Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 243 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2012-4329 | The Samsung D6000 TV and possibly other products allow remote attackers to cause a denial of service (continuous restart) via a crafted controller name. | EXPLOIT ×2 ✓HIGH 7.8EPSS 13.3% | 14 August 2012 |
| CVE-2012-2371 | Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pagination_wp_facethumb parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 12.8% | 13 August 2012 |
| CVE-2012-2577 | Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an… | EXPLOIT ✓MEDIUM 4.3EPSS 10.2% | 12 August 2012 |
| CVE-2012-4177 | The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line argument. | EXPLOIT ✓HIGH 10.0EPSS 58.0% | 7 August 2012 |
| CVE-2012-3450 | pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds… | EXPLOIT ✓LOW 2.6EPSS 11.2% | 6 August 2012 |
| CVE-2012-3951 | The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via… | EXPLOIT ✓HIGH 7.5EPSS 52.0% | 31 July 2012 |
| CVE-2012-2626 | cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action. | EXPLOIT ✓MEDIUM 5.0EPSS 44.5% | 31 July 2012 |
| CVE-2012-2962 | SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter. | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 66.8% | 30 July 2012 |
| CVE-2011-2657 | Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute… | EXPLOIT ✓MEDIUM 6.8EPSS 48.4% | 26 July 2012 |
| CVE-2012-3817 | ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote… | HIGH 7.8EPSS 23.7% | 25 July 2012 |
| CVE-2012-3571 | ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier. | EXPLOIT ✓MEDIUM 6.1EPSS 13.0% | 25 July 2012 |
| CVE-2012-2957 | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue. | EXPLOIT ✓HIGH 7.2EPSS 59.3% | 23 July 2012 |
| CVE-2012-2953 | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts. | EXPLOIT ×2 ✓HIGH 10.0EPSS 67.4% | 23 July 2012 |
| CVE-2012-2738 | The VteTerminal in gnome-terminal (vte) before 0.32.2 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value. | EXPLOIT ✓MEDIUM 4.0EPSS 11.2% | 22 July 2012 |
| CVE-2012-2688 | Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow." | HIGH 10.0EPSS 10.5% | 20 July 2012 |
| CVE-2012-0284 | Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the… | EXPLOIT ×2 ✓HIGH 9.3EPSS 36.3% | 19 July 2012 |
| CVE-2012-4032 | Open redirect vulnerability in the login page in WebsitePanel before 1.2.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in ReturnUrl to Default.aspx. | EXPLOIT ✓MEDIUM 5.8EPSS 10.3% | 17 July 2012 |
| CVE-2012-4031 | Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 52.3% | 17 July 2012 |
| CVE-2012-3236 | fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string. | EXPLOITMEDIUM 4.3EPSS 10.7% | 12 July 2012 |
| CVE-2012-1661 | ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file. | EXPLOITHIGH 9.3EPSS 23.8% | 12 July 2012 |
| CVE-2012-3399 | Config/diff.php in Basilic 1.5.14 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter. | EXPLOIT ✓HIGH 7.5EPSS 65.3% | 12 July 2012 |
| CVE-2012-2763 | Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server. | EXPLOIT ×2 ✓HIGH 7.5EPSS 81.7% | 12 July 2012 |
| CVE-2012-0911 | TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a)… | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 63.0% | 12 July 2012 |
| CVE-2012-2020 | Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1326. | EXPLOIT ✓HIGH 10.0EPSS 64.7% | 11 July 2012 |
| CVE-2012-2019 | Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1325. | EXPLOIT ✓HIGH 10.0EPSS 64.7% | 11 July 2012 |
| CVE-2012-1891 | Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in… | CRITICAL 9.8EPSS 29.4% | 10 July 2012 |
| CVE-2012-1863 | Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted… | MEDIUM 4.3EPSS 23.1% | 10 July 2012 |
| CVE-2012-1862 | Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "SharePoint URL Redirection Vulnerability." | MEDIUM 6.8EPSS 10.8% | 10 July 2012 |
| CVE-2012-1861 | Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted… | MEDIUM 4.3EPSS 15.4% | 10 July 2012 |
| CVE-2012-1860 | Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information… | MEDIUM 5.5EPSS 13.0% | 10 July 2012 |
| CVE-2012-1859 | Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML… | MEDIUM 4.3EPSS 23.1% | 10 July 2012 |
| CVE-2012-1854 | Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability | KEVHIGH 7.8EPSS 21.0% | 10 July 2012 |
| CVE-2012-1524 | Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Attribute Remove Remote Code Execution Vulnerability." | HIGH 9.3EPSS 21.5% | 10 July 2012 |
| CVE-2012-1522 | Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Cached Object Remote Code Execution Vulnerability." | HIGH 9.3EPSS 20.9% | 10 July 2012 |
| CVE-2012-0175 | The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted name for a (1) file or (2)… | HIGH 8.8EPSS 26.1% | 10 July 2012 |
| CVE-2012-2138 | The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service… | EXPLOIT ✓MEDIUM 5.0EPSS 14.1% | 9 July 2012 |
| CVE-2012-1493 | F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across… | EXPLOIT ×3 ✓HIGH 7.8EPSS 63.1% | 9 July 2012 |
| CVE-2012-2386 | Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar… | EXPLOITHIGH 7.5EPSS 42.5% | 7 July 2012 |
| CVE-2012-2516 | An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6;… | EXPLOIT ✓HIGH 9.3EPSS 39.7% | 5 July 2012 |
| CVE-2012-2515 | Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EMC Captiva Quickscan Pro 4.6 SP1;… | HIGH 9.3EPSS 27.6% | 5 July 2012 |
| CVE-2012-1831 | Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555. | EXPLOIT ✓HIGH 10.0EPSS 15.9% | 5 July 2012 |
| CVE-2012-3811 | Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 before 7.0.5.8 Q1 2012 Maintenance Release and 8.0 before 8.0.9.13 Q1 2012 Maintenance Release allows remote attackers… | EXPLOIT ✓HIGH 10.0EPSS 62.9% | 3 July 2012 |
| CVE-2012-2385 | The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value. | EXPLOIT ✓MEDIUM 4.0EPSS 10.9% | 29 June 2012 |
| CVE-2012-2098 | Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many… | MEDIUM 5.0EPSS 12.6% | 29 June 2012 |
| CVE-2012-3815 | Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 46824. | EXPLOIT ×2 ✓HIGH 9.3EPSS 44.2% | 27 June 2012 |
| CVE-2012-3814 | Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a .php.ttf extension, then accessing it via a direct request to… | EXPLOIT ✓HIGH 7.5EPSS 10.3% | 27 June 2012 |
| CVE-2012-2122 | sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain… | EXPLOIT ✓MEDIUM 5.1EPSS 96.5% | 26 June 2012 |
| CVE-2012-3797 | Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, does not properly check packet sizes before reusing packet memory buffers, which allows remote attackers to cause a denial of service (heap… | EXPLOIT ✓HIGH 10.0EPSS 12.2% | 25 June 2012 |
| CVE-2012-3796 | Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sensitive information from daemon memory via a crafted packet with a certain opcode. | EXPLOIT ✓MEDIUM 5.0EPSS 10.6% | 25 June 2012 |
| CVE-2012-3795 | Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode and a large value in a size… | EXPLOIT ✓MEDIUM 5.0EPSS 10.9% | 25 June 2012 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.