SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,453 CVEs1,723 in CISA KEV17,397 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 206 of 501

CVESummaryPriorityPublished
CVE-2010-0371Multiple cross-site scripting (XSS) vulnerabilities in index.php in Hitmaaan Gallery 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gall and (2) levela parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%21 January 2010
CVE-2010-0367Multiple PHP remote file inclusion vulnerabilities in BitScripts Bits Video Script 2.05 Gold Beta, and possibly 2.04, allow remote attackers to execute arbitrary PHP code via a URL in the rowptem[template] parameter to (1) showcasesearch.php and (2)…EXPLOIT ×2 ✓HIGH 7.5EPSS 2.31%21 January 2010
CVE-2010-0366Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then…EXPLOIT ×2 ✓MEDIUM 6.8EPSS 3.54%21 January 2010
CVE-2010-0365Cross-site scripting (XSS) vulnerability in search.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allows remote attackers to inject arbitrary web script or HTML via the order parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%21 January 2010
CVE-2010-0364Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation Alpha Subtitle (.ass) file, probably involving the Dialogue field.EXPLOIT ✓HIGH 9.3EPSS 6.58%21 January 2010
CVE-2010-0232Microsoft Windows Kernel Exception Handler VulnerabilityKEVEXPLOIT ✓HIGH 7.8EPSS 29.3%21 January 2010
CVE-2009-3999Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter.EXPLOIT ✓HIGH 10.0EPSS 71.8%20 January 2010
CVE-2010-0361Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long URI in…EXPLOIT ×3 ✓HIGH 10.0EPSS 80.4%20 January 2010
CVE-2010-0359Buffer overflow in the SSLv2 support in Zeus Web Server before 4.3r5 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in an invalid Client Hello message.EXPLOIT ✓HIGH 10.0EPSS 20.0%20 January 2010
CVE-2009-4141Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then…EXPLOIT ✓HIGH 7.2EPSS 0.97%19 January 2010
CVE-2009-4628SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.61%18 January 2010
CVE-2009-4627Directory traversal vulnerability in sources/_template_parser.php in Moa Gallery 1.2.0 and earlier allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.84%18 January 2010
CVE-2009-4626Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the conf[lang] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.49%18 January 2010
CVE-2009-4625SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute…EXPLOIT ✓HIGH 7.5EPSS 2.42%18 January 2010
CVE-2009-4624SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2005-3843.EXPLOIT ✓HIGH 7.5EPSS 0.97%18 January 2010
CVE-2009-4623Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the ACS_path parameter to (1) index.php and (2) admin.php in advanced_comment_system/.EXPLOIT ✓HIGH 7.5EPSS 9.85%18 January 2010
CVE-2009-4622PHP remote file inclusion vulnerability in admin/admin_news_bot.php in Drunken:Golem Gaming Portal 0.5.1 alpha 2 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, a different vector than CVE-2007-0572.EXPLOIT ✓HIGH 7.5EPSS 2.10%18 January 2010
CVE-2009-4621SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to forummission.php.EXPLOIT ✓HIGH 7.5EPSS 0.99%18 January 2010
CVE-2009-4620SQL injection vulnerability in the Joomloc (com_joomloc) component 1.0 for Joomla allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.15%18 January 2010
CVE-2009-4618Multiple SQL injection vulnerabilities in Tourism Script Bus Script allow remote attackers to execute arbitrary SQL commands via the sitetext_id parameter to (1) aboutus.php and (2) faq.php.EXPLOIT ✓HIGH 7.5EPSS 0.93%18 January 2010
CVE-2009-4617Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attackers to execute arbitrary SQL commands via the hotel_id parameter to (1) hotel.php, (2) details.php, (3) roomtypes.php, (4) photos.php,…EXPLOIT ✓HIGH 7.5EPSS 1.00%18 January 2010
CVE-2009-4616Cross-site scripting (XSS) vulnerability in search.php in MYRE Holiday Rental Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.22%18 January 2010
CVE-2009-4615SQL injection vulnerability in review.php in MYRE Holiday Rental Manager allows remote attackers to execute arbitrary SQL commands via the link_id parameter in a show_review action.EXPLOIT ✓HIGH 7.5EPSS 0.93%18 January 2010
CVE-2009-4614Multiple PHP remote file inclusion vulnerabilities in Moa Gallery 1.2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the MOA_PATH parameter to (1) _error_funcs.php, (2) _integrity_funcs.php, (3)…EXPLOIT ✓HIGH 7.5EPSS 2.10%18 January 2010
CVE-2010-0356Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK ActiveX 6.8 allows remote attackers to execute arbitrary code via a long strFontName parameter to the…EXPLOIT ×2 ✓HIGH 9.3EPSS 30.3%18 January 2010
CVE-2010-0321Cross-site scripting (XSS) vulnerability in jobs/index.php in Jamit Job Board 3.0 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%15 January 2010
CVE-2010-0319Cross-site scripting (XSS) vulnerability in index.php in Docmint 1.0 and 2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%15 January 2010
CVE-2010-0317Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP requests that are not properly handled by (1) the CIFS functionality in…EXPLOIT ✓HIGH 7.8EPSS 10.5%15 January 2010
CVE-2010-0249Microsoft Internet Explorer Use-After-Free VulnerabilityKEVEXPLOIT ×2 ✓HIGH 8.8EPSS 91.9%15 January 2010
CVE-2010-0315WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK…EXPLOIT ✓MEDIUM 5.0EPSS 6.89%14 January 2010
CVE-2010-0314Apple Safari allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href…EXPLOIT ✓MEDIUM 5.0EPSS 7.60%14 January 2010
CVE-2010-0313The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted LDAP Search Request message.EXPLOIT ✓MEDIUM 5.0EPSS 8.91%14 January 2010
CVE-2009-4613SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password parameter.EXPLOITHIGH 7.5EPSS 0.91%14 January 2010
CVE-2010-0002The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows local users to send escape sequences to terminal emulators, or hide the…EXPLOIT ✓LOW 2.1EPSS 0.67%14 January 2010
CVE-2009-4612Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2)…EXPLOIT ✓MEDIUM 4.3EPSS 3.33%13 January 2010
CVE-2009-4610Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature, or the (2) Name or (3) Value parameter to…EXPLOIT ✓MEDIUM 4.3EPSS 3.04%13 January 2010
CVE-2009-4496Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape…EXPLOIT ✓MEDIUM 5.0EPSS 12.3%13 January 2010
CVE-2009-4495Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence…EXPLOIT ✓MEDIUM 5.0EPSS 8.95%13 January 2010
CVE-2009-4494AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape…EXPLOIT ✓MEDIUM 5.0EPSS 8.94%13 January 2010
CVE-2009-4493Orion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request…EXPLOIT ✓MEDIUM 5.0EPSS 6.97%13 January 2010
CVE-2009-4492WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a…EXPLOIT ✓HIGH 7.5EPSS 16.2%13 January 2010
CVE-2009-4491thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape…EXPLOIT ✓CRITICAL 9.8EPSS 13.7%13 January 2010
CVE-2009-4490mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape…EXPLOIT ✓MEDIUM 5.0EPSS 10.2%13 January 2010
CVE-2009-4489header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request…EXPLOIT ✓MEDIUM 5.0EPSS 9.80%13 January 2010
CVE-2009-4488Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape…EXPLOIT ✓CRITICAL 9.8EPSS 13.0%13 January 2010
CVE-2009-4487nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape…EXPLOIT ✓MEDIUM 6.8EPSS 29.5%13 January 2010
CVE-2009-3958Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote…EXPLOITHIGH 10.0EPSS 52.6%13 January 2010
CVE-2009-3953Adobe Acrobat and Reader Universal 3D Remote Code Execution VulnerabilityKEVEXPLOIT ✓HIGH 8.8EPSS 83.9%13 January 2010
CVE-2009-4607The command line interface in Overland Storage Snap Server 410 with GuardianOS 5.1.041 runs the "less" utility with a higher-privileged uid than the CLI user and without sufficient restriction on shell escapes, which allows local users to gain…EXPLOIT ✓HIGH 7.2EPSS 0.61%13 January 2010
CVE-2009-4606South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to…EXPLOITHIGH 7.2EPSS 0.80%13 January 2010

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.