Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 259 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-3955 | pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perform array indexing, which allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Array… | HIGH 9.3EPSS 18.9% | 16 December 2010 |
| CVE-2010-3954 | Microsoft Publisher 2002 SP3, 2003 SP3, and 2010 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Publisher file, aka "Microsoft Publisher Memory Corruption Vulnerability." | HIGH 9.3EPSS 20.8% | 16 December 2010 |
| CVE-2010-3952 | The FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted FlashPix image in an Office… | HIGH 9.3EPSS 20.8% | 16 December 2010 |
| CVE-2010-3951 | Buffer overflow in the FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted FlashPix image in an Office document, aka "FlashPix Image… | HIGH 9.3EPSS 25.1% | 16 December 2010 |
| CVE-2010-3950 | The TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 does not properly convert data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via… | HIGH 9.3EPSS 20.8% | 16 December 2010 |
| CVE-2010-3949 | Buffer overflow in the TIFF image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted TIFF image in an Office document, aka "TIFF Image Converter Buffer… | HIGH 9.3EPSS 25.1% | 16 December 2010 |
| CVE-2010-3947 | Heap-based buffer overflow in the TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 allows remote attackers to execute arbitrary code via a crafted TIFF image in an Office document, aka "TIFF… | HIGH 9.3EPSS 29.3% | 16 December 2010 |
| CVE-2010-3946 | Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image… | HIGH 9.3EPSS 21.6% | 16 December 2010 |
| CVE-2010-3945 | Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image… | HIGH 9.3EPSS 25.1% | 16 December 2010 |
| CVE-2010-3937 | Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability." | MEDIUM 4.0EPSS 18.7% | 16 December 2010 |
| CVE-2010-3348 | Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cross-Domain Information Disclosure… | MEDIUM 4.3EPSS 13.6% | 16 December 2010 |
| CVE-2010-3346 | Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka… | HIGH 9.3EPSS 28.9% | 16 December 2010 |
| CVE-2010-3345 | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML… | HIGH 9.3EPSS 28.9% | 16 December 2010 |
| CVE-2010-3343 | Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML… | HIGH 9.3EPSS 28.9% | 16 December 2010 |
| CVE-2010-3342 | Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cross-Domain Information Disclosure… | MEDIUM 4.3EPSS 13.6% | 16 December 2010 |
| CVE-2010-3340 | Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka… | HIGH 9.3EPSS 25.3% | 16 December 2010 |
| CVE-2010-3338 | The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the security context of scheduled tasks, which allows local users to gain privileges via a crafted… | EXPLOIT ×2 ✓HIGH 7.2EPSS 21.7% | 16 December 2010 |
| CVE-2010-2742 | The Netlogon RPC Service in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, and R2, when the domain controller role is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted RPC… | MEDIUM 5.4EPSS 29.6% | 16 December 2010 |
| CVE-2010-2571 | Array index error in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher 97 file, aka "Memory Corruption Due To Invalid Index Into Array in… | HIGH 9.3EPSS 21.8% | 16 December 2010 |
| CVE-2010-2570 | Heap-based buffer overflow in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, 2007 SP2, and 2010 allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka… | HIGH 9.3EPSS 25.1% | 16 December 2010 |
| CVE-2010-2569 | pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a… | HIGH 9.3EPSS 21.0% | 16 December 2010 |
| CVE-2010-4345 | Exim Privilege Escalation Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 18.0% | 14 December 2010 |
| CVE-2010-4344 | Exim Heap-Based Buffer Overflow Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 71.7% | 14 December 2010 |
| CVE-2010-4259 | Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long CHARSET_REGISTRY header in a BDF font file. | EXPLOITMEDIUM 6.8EPSS 10.9% | 7 December 2010 |
| CVE-2010-4409 | Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument. | EXPLOITMEDIUM 5.0EPSS 18.9% | 6 December 2010 |
| CVE-2010-3904 | Linux Kernel Improper Input Validation Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 14.5% | 6 December 2010 |
| CVE-2010-4254 | Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call. | EXPLOIT ✓HIGH 7.5EPSS 13.6% | 6 December 2010 |
| CVE-2010-3614 | named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers… | MEDIUM 6.4EPSS 14.5% | 6 December 2010 |
| CVE-2010-4282 | Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote… | EXPLOITHIGH 7.5EPSS 19.6% | 2 December 2010 |
| CVE-2010-4279 | The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in… | EXPLOIT ×2 ✓HIGH 10.0EPSS 65.6% | 2 December 2010 |
| CVE-2010-4278 | operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to index.php. | EXPLOIT ✓HIGH 9.0EPSS 11.3% | 2 December 2010 |
| CVE-2010-4367 | awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on a (1) WebDAV server or (2) NFS server. | EXPLOIT ✓HIGH 7.5EPSS 27.7% | 2 December 2010 |
| CVE-2010-4172 | Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to… | EXPLOIT ✓MEDIUM 4.3EPSS 42.0% | 26 November 2010 |
| CVE-2010-4300 | Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly… | EXPLOIT ✓HIGH 7.5EPSS 13.8% | 26 November 2010 |
| CVE-2010-4107 | The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers enables PJL commands that use the… | EXPLOIT ×4 ✓HIGH 7.8EPSS 13.2% | 17 November 2010 |
| CVE-2010-3864 | Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, when multi-threading and internal caching are enabled on a TLS server, might allow remote attackers to execute arbitrary code via client data that triggers a… | HIGH 7.6EPSS 22.1% | 17 November 2010 |
| CVE-2010-4231 | Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 16.0% | 17 November 2010 |
| CVE-2010-3894 | Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface in IBM OmniFind Enterprise Edition before 8.5 FP6 allows remote attackers… | EXPLOITHIGH 9.3EPSS 12.0% | 12 November 2010 |
| CVE-2010-3870 | The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection… | EXPLOIT ✓MEDIUM 6.8EPSS 11.3% | 12 November 2010 |
| CVE-2010-4156 | The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter). | EXPLOIT ✓MEDIUM 5.0EPSS 12.8% | 10 November 2010 |
| CVE-2010-3936 | Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS in… | MEDIUM 4.3EPSS 18.8% | 10 November 2010 |
| CVE-2010-3337 | Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141… | HIGH 9.3EPSS 10.9% | 10 November 2010 |
| CVE-2010-3336 | Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "MSO Large SPID… | HIGH 9.3EPSS 23.9% | 10 November 2010 |
| CVE-2010-3335 | Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that… | HIGH 9.3EPSS 23.9% | 10 November 2010 |
| CVE-2010-3334 | Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Office document containing an… | HIGH 9.3EPSS 25.5% | 10 November 2010 |
| CVE-2010-3333 | Microsoft Office Stack-based Buffer Overflow Vulnerability | KEVEXPLOIT ×4 ✓HIGH 7.8EPSS 89.5% | 10 November 2010 |
| CVE-2010-2734 | Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka… | MEDIUM 4.3EPSS 14.2% | 10 November 2010 |
| CVE-2010-2733 | Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG… | MEDIUM 4.3EPSS 14.2% | 10 November 2010 |
| CVE-2010-2732 | Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via… | MEDIUM 5.8EPSS 13.4% | 10 November 2010 |
| CVE-2010-2573 | Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Integer Underflow Causes Heap Corruption… | HIGH 9.3EPSS 20.3% | 10 November 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.