Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,453 CVEs1,723 in CISA KEV17,397 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 207 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2010-0279 | Unrestricted file upload vulnerability in upload.php in BTS-GI Read excel 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified… | EXPLOIT ✓MEDIUM 6.8EPSS 3.37% | 13 January 2010 |
| CVE-2010-0071 | Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ✓HIGH 10.0EPSS 9.83% | 13 January 2010 |
| CVE-2010-0278 | A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method… | EXPLOIT ✓MEDIUM 4.3EPSS 8.31% | 12 January 2010 |
| CVE-2009-4604 | PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0 RC3 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 12 January 2010 |
| CVE-2009-4601 | Cross-site scripting (XSS) vulnerability in basic_search_result.php in Zeeways ZeeJobsite 3x allows remote attackers to inject arbitrary web script or HTML via the title parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 12 January 2010 |
| CVE-2009-4600 | SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Email parameter (aka the username field). | EXPLOITHIGH 7.5EPSS 1.00% | 12 January 2010 |
| CVE-2009-4599 | Multiple SQL injection vulnerabilities in the JS Jobs (com_jsjobs) component 1.0.5.6 for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the md parameter in an employer view_company action to index.php or (2) the oi parameter in… | EXPLOIT ×2HIGH 7.5EPSS 2.01% | 12 January 2010 |
| CVE-2009-4598 | SQL injection vulnerability in the JPhoto (com_jphoto) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action to index.php. | EXPLOITHIGH 7.5EPSS 1.18% | 12 January 2010 |
| CVE-2009-4597 | Multiple SQL injection vulnerabilities in index.php in PHP Inventory 1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the user_id parameter in a users details action, and allow remote attackers to execute arbitrary SQL… | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 12 January 2010 |
| CVE-2009-4596 | Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary web script or HTML via the sup_id parameter in a suppliers details action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 12 January 2010 |
| CVE-2009-4595 | SQL injection vulnerability in index.php in PHP Inventory 1.2 allows remote authenticated users to execute arbitrary SQL commands via the sup_id parameter in a suppliers details action. | EXPLOIT ✓MEDIUM 6.0EPSS 0.73% | 12 January 2010 |
| CVE-2010-0013 | Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 12.5% | 9 January 2010 |
| CVE-2009-4497 | Cross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5 and 0.9.6 allows remote attackers to inject arbitrary web script or HTML via the i parameter to the ident program. | EXPLOIT ✓MEDIUM 4.3EPSS 3.22% | 7 January 2010 |
| CVE-2009-4588 | Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D Player and Winds3D Viewer allows remote attackers to cause a denial of service (application crash) or… | EXPLOIT ×2 ✓HIGH 9.3EPSS 32.0% | 7 January 2010 |
| CVE-2009-4587 | Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word. | EXPLOIT ✓MEDIUM 5.0EPSS 4.12% | 7 January 2010 |
| CVE-2010-0158 | SQL injection vulnerability in the JoomlaBamboo (JB) Simpla Admin template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to the com_content component, reachable through index.php. | EXPLOITHIGH 7.5EPSS 1.15% | 6 January 2010 |
| CVE-2010-0157 | Directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 13.0% | 6 January 2010 |
| CVE-2009-4585 | UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/db.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.59% | 6 January 2010 |
| CVE-2009-4583 | SQL injection vulnerability in the DhForum (com_dhforum) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a grouplist action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 6 January 2010 |
| CVE-2009-4582 | SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 6 January 2010 |
| CVE-2009-4581 | Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the admin parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 5.24% | 6 January 2010 |
| CVE-2009-4578 | Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 6 January 2010 |
| CVE-2009-4576 | SQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a suggestions action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.18% | 6 January 2010 |
| CVE-2009-4575 | Cross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the personel_sira parameter in a sirala action to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 6 January 2010 |
| CVE-2009-4574 | SQL injection vulnerability in country_escorts.php in I-Escorts Directory Script allows remote attackers to execute arbitrary SQL commands via the country_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 6 January 2010 |
| CVE-2009-4571 | Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL commands via the (1) module_id parameter in an admin/function_list action, the (2) vendor_id parameter in a vendor/vendor_form action,… | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.02% | 5 January 2010 |
| CVE-2009-4569 | SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 5 January 2010 |
| CVE-2009-4567 | Multiple cross-site scripting (XSS) vulnerabilities in editprofile.php in Viscacha 0.8 Gold allow remote authenticated users to inject arbitrary web script or HTML via the (1) skype, (2) yahoo, (3) aol, (4) msn, or (5) jabber parameter in a profile2… | EXPLOIT ✓LOW 3.5EPSS 1.25% | 5 January 2010 |
| CVE-2009-4566 | SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title parameter in a news action. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 4 January 2010 |
| CVE-2009-4564 | SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL commands via the category parameter, related to a URI under news/category/. | EXPLOIT ✓MEDIUM 6.8EPSS 0.84% | 4 January 2010 |
| CVE-2009-4563 | Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via the 0-adminpass and… | EXPLOIT ✓MEDIUM 4.3EPSS 3.64% | 4 January 2010 |
| CVE-2009-4562 | Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the from parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.11% | 4 January 2010 |
| CVE-2009-4561 | Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 0.85% | 4 January 2010 |
| CVE-2009-4560 | SQL injection vulnerability in profile.php in WebLeague 2.2.0 allows remote attackers to execute arbitrary SQL commands via the name parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 4 January 2010 |
| CVE-2009-4556 | Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs,… | EXPLOIT ✓HIGH 7.2EPSS 0.70% | 4 January 2010 |
| CVE-2009-4554 | Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element;… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.76% | 4 January 2010 |
| CVE-2009-4553 | Stack-based buffer overflow in iRehearse allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in a .m3u playlist file. | EXPLOIT ✓MEDIUM 5.0EPSS 2.34% | 4 January 2010 |
| CVE-2009-4552 | Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.18% | 4 January 2010 |
| CVE-2009-4551 | SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 4 January 2010 |
| CVE-2009-4550 | SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the func parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 4 January 2010 |
| CVE-2009-4549 | Stack-based buffer overflow in A2 Media Player Pro 2.51 allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .m3l playlist file. | EXPLOIT ✓HIGH 9.3EPSS 4.36% | 4 January 2010 |
| CVE-2009-4548 | Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the… | EXPLOIT ×6 ✓MEDIUM 4.3EPSS 2.26% | 4 January 2010 |
| CVE-2009-4547 | Multiple cross-site scripting (XSS) vulnerabilities in ViArt CMS 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter to forums.php, or the forum_id parameter to (2) forum.php or (3) forum_topic_new.php. | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.85% | 4 January 2010 |
| CVE-2009-4546 | globepersonnel_login.asp in Logoshows BBS 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) pb_username (aka pb%5Fusername) and (2) level cookies. | EXPLOIT ✓HIGH 7.5EPSS 2.63% | 4 January 2010 |
| CVE-2009-4545 | Logoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/globepersonnel.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.23% | 4 January 2010 |
| CVE-2009-4544 | Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.55% | 4 January 2010 |
| CVE-2009-4543 | PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary PHP code via a URL in the lng parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.91% | 4 January 2010 |
| CVE-2009-4542 | Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.01% | 4 January 2010 |
| CVE-2009-4541 | Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) newticket.php or (2) rempass.php, or a URL in the lang parameter in an adduser… | EXPLOIT ✓HIGH 7.5EPSS 7.74% | 4 January 2010 |
| CVE-2009-4540 | SQL injection vulnerability in page.php in Mini CMS 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.90% | 4 January 2010 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.