Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,453 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 210 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-4227 | Stack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject function in read1_3.c in fig2dev in Transfig 3.2.5a and earlier, allows remote attackers to execute arbitrary code via… | EXPLOIT ✓MEDIUM 6.8EPSS 10.6% | 8 December 2009 |
| CVE-2009-4225 | Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to execute arbitrary code via a long argument to the Initialize method. | EXPLOIT ✓HIGH 9.3EPSS 30.6% | 8 December 2009 |
| CVE-2009-3586 | Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code via an HTTP request with a long first line that triggers a buffer overflow. | EXPLOIT ✓HIGH 7.5EPSS 6.39% | 8 December 2009 |
| CVE-2009-4224 | Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter to (1) _plugin/subscriber/inc/post.php and (2) as/lib/news_modify.php. | EXPLOIT ✓MEDIUM 6.8EPSS 2.63% | 7 December 2009 |
| CVE-2009-4223 | PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. | EXPLOIT ✓HIGH 7.5EPSS 54.6% | 7 December 2009 |
| CVE-2009-4222 | phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain access to the admin control panel via a direct request. | EXPLOIT ✓HIGH 7.5EPSS 2.41% | 7 December 2009 |
| CVE-2009-4221 | SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-3767. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 7 December 2009 |
| CVE-2009-4220 | PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pcConfig[smartyPath] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 7 December 2009 |
| CVE-2009-4219 | Stack-based buffer overflow in the MYACTIVEX.MyActiveXCtrl.1 ActiveX control in MyActiveX.ocx 1.4.8.0 in Haihaisoft Universal Player allows remote attackers to execute arbitrary code via a long URL property value. | EXPLOIT ✓HIGH 9.3EPSS 9.27% | 7 December 2009 |
| CVE-2009-4218 | Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System eXperience (JBSX) allow remote attackers to execute arbitrary SQL commands via the (1) admin or (2) password field, a related issue to CVE-2007-6091. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 7 December 2009 |
| CVE-2009-4217 | SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an itempage action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.90% | 7 December 2009 |
| CVE-2009-4216 | Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 9.3EPSS 5.60% | 7 December 2009 |
| CVE-2009-4209 | Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) file parameters in an editsite action, different vectors than CVE-2008-6127… | EXPLOIT ✓MEDIUM 4.3EPSS 1.19% | 4 December 2009 |
| CVE-2009-4208 | SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 4 December 2009 |
| CVE-2009-4206 | SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 4 December 2009 |
| CVE-2009-4205 | Directory traversal vulnerability in admin.php in Flashlight Free Edition allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.40% | 4 December 2009 |
| CVE-2009-4204 | SQL injection vulnerability in read.php in Flashlight Free Edition allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 4 December 2009 |
| CVE-2009-4203 | Multiple SQL injection vulnerabilities in admin/aclass/admin_func.php in Arab Portal 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) X-Forwarded-For or (2) Client-IP HTTP header in a request to the default URI under admin/. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 4 December 2009 |
| CVE-2009-4202 | Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to… | EXPLOIT ✓HIGH 7.5EPSS 8.11% | 4 December 2009 |
| CVE-2009-4200 | SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 4 December 2009 |
| CVE-2009-4199 | Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) property_uid parameter… | EXPLOIT ✓MEDIUM 6.8EPSS 0.83% | 4 December 2009 |
| CVE-2009-4198 | SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL commands via the orderid parameter in a status action. | EXPLOIT ✓MEDIUM 6.5EPSS 0.89% | 4 December 2009 |
| CVE-2009-4148 | DAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote attackers to execute arbitrary JavaScript code via a (1) .ds, (2) .dsa, (3) .dse, or (4) .dsb file, as demonstrated by code that loads the WScript.Shell ActiveX control, related to a "script… | EXPLOIT ✓HIGH 9.3EPSS 5.49% | 4 December 2009 |
| CVE-2009-4197 | rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically proximate attackers to obtain the… | EXPLOIT ✓MEDIUM 4.7EPSS 0.47% | 4 December 2009 |
| CVE-2009-4196 | Multiple cross-site scripting (XSS) vulnerabilities in multiple scripts in Forms/ in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 allow remote attackers to inject arbitrary web script or HTML via the (1) BackButton parameter to error_1; (2)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.03% | 4 December 2009 |
| CVE-2009-4195 | Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execute arbitrary code via a long DSC comment in an Encapsulated PostScript (.eps) file. | EXPLOIT ×3 ✓HIGH 9.3EPSS 70.7% | 4 December 2009 |
| CVE-2009-4194 | Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files via a .. | EXPLOIT ✓HIGH 8.1EPSS 3.44% | 3 December 2009 |
| CVE-2009-4192 | Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.73% | 3 December 2009 |
| CVE-2009-4189 | HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet… | EXPLOIT ✓HIGH 10.0EPSS 78.5% | 3 December 2009 |
| CVE-2009-4188 | HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager… | EXPLOIT ×2 ✓HIGH 10.0EPSS 69.5% | 3 December 2009 |
| CVE-2009-4186 | Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (application crash) via a long URI value (aka url) in the Cascading Style Sheets (CSS) background property. | EXPLOIT ✓HIGH 9.3EPSS 6.53% | 3 December 2009 |
| CVE-2009-4175 | CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_date_day parameter to search.php, which reveals the installation path in an error message. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 2.79% | 2 December 2009 |
| CVE-2009-4174 | The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access to bypass administrative moderation and edit previously submitted articles… | EXPLOIT ✓MEDIUM 6.0EPSS 1.65% | 2 December 2009 |
| CVE-2009-4173 | Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authentication of administrators for requests that create new users, including a new administrator, via an… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.03% | 2 December 2009 |
| CVE-2009-4172 | Cross-site scripting (XSS) vulnerability in index.php in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the body of a news article in an addnews… | EXPLOIT ×2 ✓LOW 2.6EPSS 1.60% | 2 December 2009 |
| CVE-2009-4171 | Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by calling the RegisterMe method with a long argument. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 5.09% | 2 December 2009 |
| CVE-2009-4147 | The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBRARY_PATH, (3) LD_LIBMAP_DISABLE, (4) LD_DEBUG, and (5) LD_ELF_HINTS_PATH environment variables, which… | EXPLOIT ✓HIGH 7.2EPSS 3.71% | 2 December 2009 |
| CVE-2009-4170 | WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message. | EXPLOIT ✓MEDIUM 5.0EPSS 6.39% | 2 December 2009 |
| CVE-2009-4168 | Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the… | EXPLOIT ✓MEDIUM 4.3EPSS 5.49% | 2 December 2009 |
| CVE-2009-4146 | The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environment variable, which allows local users to gain privileges by executing a setuid or setguid program with a… | EXPLOIT ✓HIGH 7.2EPSS 3.90% | 2 December 2009 |
| CVE-2009-4157 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in… | EXPLOITMEDIUM 4.3EPSS 1.31% | 2 December 2009 |
| CVE-2009-4156 | PHP remote file inclusion vulnerability in modules/pms/index.php in Ciamos CMS 0.9.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.10% | 2 December 2009 |
| CVE-2009-4155 | Multiple SQL injection vulnerabilities in Eshopbuilde CMS allow remote attackers to execute arbitrary SQL commands via the sitebid parameter to (1) home-f.asp and (2) opinions-f.asp; (3) sitebid, (4) id, (5) secText, (6) client-ip, and (7) G_id… | EXPLOIT ✓HIGH 7.5EPSS 0.89% | 2 December 2009 |
| CVE-2009-4154 | Directory traversal vulnerability in includes/feedcreator.class.php in Elxis CMS allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.94% | 2 December 2009 |
| CVE-2009-3672 | Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or (2) are deleted, which allows remote attackers to execute arbitrary code via vectors involving a call to the getElementsByTagName… | EXPLOIT ✓HIGH 9.3EPSS 71.8% | 2 December 2009 |
| CVE-2009-2626 | The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a… | EXPLOIT ×3 ✓MEDIUM 6.4EPSS 8.31% | 1 December 2009 |
| CVE-2009-4120 | Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete orders via an orders-delete action to admin.php, and possibly (2) delete… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.00% | 1 December 2009 |
| CVE-2009-4118 | The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service… | EXPLOIT ✓LOW 2.1EPSS 2.50% | 1 December 2009 |
| CVE-2009-4117 | Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attackers to cause a denial of service and possibly execute arbitrary code via a /Decode array for certain… | EXPLOIT ✓HIGH 9.3EPSS 7.78% | 1 December 2009 |
| CVE-2009-4115 | Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application administrative privileges to inject arbitrary PHP code into data/category.db.php via the (1) category and… | EXPLOIT ✓MEDIUM 6.5EPSS 2.00% | 30 November 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.