Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,461 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 212 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-3969 | Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file. | EXPLOIT ✓HIGH 9.3EPSS 6.23% | 18 November 2009 |
| CVE-2009-3968 | Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php, (2) cate_id parameter to category.php, (3) id parameter to news.php, and (4) productid… | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 18 November 2009 |
| CVE-2009-3967 | SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 18 November 2009 |
| CVE-2009-3966 | Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true. | EXPLOIT ✓HIGH 7.5EPSS 2.27% | 18 November 2009 |
| CVE-2009-3965 | SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote attackers to execute arbitrary SQL commands via the det parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.05% | 18 November 2009 |
| CVE-2009-3964 | SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 18 November 2009 |
| CVE-2009-3962 | The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.29.52 allows remote attackers to cause a denial of service (reboot) via a %0d%0a sequence in the page parameter to the xslt program… | EXPLOIT ✓HIGH 7.8EPSS 3.02% | 17 November 2009 |
| CVE-2009-3890 | Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users… | EXPLOIT ✓MEDIUM 6.0EPSS 8.43% | 17 November 2009 |
| CVE-2009-3949 | cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.20% | 16 November 2009 |
| CVE-2009-3948 | JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and application crash) via a long string at the end of a .wav file. | EXPLOIT ✓MEDIUM 4.3EPSS 1.87% | 16 November 2009 |
| CVE-2009-3947 | Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (process crash or device reboot) or possibly execute arbitrary code via a long USER command, as demonstrated by a command ending with many… | EXPLOIT ✓HIGH 9.3EPSS 4.81% | 16 November 2009 |
| CVE-2009-3888 | The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management unit, allows local users to cause a denial of service (OOPS) via an application that attempts to allocate a large amount of memory. | EXPLOIT ✓MEDIUM 4.9EPSS 0.75% | 16 November 2009 |
| CVE-2009-3566 | McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS)… | EXPLOIT ✓MEDIUM 4.3EPSS 4.04% | 13 November 2009 |
| CVE-2009-3565 | Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.11.6 allow remote attackers to inject arbitrary web script or HTML via the (1) iaction or (2) node… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.21% | 13 November 2009 |
| CVE-2009-3548 | The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges. | EXPLOIT ×2 ✓HIGH 7.5EPSS 79.0% | 12 November 2009 |
| CVE-2009-3129 | Microsoft Excel Featheader Record Memory Corruption Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 84.0% | 11 November 2009 |
| CVE-2009-2514 | win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded… | EXPLOIT ✓HIGH 9.3EPSS 47.5% | 11 November 2009 |
| CVE-2009-2820 | The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP… | EXPLOIT ✓MEDIUM 4.3EPSS 5.78% | 10 November 2009 |
| CVE-2009-3726 | The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect… | EXPLOIT ✓HIGH 7.8EPSS 12.0% | 9 November 2009 |
| CVE-2009-3913 | SQL injection vulnerability in summary.php in Xerox Fiery Webtools allows remote attackers to execute arbitrary SQL commands via the select parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.74% | 9 November 2009 |
| CVE-2009-3912 | Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the album parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.74% | 9 November 2009 |
| CVE-2009-3911 | Cross-site scripting (XSS) vulnerability in settings.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the sample parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 9 November 2009 |
| CVE-2009-3555 | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network… | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 87.3% | 9 November 2009 |
| CVE-2009-3904 | classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to bypass restrictions and gain administrative access via a HTTP request that contains an empty (1) sessID… | EXPLOIT ✓HIGH 7.5EPSS 8.67% | 6 November 2009 |
| CVE-2009-3902 | Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. | EXPLOIT ✓MEDIUM 5.0EPSS 3.54% | 6 November 2009 |
| CVE-2009-3901 | Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to home/index.asp and other unspecified vectors. | EXPLOIT ✓MEDIUM 4.3EPSS 1.27% | 6 November 2009 |
| CVE-2009-3850 | Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA. | EXPLOIT ✓HIGH 9.3EPSS 9.44% | 6 November 2009 |
| CVE-2009-2685 | Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers to execute arbitrary code via the Login variable. | EXPLOIT ×2 ✓HIGH 10.0EPSS 76.7% | 6 November 2009 |
| CVE-2009-3869 | Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK… | EXPLOIT ✓HIGH 9.3EPSS 65.4% | 5 November 2009 |
| CVE-2009-3867 | Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to… | EXPLOIT ×3 ✓HIGH 9.3EPSS 73.4% | 5 November 2009 |
| CVE-2009-3863 | Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argument to the SetFontFace method. | EXPLOIT ✓MEDIUM 5.0EPSS 5.02% | 4 November 2009 |
| CVE-2009-3861 | Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions before 10.8.9, allows local users to execute arbitrary code via a long string in a (1) TREENAME or (2) GROUPNAME Policy file (spd). | EXPLOIT ✓MEDIUM 6.9EPSS 3.73% | 4 November 2009 |
| CVE-2009-3860 | Multiple insecure method vulnerabilities in Idefense Labs COMRaider allow remote attackers to create or overwrite arbitrary files via the (1) CreateFolder and (2) Copy methods. | EXPLOIT ✓MEDIUM 5.8EPSS 1.83% | 4 November 2009 |
| CVE-2009-3859 | Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .rws file with a long RWS010… | EXPLOIT ✓HIGH 9.3EPSS 11.6% | 4 November 2009 |
| CVE-2009-3858 | Cross-site scripting (XSS) vulnerability in GejoSoft allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI in photos/tags. | EXPLOIT ✓MEDIUM 4.3EPSS 1.54% | 4 November 2009 |
| CVE-2009-3857 | Buffer overflow in Softonic International SciTE 1.72 allows user-assisted remote attackers to cause a denial of service (application crash) via a Ruby (.rb) file containing a long string, which triggers the crash when a scroll bar is used. | EXPLOIT ✓MEDIUM 4.3EPSS 1.98% | 4 November 2009 |
| CVE-2009-3856 | Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script or HTML via the calendar parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.01% | 4 November 2009 |
| CVE-2009-3853 | Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows… | EXPLOIT ✓HIGH 9.3EPSS 36.7% | 4 November 2009 |
| CVE-2009-3547 | Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname. | EXPLOIT ×5 ✓HIGH 7.0EPSS 4.89% | 4 November 2009 |
| CVE-2009-3031 | Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in… | EXPLOIT ×2 ✓HIGH 9.3EPSS 45.4% | 3 November 2009 |
| CVE-2009-3838 | Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message. | EXPLOIT ✓HIGH 9.3EPSS 6.21% | 2 November 2009 |
| CVE-2009-3837 | Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error message. | EXPLOIT ×3 ✓HIGH 9.3EPSS 32.1% | 2 November 2009 |
| CVE-2009-3835 | SQL injection vulnerability in the JShop (com_jshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 November 2009 |
| CVE-2009-3833 | Cross-site scripting (XSS) vulnerability in index.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the album parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.27% | 2 November 2009 |
| CVE-2009-3733 | Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors. | EXPLOIT ✓MEDIUM 5.0EPSS 83.4% | 2 November 2009 |
| CVE-2009-2267 | VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6… | EXPLOIT ✓MEDIUM 6.9EPSS 1.75% | 2 November 2009 |
| CVE-2009-3830 | The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx. | EXPLOIT ✓MEDIUM 5.0EPSS 32.6% | 30 October 2009 |
| CVE-2009-3828 | The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors. | EXPLOIT ✓MEDIUM 5.0EPSS 2.89% | 30 October 2009 |
| CVE-2009-3382 | layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or… | EXPLOIT ✓HIGH 10.0EPSS 10.8% | 29 October 2009 |
| CVE-2009-3373 | Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 15.5% | 29 October 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.