ✓HIGH 7.8EPSS 88.2% | 22 February 2010 |
| CVE-2010-0665 | JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for jag/database.sql. | EXPLOITMEDIUM 5.0EPSS 2.20% | 19 February 2010 |
| CVE-2010-0108 | Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4; and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers… | EXPLOIT ✓HIGH 10.0EPSS 19.4% | 19 February 2010 |
| CVE-2009-4648 | Accellion Secure File Transfer Appliance before 8_0_105 does not properly restrict access to sensitive commands and arguments that run with extra sudo privileges, which allows local administrators to gain privileges via (1) arbitrary arguments in the… | EXPLOIT ✓HIGH 7.2EPSS 0.82% | 19 February 2010 |
| CVE-2009-4645 | Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 2.76% | 19 February 2010 |
| CVE-2010-0416 | Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… | EXPLOIT ✓HIGH 7.5EPSS 11.3% | 18 February 2010 |
| CVE-2010-0655 | Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving the display of a blocked popup window during… | EXPLOIT ✓HIGH 9.3EPSS 7.46% | 18 February 2010 |
| CVE-2010-0642 | Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extension, as demonstrated by (1) changing .jhtml to %2Ejhtml, (2) changing .jhtml to .jhtm%6C, (3) appending… | EXPLOIT ✓MEDIUM 5.0EPSS 7.52% | 17 February 2010 |
| CVE-2010-0641 | Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5 allows remote attackers to inject arbitrary web script or HTML via the dest parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.24% | 17 February 2010 |
| CVE-2010-0415 | The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other… | EXPLOITMEDIUM 4.6EPSS 1.82% | 17 February 2010 |
| CVE-2010-0307 | The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensure that the ELF interpreter is available before a call to the SET_PERSONALITY macro, which allows local users to cause a denial of… | EXPLOIT ✓MEDIUM 4.7EPSS 0.83% | 17 February 2010 |
| CVE-2010-0288 | A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the… | EXPLOIT ✓HIGH 7.5EPSS 10.5% | 15 February 2010 |
| CVE-2010-0287 | Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 10.6% | 15 February 2010 |
| CVE-2010-0187 | Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file. | EXPLOIT ✓MEDIUM 4.3EPSS 15.6% | 15 February 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.