Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 260 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-2572 | Microsoft PowerPoint Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 62.5% | 10 November 2010 |
| CVE-2010-4221 | Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server. | EXPLOIT ×3 ✓HIGH 10.0EPSS 91.3% | 9 November 2010 |
| CVE-2010-3709 | The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive. | EXPLOITMEDIUM 4.3EPSS 13.3% | 9 November 2010 |
| CVE-2010-4091 | The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF… | EXPLOIT ✓HIGH 9.3EPSS 18.5% | 7 November 2010 |
| CVE-2010-3639 | Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown… | EXPLOIT ✓HIGH 9.3EPSS 21.6% | 7 November 2010 |
| CVE-2010-3962 | Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability | KEVEXPLOIT ×3 ✓HIGH 8.1EPSS 96.8% | 5 November 2010 |
| CVE-2010-3863 | Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the… | EXPLOIT ✓MEDIUM 5.0EPSS 54.5% | 5 November 2010 |
| CVE-2010-4182 | Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users,… | HIGH 9.3EPSS 24.2% | 4 November 2010 |
| CVE-2010-4142 | Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) SCPC_INITIALIZE, (2) SCPC_INITIALIZE_RF, or (3)… | EXPLOIT ×5 ✓HIGH 10.0EPSS 63.0% | 2 November 2010 |
| CVE-2010-3654 | Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows… | EXPLOIT ×2 ✓HIGH 9.3EPSS 69.7% | 29 October 2010 |
| CVE-2010-3765 | Mozilla Multiple Products Remote Code Execution Vulnerability | KEVEXPLOIT ×4 ✓CRITICAL 9.8EPSS 83.2% | 28 October 2010 |
| CVE-2010-2891 | Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by . | EXPLOIT ✓HIGH 7.5EPSS 14.0% | 28 October 2010 |
| CVE-2010-3227 | Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows… | EXPLOIT ✓HIGH 9.3EPSS 20.8% | 26 October 2010 |
| CVE-2010-4094 | The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role. | EXPLOIT ✓MEDIUM 5.0EPSS 64.5% | 26 October 2010 |
| CVE-2010-3653 | The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted rcsL chunk containing a field whose value… | EXPLOIT ×2 ✓HIGH 9.3EPSS 74.6% | 26 October 2010 |
| CVE-2010-3714 | The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote… | EXPLOITHIGH 7.1EPSS 24.1% | 25 October 2010 |
| CVE-2010-3179 | Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code or… | EXPLOIT ✓HIGH 9.3EPSS 10.1% | 21 October 2010 |
| CVE-2010-3573 | Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOITMEDIUM 5.1EPSS 10.6% | 19 October 2010 |
| CVE-2010-3563 | Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ✓HIGH 10.0EPSS 84.3% | 19 October 2010 |
| CVE-2010-3552 | Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ×2 ✓HIGH 10.0EPSS 80.7% | 19 October 2010 |
| CVE-2010-3749 | The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, which allows remote attackers to download an arbitrary program onto a client… | EXPLOITHIGH 9.3EPSS 25.6% | 19 October 2010 |
| CVE-2010-3747 | An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly initialize an unspecified object component during parsing of a CDDA URI, which allows remote attackers to… | EXPLOIT ✓HIGH 9.3EPSS 34.8% | 19 October 2010 |
| CVE-2010-0219 | Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by… | EXPLOIT ×3 ✓HIGH 10.0EPSS 90.9% | 18 October 2010 |
| CVE-2010-3585 | Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. | EXPLOIT ✓HIGH 9.0EPSS 52.1% | 14 October 2010 |
| CVE-2010-3331 | Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory in certain circumstances involving use of Microsoft Word to read Word documents, which allows remote attackers to execute arbitrary code by accessing an object that (1)… | HIGH 9.3EPSS 25.0% | 13 October 2010 |
| CVE-2010-3330 | Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Cross-Domain Information… | MEDIUM 6.5EPSS 22.3% | 13 October 2010 |
| CVE-2010-3329 | mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Microsoft Office document that causes the HtmlDlgHelper class destructor to access uninitialized memory, aka "Uninitialized Memory… | EXPLOIT ✓HIGH 9.3EPSS 28.4% | 13 October 2010 |
| CVE-2010-3328 | Use-after-free vulnerability in the CAttrArray::PrivateFind function in mshtml.dll in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code by setting an unspecified property of a stylesheet object, aka "Uninitialized… | HIGH 8.8EPSS 31.9% | 13 October 2010 |
| CVE-2010-3327 | The implementation of HTML content creation in Microsoft Internet Explorer 6 through 8 does not remove the Anchor element during pasting and editing, which might allow remote attackers to obtain sensitive deleted information by visiting a web page, aka… | MEDIUM 4.3EPSS 14.4% | 13 October 2010 |
| CVE-2010-3326 | Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka… | HIGH 9.3EPSS 24.9% | 13 October 2010 |
| CVE-2010-3325 | Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allows remote attackers to obtain sensitive information from a different (1) domain or (2) zone via a… | EXPLOIT ✓MEDIUM 4.3EPSS 22.0% | 13 October 2010 |
| CVE-2010-3243 | Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject… | MEDIUM 4.3EPSS 15.7% | 13 October 2010 |
| CVE-2010-3242 | Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type… | HIGH 9.3EPSS 21.0% | 13 October 2010 |
| CVE-2010-3241 | Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka… | HIGH 9.3EPSS 21.0% | 13 October 2010 |
| CVE-2010-3240 | Microsoft Excel 2002 SP3 and 2007 SP2; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information, which allows remote attackers to execute arbitrary code via a… | HIGH 9.3EPSS 21.0% | 13 October 2010 |
| CVE-2010-3239 | Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability." | HIGH 9.3EPSS 21.0% | 13 October 2010 |
| CVE-2010-3238 | Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability." | HIGH 9.3EPSS 21.0% | 13 October 2010 |
| CVE-2010-3237 | Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability." | HIGH 9.3EPSS 21.0% | 13 October 2010 |
| CVE-2010-3236 | Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out… | HIGH 9.3EPSS 21.0% | 13 October 2010 |
| CVE-2010-3235 | Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Biff Record Vulnerability." | HIGH 9.3EPSS 21.0% | 13 October 2010 |
| CVE-2010-3234 | Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability." | HIGH 9.3EPSS 20.3% | 13 October 2010 |
| CVE-2010-3233 | Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted .wk3 (aka Lotus 1-2-3 workbook) file, aka "Lotus 1-2-3 Workbook Parsing Vulnerability." | HIGH 9.3EPSS 21.0% | 13 October 2010 |
| CVE-2010-3232 | Microsoft Excel 2003 SP3 and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record… | HIGH 9.3EPSS 21.0% | 13 October 2010 |
| CVE-2010-3231 | Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record… | HIGH 9.3EPSS 20.3% | 13 October 2010 |
| CVE-2010-3230 | Integer overflow in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel document with crafted record information, aka "Excel Record Parsing Integer Overflow Vulnerability." | HIGH 9.3EPSS 20.1% | 13 October 2010 |
| CVE-2010-3229 | The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which… | HIGH 7.1EPSS 50.2% | 13 October 2010 |
| CVE-2010-3228 | The JIT compiler in Microsoft .NET Framework 4.0 on 64-bit platforms does not properly perform optimizations, which allows remote attackers to execute arbitrary code via a crafted .NET application that triggers memory corruption, aka ".NET Framework x64… | HIGH 9.3EPSS 19.4% | 13 October 2010 |
| CVE-2010-3225 | Use-after-free vulnerability in the Media Player Network Sharing Service in Microsoft Windows Vista SP1 and SP2 and Windows 7 allows remote attackers to execute arbitrary code via a crafted Real Time Streaming Protocol (RTSP) packet, aka "RTSP Use After… | HIGH 7.6EPSS 16.7% | 13 October 2010 |
| CVE-2010-3223 | The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not properly set administrative-share permissions for new cluster disks that are shared as part of a failover cluster, which allows remote attackers to read… | HIGH 7.5EPSS 12.8% | 13 October 2010 |
| CVE-2010-3221 | Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory… | HIGH 9.3EPSS 19.4% | 13 October 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.