Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 241 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-5672 | Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file… | EXPLOIT ✓MEDIUM 4.3EPSS 12.5% | 25 October 2012 |
| CVE-2012-3001 | Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection vulnerability." | EXPLOIT ✓HIGH 8.5EPSS 27.3% | 22 October 2012 |
| CVE-2012-4933 | The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of Scott for the (1) GetFile_Password and (2) GetConfigInfo_Password operations, which allows… | HIGH 7.8EPSS 44.0% | 20 October 2012 |
| CVE-2012-3153 | Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. | EXPLOITMEDIUM 6.4EPSS 98.2% | 16 October 2012 |
| CVE-2012-3152 | Oracle Fusion Middleware Unspecified Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.1EPSS 98.8% | 16 October 2012 |
| CVE-2012-5088 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. | EXPLOIT ✓HIGH 10.0EPSS 78.7% | 16 October 2012 |
| CVE-2012-5081 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect availability, related to… | MEDIUM 5.0EPSS 45.1% | 16 October 2012 |
| CVE-2012-5076 | Oracle Java SE Sandbox Bypass Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 91.3% | 16 October 2012 |
| CVE-2012-5067 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Deployment. | EXPLOIT ✓MEDIUM 5.0EPSS 64.0% | 16 October 2012 |
| CVE-2012-1533 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related… | EXPLOITHIGH 10.0EPSS 69.0% | 16 October 2012 |
| CVE-2012-5166 | ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records. | HIGH 7.8EPSS 34.2% | 10 October 2012 |
| CVE-2012-4188 | Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary… | HIGH 9.3EPSS 14.7% | 10 October 2012 |
| CVE-2012-4186 | Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to… | HIGH 9.3EPSS 14.7% | 10 October 2012 |
| CVE-2012-3993 | The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures of… | EXPLOIT ✓HIGH 9.3EPSS 42.6% | 10 October 2012 |
| CVE-2012-4399 | The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack. | EXPLOIT ✓HIGH 7.5EPSS 12.1% | 9 October 2012 |
| CVE-2012-2552 | Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML… | MEDIUM 4.3EPSS 16.3% | 9 October 2012 |
| CVE-2012-2551 | The server in Kerberos in Microsoft Windows Server 2008 R2 and R2 SP1, and Windows 7 Gold and SP1, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted session request, aka "Kerberos NULL Dereference… | MEDIUM 5.0EPSS 27.5% | 9 October 2012 |
| CVE-2012-2550 | Microsoft Works 9 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Word .doc file, aka "Works Heap Vulnerability." | HIGH 9.3EPSS 22.2% | 9 October 2012 |
| CVE-2012-2528 | Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; Word Automation Services on Microsoft SharePoint Server 2010; and Office Web Apps 2010 SP1 allows remote… | HIGH 9.3EPSS 22.1% | 9 October 2012 |
| CVE-2012-2520 | Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0… | MEDIUM 4.3EPSS 28.5% | 9 October 2012 |
| CVE-2012-0182 | Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability." | HIGH 9.3EPSS 68.3% | 9 October 2012 |
| CVE-2012-5321 | tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection." | EXPLOIT ✓MEDIUM 5.8EPSS 13.8% | 8 October 2012 |
| CVE-2011-4929 | Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors. | EXPLOIT ✓HIGH 7.5EPSS 46.4% | 8 October 2012 |
| CVE-2011-4342 | PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter. | EXPLOITHIGH 7.5EPSS 10.7% | 8 October 2012 |
| CVE-2012-1125 | Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with a PHP extension, then accessing it via a… | EXPLOITMEDIUM 6.8EPSS 11.6% | 8 October 2012 |
| CVE-2010-5278 | Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 18.6% | 7 October 2012 |
| CVE-2012-5306 | Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as used in D-Link DCS-5605 PTZ IP Network Camera, allows remote attackers to cause a denial of service (crash) and possibly execute… | EXPLOIT ✓HIGH 9.3EPSS 12.1% | 6 October 2012 |
| CVE-2012-1153 | Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 32.4% | 6 October 2012 |
| CVE-2012-5223 | The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted… | EXPLOIT ✓HIGH 7.5EPSS 40.5% | 1 October 2012 |
| CVE-2012-4415 | Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name. | EXPLOIT ✓HIGH 7.5EPSS 13.6% | 1 October 2012 |
| CVE-2012-0419 | Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrary files via directory traversal sequences in a request. | MEDIUM 5.0EPSS 42.5% | 28 September 2012 |
| CVE-2012-2897 | The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before… | HIGH 7.8EPSS 21.7% | 26 September 2012 |
| CVE-2012-5159 | phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via… | EXPLOIT ✓HIGH 7.5EPSS 74.5% | 25 September 2012 |
| CVE-2012-0209 | Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js,… | EXPLOIT ✓HIGH 7.5EPSS 71.9% | 25 September 2012 |
| CVE-2012-3261 | Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1463. | HIGH 10.0EPSS 40.2% | 25 September 2012 |
| CVE-2012-3260 | Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1462. | HIGH 10.0EPSS 40.2% | 25 September 2012 |
| CVE-2012-3259 | Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1461. | HIGH 10.0EPSS 60.2% | 25 September 2012 |
| CVE-2012-5054 | Adobe Flash Player Integer Overflow Vulnerability | KEVHIGH 8.8EPSS 21.2% | 24 September 2012 |
| CVE-2012-3137 | The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and… | EXPLOITMEDIUM 6.4EPSS 31.4% | 21 September 2012 |
| CVE-2012-2557 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "cloneNode Use After Free Vulnerability." | HIGH 9.3EPSS 19.5% | 21 September 2012 |
| CVE-2012-2548 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Layout Use After Free Vulnerability." | HIGH 9.3EPSS 19.5% | 21 September 2012 |
| CVE-2012-2546 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Event Listener Use After Free Vulnerability." | HIGH 9.3EPSS 20.2% | 21 September 2012 |
| CVE-2012-1529 | Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly initialized or (2) is deleted, aka "OnMove Use After… | HIGH 9.3EPSS 20.2% | 21 September 2012 |
| CVE-2011-5181 | Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 10.4% | 20 September 2012 |
| CVE-2012-5002 | Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 31.2% | 19 September 2012 |
| CVE-2012-4992 | Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox. | EXPLOITHIGH 9.0EPSS 17.7% | 19 September 2012 |
| CVE-2012-0271 | Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a… | EXPLOIT ✓HIGH 10.0EPSS 17.2% | 19 September 2012 |
| CVE-2012-1184 | Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in an… | EXPLOITHIGH 7.5EPSS 16.4% | 18 September 2012 |
| CVE-2012-4969 | Microsoft Internet Explorer Use-After-Free Vulnerability | KEVEXPLOIT ✓HIGH 8.1EPSS 81.7% | 18 September 2012 |
| CVE-2012-4924 | Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long parameter to the Alert method. | EXPLOIT ✓HIGH 9.3EPSS 36.3% | 15 September 2012 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.