Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,434 CVEs1,723 in CISA KEV17,397 with EPSS ≥ 10%25,049 with a public exploitUpdated 24 September 2026
25,049 results · page 197 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-4809 | Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.76% | 23 April 2010 |
| CVE-2009-4808 | admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.76% | 23 April 2010 |
| CVE-2009-4807 | Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) c parameter to index.php and the (2) id parameter to view.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 23 April 2010 |
| CVE-2009-4806 | admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 2.64% | 23 April 2010 |
| CVE-2009-4805 | Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the storyid parameter to public/view.php or (2) the kill parameter to admin/remove.php. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 23 April 2010 |
| CVE-2009-4801 | EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts. | EXPLOIT ✓HIGH 7.5EPSS 2.25% | 23 April 2010 |
| CVE-2010-1486 | Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in CactuShop before 6.155 allow remote attackers to inject arbitrary web script or HTML via the (1) billing address or (2) shipping address. | EXPLOIT ✓MEDIUM 4.3EPSS 1.20% | 22 April 2010 |
| CVE-2010-1320 | Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via… | EXPLOIT ✓MEDIUM 4.0EPSS 11.9% | 22 April 2010 |
| CVE-2009-4800 | Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot slash slash) in a DELE command. | EXPLOIT ✓MEDIUM 4.0EPSS 1.93% | 22 April 2010 |
| CVE-2009-4799 | Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) artikler_prod.mdb or (2) medlemmer.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.59% | 22 April 2010 |
| CVE-2009-4798 | Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via the (1) kat parameter to side.asp, and the (2) brugerid and (3) password fields to the administration login feature. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 22 April 2010 |
| CVE-2009-4797 | SQL injection vulnerability in browse.php in JobHut 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pk parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 22 April 2010 |
| CVE-2009-4796 | Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order and (2) direction parameters… | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 22 April 2010 |
| CVE-2009-4795 | Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command. | EXPLOIT ✓MEDIUM 6.8EPSS 2.03% | 22 April 2010 |
| CVE-2009-4794 | Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to view.php and the (2) a parameter in an event action to calendar.php, reachable through index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 22 April 2010 |
| CVE-2009-4793 | Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension via an addphotos action to… | EXPLOIT ✓MEDIUM 6.0EPSS 1.54% | 22 April 2010 |
| CVE-2009-4792 | SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to execute arbitrary SQL commands via the memid parameter to members.php. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 22 April 2010 |
| CVE-2009-4791 | Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to addressbook.php, (2) id parameter to recipes.php, (3) year parameter to… | EXPLOIT ✓HIGH 7.5EPSS 1.28% | 22 April 2010 |
| CVE-2009-4790 | Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted FTP commands. | EXPLOIT ✓HIGH 9.0EPSS 3.91% | 22 April 2010 |
| CVE-2010-1033 | Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers to execute arbitrary code via a long string argument to the (1) LoadFile or (2) SaveFile method,… | EXPLOIT ✓HIGH 9.3EPSS 13.4% | 21 April 2010 |
| CVE-2009-4789 | Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) wp-comments-post.php and (2) wp-trackback.php. | EXPLOIT ✓HIGH 7.5EPSS 2.30% | 21 April 2010 |
| CVE-2009-4785 | SQL injection vulnerability in the Quick News (com_quicknews) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a view_item action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 21 April 2010 |
| CVE-2009-4784 | SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the treeId parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 21 April 2010 |
| CVE-2009-4783 | Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL commands via the start parameter to (1) forum.php and (2) thread.php in community/, and (3) blog/index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 21 April 2010 |
| CVE-2009-4782 | Multiple cross-site scripting (XSS) vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) forum, and (3) cat parameters to community/thread.php; (4) start and (5) cat… | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 21 April 2010 |
| CVE-2009-4781 | TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a DBI connection. | EXPLOIT ✓HIGH 7.2EPSS 0.75% | 21 April 2010 |
| CVE-2009-4780 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in phpMyFAQ before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter in a sitemap action, (2) the search parameter in a search action, (3) the… | EXPLOIT ✓MEDIUM 4.3EPSS 1.18% | 21 April 2010 |
| CVE-2009-4779 | Multiple PHP remote file inclusion vulnerabilities in NukeHall 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter to (1) blocks.php, (2) messages.php, and (3) stories.php in admin/modules/. | EXPLOIT ✓HIGH 7.5EPSS 2.15% | 21 April 2010 |
| CVE-2009-4775 | Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status code portion of an HTTP response. | EXPLOIT ✓MEDIUM 4.3EPSS 5.61% | 21 April 2010 |
| CVE-2010-0886 | Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ×4 ✓HIGH 10.0EPSS 69.9% | 20 April 2010 |
| CVE-2010-1458 | Stack-based buffer overflow in Create and Extract Zips TweakFS Zip Utility 1.0 for Flight Simulator X (FSX) allows remote attackers to execute arbitrary code via a long filename in a ZIP archive. | EXPLOIT ✓MEDIUM 6.8EPSS 4.67% | 20 April 2010 |
| CVE-2010-1318 | Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified… | EXPLOIT ×2 ✓HIGH 10.0EPSS 58.1% | 20 April 2010 |
| CVE-2009-4769 | Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is… | EXPLOIT ×2 ✓HIGH 9.3EPSS 37.9% | 20 April 2010 |
| CVE-2009-4767 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Plohni Shoutbox 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) input_name and (2) input_text parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 20 April 2010 |
| CVE-2010-1480 | SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the module parameter to index.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.96% | 19 April 2010 |
| CVE-2010-1479 | SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter in a raw action to index.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.31% | 19 April 2010 |
| CVE-2010-1478 | Directory traversal vulnerability in the Ternaria Informatica Jfeedback! | EXPLOIT ✓MEDIUM 6.8EPSS 8.16% | 19 April 2010 |
| CVE-2010-1477 | SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a latest_sermons action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 19 April 2010 |
| CVE-2010-1476 | Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 9.94% | 19 April 2010 |
| CVE-2010-1475 | Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 9.47% | 19 April 2010 |
| CVE-2010-1474 | Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 9.47% | 19 April 2010 |
| CVE-2010-1473 | Directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 8.16% | 19 April 2010 |
| CVE-2010-1472 | Directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 13.4% | 19 April 2010 |
| CVE-2010-1471 | Directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 16.2% | 19 April 2010 |
| CVE-2010-1470 | Directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 13.4% | 19 April 2010 |
| CVE-2010-1469 | Directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 8.16% | 19 April 2010 |
| CVE-2010-1468 | SQL injection vulnerability in the Multi-Venue Restaurant Menu Manager (aka MVRMM or com_mv_restaurantmenumanager) component 1.5.2 Stable Update 3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the mid parameter in… | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 19 April 2010 |
| CVE-2010-1467 | Multiple PHP remote file inclusion vulnerabilities in openUrgence Vaccin 1.03 allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) collectivite.class.php, (2) injection.class.php, (3) utilisateur.class.php, (4)… | EXPLOIT ✓HIGH 7.5EPSS 2.25% | 16 April 2010 |
| CVE-2010-1466 | Directory traversal vulnerability in scr/soustab.php in openUrgence Vaccin 1.03 allows remote attackers to read arbitrary files via the dsn[phptype] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 4.09% | 16 April 2010 |
| CVE-2010-1465 | Stack-based buffer overflow in Trellian FTP client 3.01, including 3.1.3.1789, allows remote attackers to execute arbitrary code via a long PASV response. | EXPLOIT ×2 ✓HIGH 9.3EPSS 31.3% | 16 April 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.