Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 262 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-3146 | Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2) GroovePerfmon.dll file in the current working directory, as demonstrated by a directory that contains… | EXPLOITHIGH 9.3EPSS 13.7% | 27 August 2010 |
| CVE-2010-3145 | Untrusted search path vulnerability in the BitLocker Drive Encryption API, as used in sdclt.exe in Backup Manager in Microsoft Windows Vista SP1 and SP2, allows local users to gain privileges via a Trojan horse fveapi.dll file in the current working… | EXPLOITHIGH 9.3EPSS 10.9% | 27 August 2010 |
| CVE-2010-3144 | Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory, as… | EXPLOIT ✓HIGH 9.3EPSS 13.6% | 27 August 2010 |
| CVE-2010-3143 | Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32res.dll that is located in the same folder as a… | EXPLOIT ×3 ✓HIGH 9.3EPSS 20.8% | 27 August 2010 |
| CVE-2010-3142 | Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse rpawinet.dll that is located in the same folder as… | EXPLOIT ×2HIGH 9.3EPSS 16.3% | 27 August 2010 |
| CVE-2010-3141 | Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse pptimpconv.dll that is located in the same folder as a… | EXPLOIT ×2HIGH 9.3EPSS 15.4% | 27 August 2010 |
| CVE-2010-3140 | Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse schannel.dll… | EXPLOIT ✓HIGH 9.3EPSS 15.1% | 27 August 2010 |
| CVE-2010-3139 | Untrusted search path vulnerability in Microsoft Windows Progman Group Converter (grpconv.exe) allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse imm.dll that is located in… | EXPLOIT ✓HIGH 9.3EPSS 23.5% | 27 August 2010 |
| CVE-2010-3138 | Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or… | EXPLOIT ×2 ✓HIGH 9.3EPSS 27.3% | 27 August 2010 |
| CVE-2010-2866 | Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a count value associated with an "undocumented structure"… | EXPLOIT ✓HIGH 9.3EPSS 13.0% | 26 August 2010 |
| CVE-2010-3132 | Untrusted search path vulnerability in Adobe Dreamweaver CS5 11.0 build 4916, build 4909, and probably other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1)… | EXPLOIT ×2HIGH 9.3EPSS 14.0% | 26 August 2010 |
| CVE-2010-3131 | Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute… | EXPLOIT ×2 ✓HIGH 9.3EPSS 22.9% | 26 August 2010 |
| CVE-2010-3127 | Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or Wintab32.dll that is located in the… | EXPLOITHIGH 9.3EPSS 13.9% | 26 August 2010 |
| CVE-2010-3124 | Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll that is located in… | EXPLOITHIGH 9.3EPSS 12.5% | 26 August 2010 |
| CVE-2009-4988 | Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary code via a long GIOP request to TCP port 30000. | EXPLOIT ×2 ✓HIGH 10.0EPSS 65.5% | 25 August 2010 |
| CVE-2010-3055 | The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request. | HIGH 7.5EPSS 14.8% | 24 August 2010 |
| CVE-2010-3106 | The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the debug parameter, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a… | EXPLOIT ×2 ✓HIGH 9.3EPSS 37.3% | 23 August 2010 |
| CVE-2010-1527 | Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter in an op-client-interface-version action. | EXPLOIT ×2 ✓HIGH 9.3EPSS 36.0% | 23 August 2010 |
| CVE-2010-2710 | Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors. | HIGH 10.0EPSS 10.2% | 20 August 2010 |
| CVE-2010-1870 | The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 92.0% | 17 August 2010 |
| CVE-2010-1799 | Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file. | EXPLOIT ✓HIGH 9.3EPSS 33.7% | 16 August 2010 |
| CVE-2010-1797 | Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on… | EXPLOIT ×2 ✓HIGH 9.3EPSS 30.7% | 16 August 2010 |
| CVE-2010-2861 | Adobe ColdFusion Directory Traversal Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 99.7% | 11 August 2010 |
| CVE-2010-2566 | The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote servers to execute arbitrary code… | HIGH 9.3EPSS 15.3% | 11 August 2010 |
| CVE-2010-2564 | Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability." | HIGH 9.3EPSS 22.6% | 11 August 2010 |
| CVE-2010-2562 | Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code or cause a denial of service… | HIGH 9.3EPSS 17.6% | 11 August 2010 |
| CVE-2010-2561 | Microsoft XML Core Services (aka MSXML) 3.0 does not properly handle HTTP responses, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted response, aka "Msxml2.XMLHTTP.3.0 Response… | EXPLOIT ✓HIGH 9.3EPSS 24.9% | 11 August 2010 |
| CVE-2010-2560 | Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka… | HIGH 9.3EPSS 24.2% | 11 August 2010 |
| CVE-2010-2559 | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka… | HIGH 9.3EPSS 27.5% | 11 August 2010 |
| CVE-2010-2558 | Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to an object in memory, aka "Race Condition Memory Corruption Vulnerability." | HIGH 9.3EPSS 21.0% | 11 August 2010 |
| CVE-2010-2557 | Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka… | HIGH 9.3EPSS 27.5% | 11 August 2010 |
| CVE-2010-2556 | Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka… | HIGH 9.3EPSS 27.5% | 11 August 2010 |
| CVE-2010-2553 | The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decompress media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Cinepak Codec Decompression… | EXPLOIT ×2 ✓HIGH 9.3EPSS 30.9% | 11 August 2010 |
| CVE-2010-2552 | Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request,… | HIGH 7.8EPSS 32.6% | 11 August 2010 |
| CVE-2010-2551 | The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denial of service (system hang) via a… | HIGH 7.8EPSS 66.6% | 11 August 2010 |
| CVE-2010-2550 | The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute… | EXPLOIT ✓HIGH 10.0EPSS 75.7% | 11 August 2010 |
| CVE-2010-1903 | Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory… | HIGH 9.3EPSS 19.4% | 11 August 2010 |
| CVE-2010-1902 | Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File… | HIGH 9.3EPSS 23.4% | 11 August 2010 |
| CVE-2010-1901 | Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not… | HIGH 9.3EPSS 19.4% | 11 August 2010 |
| CVE-2010-1900 | Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Works 9 do… | EXPLOIT ✓HIGH 9.3EPSS 39.8% | 11 August 2010 |
| CVE-2010-1898 | The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and… | HIGH 9.3EPSS 25.0% | 11 August 2010 |
| CVE-2010-1892 | The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted… | HIGH 7.8EPSS 62.0% | 11 August 2010 |
| CVE-2010-1882 | Multiple buffer overflows in the MPEG Layer-3 Audio Codec for Microsoft DirectShow in l3codecx.ax in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via an MPEG Layer-3 audio stream in (1) a crafted… | HIGH 9.3EPSS 23.4% | 11 August 2010 |
| CVE-2010-1258 | Microsoft Internet Explorer 6, 7, and 8 does not properly determine the origin of script code, which allows remote attackers to execute script in an unintended domain or security zone, and obtain sensitive information, via unspecified vectors, aka… | MEDIUM 4.3EPSS 17.0% | 11 August 2010 |
| CVE-2010-0019 | Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and framework outage)… | HIGH 9.3EPSS 14.4% | 11 August 2010 |
| CVE-2010-2862 | Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table. | EXPLOIT ✓HIGH 9.3EPSS 16.3% | 5 August 2010 |
| CVE-2010-2709 | Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long OvJavaLocale value in a cookie. | EXPLOIT ×2 ✓HIGH 9.3EPSS 42.3% | 5 August 2010 |
| CVE-2010-1871 | Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 83.4% | 5 August 2010 |
| CVE-2010-2965 | The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations,… | CRITICAL 9.8EPSS 57.8% | 5 August 2010 |
| CVE-2010-2918 | PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 13.7% | 30 July 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.