Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 250 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-5071 | The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information… | MEDIUM 5.0EPSS 12.7% | 7 December 2011 |
| CVE-2002-2435 | The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML… | MEDIUM 4.3EPSS 13.7% | 7 December 2011 |
| CVE-2011-4130 | Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer. | HIGH 9.0EPSS 12.6% | 6 December 2011 |
| CVE-2011-4051 | CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and… | EXPLOIT ✓HIGH 10.0EPSS 69.1% | 5 December 2011 |
| CVE-2011-4034 | Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause… | HIGH 9.3EPSS 13.4% | 2 December 2011 |
| CVE-2011-4161 | The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500… | HIGH 10.0EPSS 13.9% | 1 December 2011 |
| CVE-2011-4542 | Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI. | EXPLOIT ✓HIGH 7.5EPSS 24.1% | 30 November 2011 |
| CVE-2011-4317 | The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern… | EXPLOIT ✓MEDIUM 4.3EPSS 59.6% | 30 November 2011 |
| CVE-2011-4191 | Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (abend or NFS outage) via long packets. | EXPLOIT ×3 ✓HIGH 7.5EPSS 10.2% | 30 November 2011 |
| CVE-2011-3639 | The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of… | EXPLOIT ✓MEDIUM 4.3EPSS 50.6% | 30 November 2011 |
| CVE-2011-4313 | query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named… | MEDIUM 5.0EPSS 16.2% | 29 November 2011 |
| CVE-2011-4496 | Buffer overflow in Aviosoft DTV Player 1.0.1.2 allows remote attackers to execute arbitrary code via a crafted .plf (aka playlist) file. | HIGH 9.3EPSS 11.1% | 21 November 2011 |
| CVE-2011-4040 | Buffer overflow in MiniSmtp 3.0.11818 in NJStar Communicator allows remote attackers to execute arbitrary code via a crafted packet. | EXPLOIT ×2 ✓HIGH 10.0EPSS 65.3% | 21 November 2011 |
| CVE-2011-4404 | The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via… | EXPLOITMEDIUM 5.0EPSS 59.7% | 19 November 2011 |
| CVE-2011-4107 | The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity… | EXPLOITMEDIUM 6.5EPSS 12.7% | 17 November 2011 |
| CVE-2011-4096 | The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an… | MEDIUM 5.0EPSS 37.2% | 17 November 2011 |
| CVE-2011-4157 | Stack-based buffer overflow in hydra.exe in HP SAN/iQ before 9.5 on the HP StorageWorks P4000 Virtual SAN Appliance allows remote attackers to execute arbitrary code via a crafted login request. | HIGH 10.0EPSS 13.2% | 16 November 2011 |
| CVE-2011-2014 | The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2,… | HIGH 9.0EPSS 11.0% | 8 November 2011 |
| CVE-2011-2013 | Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed… | EXPLOIT ✓CRITICAL 9.8EPSS 33.7% | 8 November 2011 |
| CVE-2011-2004 | Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font… | HIGH 7.1EPSS 24.6% | 8 November 2011 |
| CVE-2011-3402 | Microsoft Windows Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 78.1% | 4 November 2011 |
| CVE-2011-4075 | The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October… | EXPLOIT ×2 ✓HIGH 7.5EPSS 51.9% | 2 November 2011 |
| CVE-2011-3167 | Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210. | EXPLOIT ✓HIGH 10.0EPSS 66.4% | 2 November 2011 |
| CVE-2011-3166 | Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1209. | HIGH 10.0EPSS 12.0% | 2 November 2011 |
| CVE-2011-3165 | Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1208. | HIGH 10.0EPSS 12.0% | 2 November 2011 |
| CVE-2010-4977 | SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the mealid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 15.3% | 1 November 2011 |
| CVE-2011-3315 | Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP… | EXPLOIT ✓HIGH 7.8EPSS 25.7% | 27 October 2011 |
| CVE-2011-3310 | The Home Page component in Cisco CiscoWorks Common Services before 4.1 on Windows, as used in CiscoWorks LAN Management Solution, Cisco Security Manager, Cisco Unified Service Monitor, Cisco Unified Operations Manager, CiscoWorks QoS Policy Manager, and… | HIGH 9.0EPSS 15.2% | 20 October 2011 |
| CVE-2011-3556 | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect… | EXPLOIT ✓HIGH 7.5EPSS 76.4% | 19 October 2011 |
| CVE-2011-3544 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 96.7% | 19 October 2011 |
| CVE-2011-3162 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1296. | HIGH 10.0EPSS 11.7% | 19 October 2011 |
| CVE-2011-3161 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1229. | HIGH 10.0EPSS 11.7% | 19 October 2011 |
| CVE-2011-3160 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1228. | HIGH 10.0EPSS 11.7% | 19 October 2011 |
| CVE-2011-3159 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1227. | HIGH 10.0EPSS 11.7% | 19 October 2011 |
| CVE-2011-3158 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1226. | HIGH 10.0EPSS 11.7% | 19 October 2011 |
| CVE-2011-3157 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1225. | HIGH 10.0EPSS 11.7% | 19 October 2011 |
| CVE-2011-3156 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1222. | HIGH 10.0EPSS 11.7% | 19 October 2011 |
| CVE-2011-3230 | Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via a crafted web site. | EXPLOIT ✓MEDIUM 6.8EPSS 49.3% | 14 October 2011 |
| CVE-2011-2012 | Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null… | MEDIUM 5.0EPSS 16.6% | 12 October 2011 |
| CVE-2011-2008 | Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability." | MEDIUM 5.0EPSS 21.3% | 12 October 2011 |
| CVE-2011-2007 | Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability." | EXPLOIT ✓MEDIUM 5.0EPSS 23.0% | 12 October 2011 |
| CVE-2011-2005 | Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 31.5% | 12 October 2011 |
| CVE-2011-2003 | Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary… | EXPLOIT ✓HIGH 9.3EPSS 26.6% | 12 October 2011 |
| CVE-2011-2001 | Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an attempted access to a virtual function table after corruption of this table has occurred, aka "Virtual… | HIGH 9.3EPSS 43.1% | 12 October 2011 |
| CVE-2011-2000 | Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Body Element Remote Code Execution Vulnerability." | HIGH 9.3EPSS 18.9% | 12 October 2011 |
| CVE-2011-1999 | Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arbitrary code via vectors involving a "dereferenced memory address," aka "Select Element Remote Code Execution Vulnerability." | EXPLOIT ✓HIGH 9.3EPSS 26.7% | 12 October 2011 |
| CVE-2011-1998 | Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "Jscript9.dll Remote Code Execution Vulnerability." | HIGH 9.3EPSS 21.2% | 12 October 2011 |
| CVE-2011-1997 | Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnLoad Event Remote Code Execution Vulnerability." | HIGH 9.3EPSS 14.5% | 12 October 2011 |
| CVE-2011-1996 | Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability." | EXPLOIT ✓HIGH 9.3EPSS 58.8% | 12 October 2011 |
| CVE-2011-1995 | Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "OLEAuto32.dll Remote Code Execution Vulnerability." | HIGH 9.3EPSS 28.9% | 12 October 2011 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.