Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 242 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2011-5171 | Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to execute arbitrary code via the (1) src and (2) name parameters in a p2g project file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 45.8% | 15 September 2012 |
| CVE-2011-5170 | Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u playlist. | EXPLOIT ×2 ✓HIGH 9.3EPSS 32.0% | 15 September 2012 |
| CVE-2011-5165 | Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wav file. | EXPLOIT ×8 ✓HIGH 9.3EPSS 37.0% | 15 September 2012 |
| CVE-2011-5164 | Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response. | EXPLOIT ✓HIGH 9.3EPSS 28.6% | 15 September 2012 |
| CVE-2012-4244 | ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record. | HIGH 7.8EPSS 36.8% | 14 September 2012 |
| CVE-2012-3955 | ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later reduced. | HIGH 7.1EPSS 21.7% | 14 September 2012 |
| CVE-2012-2983 | file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field. | MEDIUM 5.0EPSS 20.5% | 11 September 2012 |
| CVE-2012-2982 | file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character. | EXPLOIT ✓MEDIUM 6.5EPSS 62.2% | 11 September 2012 |
| CVE-2012-2536 | Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS… | MEDIUM 4.3EPSS 16.2% | 11 September 2012 |
| CVE-2012-1892 | Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability." | MEDIUM 4.3EPSS 16.5% | 11 September 2012 |
| CVE-2012-4876 | Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long string to the OpenFileDlg method. | EXPLOIT ×2 ✓HIGH 10.0EPSS 71.2% | 6 September 2012 |
| CVE-2012-4869 | The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter in a c action. | EXPLOIT ×3 ✓HIGH 7.5EPSS 70.3% | 6 September 2012 |
| CVE-2011-4451 | libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the spamlog_path file via the User-Agent HTTP header in an addcomment request. | EXPLOITMEDIUM 4.3EPSS 14.2% | 5 September 2012 |
| CVE-2012-2288 | Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via format string specifiers in a message. | EXPLOIT ✓HIGH 9.3EPSS 33.1% | 4 September 2012 |
| CVE-2010-5193 | Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewer CP Pro 8.0 and Gold 6.0 allows remote attackers to execute arbitrary code via a long strDelimit… | EXPLOIT ×2 ✓HIGH 9.3EPSS 32.0% | 31 August 2012 |
| CVE-2012-4170 | Buffer overflow in Adobe Photoshop CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted file. | EXPLOIT ✓HIGH 9.3EPSS 11.0% | 31 August 2012 |
| CVE-2012-0547 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly… | EXPLOIT ✓LOW 0.0EPSS 12.5% | 30 August 2012 |
| CVE-2011-5130 | dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the argv[1] parameter. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 36.5% | 30 August 2012 |
| CVE-2011-1398 | The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a… | EXPLOIT ✓MEDIUM 4.3EPSS 10.2% | 30 August 2012 |
| CVE-2012-3579 | Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain privileged access via an SSH session. | EXPLOIT ✓HIGH 7.9EPSS 40.2% | 29 August 2012 |
| CVE-2011-4926 | Cross-site scripting (XSS) vulnerability in adminimize/adminimize_page.php in the Adminimize plugin before 1.7.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 10.9% | 29 August 2012 |
| CVE-2012-4681 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 98.5% | 28 August 2012 |
| CVE-2011-5127 | Directory traversal vulnerability in Blue Coat Reporter 9.x before 9.2.4.13, 9.2.5.x before 9.2.5.1, and 9.3 before 9.3.1.2 on Windows allows remote attackers to read arbitrary files, and consequently execute arbitrary code, via an unspecified HTTP… | EXPLOITHIGH 10.0EPSS 13.2% | 26 August 2012 |
| CVE-2011-5124 | Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 and ProxyOne, allows remote attackers to execute arbitrary code via a large packet to the synchronization port (16102/tcp). | EXPLOIT ✓HIGH 10.0EPSS 54.6% | 26 August 2012 |
| CVE-2011-5106 | Cross-site scripting (XSS) vulnerability in edit-post.php in the Flexible Custom Post Type plugin before 0.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 10.9% | 23 August 2012 |
| CVE-2012-2687 | Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to… | LOW 2.6EPSS 22.5% | 22 August 2012 |
| CVE-2012-4598 | An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to execute arbitrary code or cause a denial of service (Internet Explorer crash) via a crafted web site. | EXPLOIT ×2 ✓HIGH 9.3EPSS 29.4% | 22 August 2012 |
| CVE-2012-4361 | lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the second parameter. | EXPLOIT ×2 ✓HIGH 7.7EPSS 47.8% | 20 August 2012 |
| CVE-2012-3456 | Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute… | EXPLOIT ✓HIGH 7.5EPSS 20.1% | 20 August 2012 |
| CVE-2012-4356 | Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allow remote attackers to read arbitrary files via port-46824 TCP packets specifying a file-open operation with opcode… | EXPLOIT ✓MEDIUM 4.3EPSS 27.4% | 19 August 2012 |
| CVE-2012-4353 | Stack-based buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allows remote attackers to execute arbitrary code via a crafted port-46824 TCP packet that triggers an incorrect file-open… | EXPLOIT ✓HIGH 9.3EPSS 24.7% | 19 August 2012 |
| CVE-2012-4157 | Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051,… | HIGH 10.0EPSS 45.8% | 15 August 2012 |
| CVE-2012-2050 | Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors. | HIGH 10.0EPSS 13.2% | 15 August 2012 |
| CVE-2012-2049 | Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors. | HIGH 10.0EPSS 13.2% | 15 August 2012 |
| CVE-2012-1535 | Adobe Flash Player Arbitrary Code Execution Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 70.4% | 15 August 2012 |
| CVE-2012-1525 | Heap-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors. | HIGH 10.0EPSS 31.8% | 15 August 2012 |
| CVE-2012-2526 | The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP3 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to a deleted object, aka… | HIGH 9.3EPSS 25.0% | 15 August 2012 |
| CVE-2012-2524 | Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability." | HIGH 9.3EPSS 20.1% | 15 August 2012 |
| CVE-2012-2523 | Integer overflow in Microsoft Internet Explorer 8 and 9, JScript 5.8, and VBScript 5.8 on 64-bit platforms allows remote attackers to execute arbitrary code by leveraging an incorrect size calculation during object copying, aka "JavaScript Integer… | HIGH 9.3EPSS 22.2% | 15 August 2012 |
| CVE-2012-2522 | Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a malformed virtual function table after this table's deletion, aka "Virtual Function Table… | HIGH 9.3EPSS 24.5% | 15 August 2012 |
| CVE-2012-2521 | Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Asynchronous NULL Object Access Remote Code Execution Vulnerability." | HIGH 9.3EPSS 20.9% | 15 August 2012 |
| CVE-2012-1888 | Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer Overflow Vulnerability." | HIGH 9.3EPSS 24.2% | 15 August 2012 |
| CVE-2012-1856 | Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 72.0% | 15 August 2012 |
| CVE-2012-1853 | Stack-based buffer overflow in the Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP3 allows remote attackers to execute arbitrary code via crafted RAP response packets, aka "Remote… | HIGH 10.0EPSS 29.0% | 15 August 2012 |
| CVE-2012-1852 | Heap-based buffer overflow in the Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted RAP response packets, aka "Remote… | HIGH 10.0EPSS 29.0% | 15 August 2012 |
| CVE-2012-1851 | Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary… | HIGH 10.0EPSS 65.6% | 15 August 2012 |
| CVE-2012-1850 | The Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not… | MEDIUM 5.0EPSS 27.5% | 15 August 2012 |
| CVE-2012-1526 | Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not initialized or (2) is deleted, aka "Layout Memory Corruption Vulnerability." | HIGH 9.3EPSS 20.0% | 15 August 2012 |
| CVE-2012-4333 | Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow remote attackers to execute arbitrary code via a long string in the fname… | EXPLOIT ×2 ✓HIGH 10.0EPSS 59.6% | 14 August 2012 |
| CVE-2012-4330 | The Samsung D6000 TV and possibly other products allows remote attackers to cause a denial of service (crash) via a long string in certain fields, as demonstrated by the MAC address field, possibly a buffer overflow. | EXPLOIT ×2 ✓HIGH 7.8EPSS 13.9% | 14 August 2012 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.