Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,441 CVEs1,723 in CISA KEV17,397 with EPSS ≥ 10%25,049 with a public exploitUpdated 24 September 2026
25,049 results · page 205 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-3960 | Adobe BlazeDS Information Disclosure Vulnerability | KEVEXPLOIT ×2 ✓MEDIUM 6.5EPSS 90.0% | 15 February 2010 |
| CVE-2010-0632 | SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 February 2010 |
| CVE-2010-0631 | Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow remote attackers to execute arbitrary SQL commands via the (1) users (username) and (2) passwords parameters. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 12 February 2010 |
| CVE-2010-0630 | SQL injection vulnerability in viewjokes.php in Evernew Free Joke Script 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 12 February 2010 |
| CVE-2001-1586 | Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vulnerability than CVE-2000-0664. | EXPLOIT ✓HIGH 10.0EPSS 8.20% | 12 February 2010 |
| CVE-2010-0614 | SQL injection vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to execute arbitrary SQL commands via the query parameter in the (1) question action, and possibly the (2) sub_par or (3) num_quest actions. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 11 February 2010 |
| CVE-2010-0611 | Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 11 February 2010 |
| CVE-2010-0610 | Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the blog parameter in an images action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 11 February 2010 |
| CVE-2010-0608 | SQL injection vulnerability in index.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter in a search action. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 11 February 2010 |
| CVE-2010-0607 | Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote attackers to inject arbitrary web script or HTML via the Stat_Radio parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 11 February 2010 |
| CVE-2010-0605 | SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.05% | 11 February 2010 |
| CVE-2010-0239 | The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute… | EXPLOIT ✓HIGH 10.0EPSS 61.3% | 10 February 2010 |
| CVE-2010-0233 | Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double… | EXPLOIT ✓HIGH 7.2EPSS 2.70% | 10 February 2010 |
| CVE-2010-0231 | The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of… | EXPLOIT ✓HIGH 10.0EPSS 41.3% | 10 February 2010 |
| CVE-2010-0033 | Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability." | EXPLOIT ✓HIGH 9.3EPSS 51.1% | 10 February 2010 |
| CVE-2010-0028 | Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability." | EXPLOIT ✓HIGH 9.3EPSS 48.5% | 10 February 2010 |
| CVE-2010-0017 | Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and… | EXPLOIT ✓HIGH 9.3EPSS 30.9% | 10 February 2010 |
| CVE-2009-4637 | FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow. | EXPLOIT ✓HIGH 10.0EPSS 17.0% | 10 February 2010 |
| CVE-2010-0411 | Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large… | EXPLOIT ✓MEDIUM 4.9EPSS 0.95% | 8 February 2010 |
| CVE-2010-0557 | IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials. | EXPLOIT ✓HIGH 7.5EPSS 51.1% | 5 February 2010 |
| CVE-2010-0553 | Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long NMEA data sentence. | EXPLOIT ✓MEDIUM 6.5EPSS 3.27% | 4 February 2010 |
| CVE-2010-0552 | Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via multiple requests for a non-existent file using a long URI. | EXPLOIT ✓HIGH 7.5EPSS 4.22% | 4 February 2010 |
| CVE-2010-0303 | mystring.c in hybserv in IRCD-Hybrid (aka Hybrid2 IRC Services) 1.9.2 through 1.9.4 allows remote attackers to cause a denial of service (daemon crash) via a ":help \t" private message to the MemoServ service. | EXPLOIT ✓MEDIUM 5.0EPSS 8.06% | 4 February 2010 |
| CVE-2010-0496 | FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / URI. | EXPLOIT ✓MEDIUM 5.0EPSS 6.26% | 3 February 2010 |
| CVE-2010-0295 | lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate. | EXPLOIT ✓MEDIUM 5.0EPSS 12.1% | 3 February 2010 |
| CVE-2010-0453 | The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the… | EXPLOITMEDIUM 4.9EPSS 0.84% | 3 February 2010 |
| CVE-2010-0440 | Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers to inject arbitrary web script… | EXPLOIT ✓MEDIUM 4.3EPSS 4.76% | 3 February 2010 |
| CVE-2010-0304 | Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the… | EXPLOIT ×3 ✓HIGH 7.5EPSS 73.7% | 3 February 2010 |
| CVE-2010-0442 | The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the… | EXPLOIT ✓MEDIUM 6.5EPSS 13.4% | 2 February 2010 |
| CVE-2010-0470 | Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web script or HTML via the srvName parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 2 February 2010 |
| CVE-2010-0468 | Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 2 February 2010 |
| CVE-2010-0467 | Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.8EPSS 43.3% | 2 February 2010 |
| CVE-2010-0462 | Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function. | EXPLOIT ✓MEDIUM 6.5EPSS 7.52% | 28 January 2010 |
| CVE-2010-0461 | SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) category or (2) player action to index.php. | EXPLOITMEDIUM 6.5EPSS 0.86% | 28 January 2010 |
| CVE-2010-0459 | SQL injection vulnerability in the Mochigames (com_mochigames) component 0.51 and possibly other versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | EXPLOITHIGH 7.5EPSS 0.97% | 28 January 2010 |
| CVE-2010-0458 | Multiple SQL injection vulnerabilities in NetArt Media Blog System 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to index.php and the (2) note parameter to blog.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 28 January 2010 |
| CVE-2010-0457 | SQL injection vulnerability in home.php in magic-portal 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 28 January 2010 |
| CVE-2010-0456 | SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the grp parameter in a gameserver action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 28 January 2010 |
| CVE-2010-0390 | Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by… | EXPLOIT ✓MEDIUM 6.8EPSS 3.34% | 26 January 2010 |
| CVE-2009-4273 | stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line arguments in a request. | EXPLOIT ✓HIGH 10.0EPSS 17.7% | 26 January 2010 |
| CVE-2010-0388 | Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers… | EXPLOIT ✓HIGH 7.5EPSS 7.18% | 25 January 2010 |
| CVE-2010-0387 | Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long string in… | EXPLOIT ✓HIGH 7.5EPSS 7.70% | 25 January 2010 |
| CVE-2010-0380 | install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify application settings via a direct request. | EXPLOITMEDIUM 5.0EPSS 1.95% | 22 January 2010 |
| CVE-2010-0248 | Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory… | EXPLOIT ✓HIGH 8.1EPSS 53.1% | 22 January 2010 |
| CVE-2010-0027 | The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote… | EXPLOIT ✓HIGH 9.3EPSS 34.0% | 22 January 2010 |
| CVE-2010-0376 | Cross-site scripting (XSS) vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | EXPLOITMEDIUM 4.3EPSS 1.50% | 21 January 2010 |
| CVE-2010-0375 | SQL injection vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOITHIGH 7.5EPSS 1.00% | 21 January 2010 |
| CVE-2010-0374 | Cross-site scripting (XSS) vulnerability in the Marketplace (com_marketplace) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the catid parameter in a show_category action to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 21 January 2010 |
| CVE-2010-0373 | SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 21 January 2010 |
| CVE-2010-0372 | SQL injection vulnerability in the Articlemanager (com_articlemanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the artid parameter in a display action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 21 January 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.