Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,461 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 213 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-3641 | Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packet that uses the (1) TCP or (2) ICMP protocol. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 38.8% | 28 October 2009 |
| CVE-2009-3825 | Multiple directory traversal vulnerabilities in GenCMS 2006 allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 28 October 2009 |
| CVE-2009-3824 | Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.40% | 28 October 2009 |
| CVE-2009-3823 | Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 2.35% | 28 October 2009 |
| CVE-2009-3822 | PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php. | EXPLOIT ✓HIGH 7.5EPSS 2.58% | 28 October 2009 |
| CVE-2009-3817 | PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector… | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 28 October 2009 |
| CVE-2009-3812 | Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 allows remote attackers to execute arbitrary code via a long playlist in an Ots File List (.ofl) file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 6.90% | 27 October 2009 |
| CVE-2009-3811 | Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag. | EXPLOIT ✓HIGH 9.3EPSS 5.76% | 27 October 2009 |
| CVE-2009-3810 | Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file. | EXPLOIT ✓HIGH 9.3EPSS 6.04% | 27 October 2009 |
| CVE-2009-3809 | Acoustica MP3 Audio Mixer 1.0 and possibly 2.471 allows remote attackers to cause a denial of service (crash) via a long string in a .sgp playlist file. | EXPLOIT ✓MEDIUM 4.3EPSS 2.28% | 27 October 2009 |
| CVE-2009-3808 | MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an .mp3 playlist file. | EXPLOIT ✓HIGH 9.3EPSS 4.48% | 27 October 2009 |
| CVE-2009-3807 | Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file. | EXPLOIT ✓HIGH 9.3EPSS 2.81% | 27 October 2009 |
| CVE-2009-3806 | SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.64% | 27 October 2009 |
| CVE-2009-3805 | gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (application crash) via a long certificate signature. | EXPLOIT ✓MEDIUM 4.3EPSS 1.37% | 27 October 2009 |
| CVE-2009-3804 | Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in… | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 0.81% | 27 October 2009 |
| CVE-2009-3803 | Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the status_message parameter to (1) /news, (2) /comment, (3) /forum, (4) /blog, and (5) /tags; the… | EXPLOIT ✓MEDIUM 4.3EPSS 1.76% | 27 October 2009 |
| CVE-2009-3802 | Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message. | EXPLOIT ✓MEDIUM 5.0EPSS 2.59% | 27 October 2009 |
| CVE-2009-3789 | Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO… | EXPLOIT ×12 ✓MEDIUM 4.3EPSS 2.81% | 26 October 2009 |
| CVE-2009-3787 | files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . | EXPLOIT ✓MEDIUM 5.0EPSS 6.58% | 26 October 2009 |
| CVE-2009-3625 | Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 8.19% | 26 October 2009 |
| CVE-2009-1979 | Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ×2 ✓HIGH 10.0EPSS 76.4% | 22 October 2009 |
| CVE-2009-3760 | Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.73% | 22 October 2009 |
| CVE-2009-3759 | Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the… | EXPLOIT ✓HIGH 8.8EPSS 2.29% | 22 October 2009 |
| CVE-2009-3758 | SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 22 October 2009 |
| CVE-2009-3757 | Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to config/edituser.php; (2) location,… | EXPLOIT ✓MEDIUM 4.3EPSS 1.74% | 22 October 2009 |
| CVE-2009-3756 | phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which reveals the installation path in an error message. | EXPLOIT ✓MEDIUM 5.0EPSS 2.29% | 22 October 2009 |
| CVE-2009-3755 | Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php and (2) modules\base\myaccount.php; and the PATH_INFO to (3) modules_view.php, (4)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.25% | 22 October 2009 |
| CVE-2009-3754 | Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to modules/bms/invoices_discount_ajax.php, (2) f parameter to dbgraphic.php, and (3) tid parameter in a show action… | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 22 October 2009 |
| CVE-2009-3753 | Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in userimages, related to register.php. | EXPLOIT ✓HIGH 7.5EPSS 3.96% | 22 October 2009 |
| CVE-2009-3752 | SQL injection vulnerability in home.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the genres_parent parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 22 October 2009 |
| CVE-2009-3751 | Cross-site scripting (XSS) vulnerability in home.php in Opial 1.0 allows remote attackers to inject arbitrary web script or HTML via the genres_parent parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 22 October 2009 |
| CVE-2009-3750 | SQL injection vulnerability in read.php in ToyLog 0.1 allows remote attackers to execute arbitrary SQL commands via the idm parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 22 October 2009 |
| CVE-2009-3749 | The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remote attackers to cause a denial of service (crash) by sending a HTTP GET request to TCP port 8181 and… | EXPLOIT ✓MEDIUM 5.0EPSS 7.64% | 22 October 2009 |
| CVE-2009-3748 | Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allow remote attackers to inject arbitrary web script or HTML via the (1)… | EXPLOIT ✓MEDIUM 4.3EPSS 3.46% | 22 October 2009 |
| CVE-2009-3747 | Cross-site scripting (XSS) vulnerability in index.php in TBmnetCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the content parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 22 October 2009 |
| CVE-2009-3744 | rep_serv.exe 6.3.1.3 in the server in EMC RepliStor allows remote attackers to cause a denial of service via a crafted packet to TCP port 7144. | EXPLOIT ✓MEDIUM 5.0EPSS 7.27% | 22 October 2009 |
| CVE-2009-3621 | net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a… | EXPLOIT ✓MEDIUM 5.5EPSS 0.99% | 22 October 2009 |
| CVE-2009-1479 | Directory traversal vulnerability in client/desktop/default.htm in Boxalino before 09.05.25-0421 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.39% | 22 October 2009 |
| CVE-2009-3730 | Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help feature (aka the Web Client Help system) in IBM Rational RequisitePro 7.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the operation parameter to… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 3.45% | 20 October 2009 |
| CVE-2009-2994 | Buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ✓HIGH 9.3EPSS 18.6% | 19 October 2009 |
| CVE-2009-2990 | Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ×2 ✓HIGH 9.3EPSS 68.7% | 19 October 2009 |
| CVE-2009-2983 | Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors. | EXPLOIT ✓HIGH 9.3EPSS 12.2% | 19 October 2009 |
| CVE-2009-3613 | The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6.27.22 allows remote attackers to cause a denial of service (IOMMU space exhaustion and system crash) by using jumbo frames for a large amount of network… | EXPLOIT ✓HIGH 7.8EPSS 12.5% | 19 October 2009 |
| CVE-2009-3704 | ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service (crash) via a SIP INVITE request with an empty Call-Info header. | EXPLOIT ✓MEDIUM 5.0EPSS 8.14% | 16 October 2009 |
| CVE-2009-3719 | Cross-site scripting (XSS) vulnerability in comment.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to inject arbitrary web script or HTML via a comment. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 16 October 2009 |
| CVE-2009-3718 | SQL injection vulnerability in admin/authenticate.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to execute arbitrary SQL commands via the UserName parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 16 October 2009 |
| CVE-2009-3717 | Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URI in a playlist (.m3u) file. | EXPLOIT ✓HIGH 9.3EPSS 6.42% | 16 October 2009 |
| CVE-2009-3716 | Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/. | EXPLOIT ✓MEDIUM 6.5EPSS 3.57% | 16 October 2009 |
| CVE-2009-3715 | Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 16 October 2009 |
| CVE-2009-3714 | Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.74% | 16 October 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.