Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,461 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 216 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-3457 | Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request,… | EXPLOIT ✓MEDIUM 5.0EPSS 4.19% | 29 September 2009 |
| CVE-2009-3449 | MP3 Collector 2.3 allows remote attackers to cause a denial of service (application crash) via a long URL in a .m3u playlist file. | EXPLOIT ✓MEDIUM 4.3EPSS 1.88% | 29 September 2009 |
| CVE-2009-3446 | SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 28 September 2009 |
| CVE-2009-3444 | Cross-site scripting (XSS) vulnerability in email.php in e107 0.7.16 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header in a news.1 (aka news to email) action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.73% | 28 September 2009 |
| CVE-2009-3443 | SQL injection vulnerability in the Fastball (com_fastball) component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 28 September 2009 |
| CVE-2009-3440 | Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to the default URI (aka the main menu). | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 28 September 2009 |
| CVE-2009-3439 | Multiple SQL injection vulnerabilities in Open Source Security Information Management (OSSIM) before 2.1.2 allow remote authenticated users to execute arbitrary SQL commands via the id_document parameter to (1) repository_document.php, (2)… | EXPLOIT ✓MEDIUM 6.5EPSS 0.85% | 28 September 2009 |
| CVE-2009-3438 | SQL injection vulnerability in the JoomlaFacebook (com_facebook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.00% | 28 September 2009 |
| CVE-2009-3436 | Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 28 September 2009 |
| CVE-2009-3434 | SQL injection vulnerability in the Tupinambis (com_tupinambis) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 28 September 2009 |
| CVE-2009-3431 | Stack consumption vulnerability in Adobe Reader and Acrobat 9.1.3, 9.1.2, 9.1.1, and earlier 9.x versions; 8.1.6 and earlier 8.x versions; and possibly 7.1.4 and earlier 7.x versions allows remote attackers to cause a denial of service (application… | EXPLOIT ✓MEDIUM 5.0EPSS 21.6% | 25 September 2009 |
| CVE-2009-3430 | SQL injection vulnerability in login.php in Allomani Mobile 2.5 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 25 September 2009 |
| CVE-2009-3429 | Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file. | EXPLOIT ×6 ✓HIGH 9.3EPSS 35.0% | 25 September 2009 |
| CVE-2009-3428 | Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted .wav file. | EXPLOIT ×3 ✓HIGH 9.3EPSS 6.07% | 25 September 2009 |
| CVE-2009-3426 | PHP remote file inclusion vulnerability in includes/file_manager/special.php in MaxCMS 3.11.20b allows remote attackers to execute arbitrary PHP code via a URL in the fm_includes_special parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.91% | 25 September 2009 |
| CVE-2009-3425 | Directory traversal vulnerability in includes/inc.thcms_admin_dirtree.php in MaxCMS 3.11.20b allows remote attackers to read arbitrary files via directory traversal sequences in the thCMS_root parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.92% | 25 September 2009 |
| CVE-2009-3424 | Multiple PHP remote file inclusion vulnerabilities in MaxCMS 3.11.20b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) is_projectPath parameter to includes/InstantSite/inc.is_root.php;… | EXPLOIT ✓MEDIUM 6.8EPSS 1.89% | 25 September 2009 |
| CVE-2009-3423 | login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1. | EXPLOIT ✓MEDIUM 6.8EPSS 2.57% | 25 September 2009 |
| CVE-2009-3422 | login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1. | EXPLOIT ✓MEDIUM 6.8EPSS 2.57% | 25 September 2009 |
| CVE-2009-3421 | login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1. | EXPLOIT ✓CRITICAL 9.8EPSS 4.99% | 25 September 2009 |
| CVE-2009-3420 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter and the (2) PATH_INFO. | EXPLOIT ✓MEDIUM 4.3EPSS 1.18% | 25 September 2009 |
| CVE-2009-3419 | SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 25 September 2009 |
| CVE-2009-3418 | Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL commands via the m parameter to manager/index.php and (2) remote authenticated administrators to execute arbitrary SQL commands via… | EXPLOIT ✓MEDIUM 6.5EPSS 0.80% | 25 September 2009 |
| CVE-2009-3417 | SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than CVE-2008-2627. | EXPLOIT ✓HIGH 7.5EPSS 1.79% | 25 September 2009 |
| CVE-2009-2817 | Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .pls file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 8.95% | 24 September 2009 |
| CVE-2009-3368 | Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to… | EXPLOIT ✓MEDIUM 4.3EPSS 1.53% | 24 September 2009 |
| CVE-2009-3367 | Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) index.php and (2) main.php, and the (3) show parameter to main.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 24 September 2009 |
| CVE-2009-3366 | Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary directories via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.69% | 24 September 2009 |
| CVE-2009-3365 | PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the AURORA_MODULES_FOLDER parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.09% | 24 September 2009 |
| CVE-2009-3364 | Stack-based buffer overflow in FTPShell Client 4.1 RC2 allows remote FTP servers to execute arbitrary code via a long response to a PASV command. | EXPLOIT ✓HIGH 9.3EPSS 5.45% | 24 September 2009 |
| CVE-2009-3362 | PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.96% | 24 September 2009 |
| CVE-2009-3361 | SQL injection vulnerability in index.php in PHP-IPNMonitor allows remote attackers to execute arbitrary SQL commands via the maincat_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 24 September 2009 |
| CVE-2009-3360 | Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) return parameter to photo_view.php, and st parameter to (2) photo_search.php and (3) search.php. | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.80% | 24 September 2009 |
| CVE-2009-3359 | Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.57% | 24 September 2009 |
| CVE-2009-3358 | SQL injection vulnerability in profile.php in Tourism Scripts Adult Portal escort listing allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.94% | 24 September 2009 |
| CVE-2009-3357 | Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) h_id, (2) id, and (3) rid parameters to longDesc.php,… | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 24 September 2009 |
| CVE-2009-3356 | SQL injection vulnerability in index.php in Image voting 1.0 allows remote attackers to execute arbitrary SQL commands via the show parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 24 September 2009 |
| CVE-2009-3355 | Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inject arbitrary web script or HTML via the s_r parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 24 September 2009 |
| CVE-2009-3349 | SQL injection vulnerability in Datavore Gyro 5.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a cat action to the home component. | EXPLOIT ✓HIGH 7.5EPSS 1.84% | 24 September 2009 |
| CVE-2009-3348 | Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a cat action to the home component. | EXPLOIT ✓MEDIUM 4.3EPSS 1.25% | 24 September 2009 |
| CVE-2009-3343 | SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 24 September 2009 |
| CVE-2009-3342 | SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 24 September 2009 |
| CVE-2009-3338 | Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file. | EXPLOIT ✓HIGH 9.3EPSS 5.79% | 24 September 2009 |
| CVE-2009-3336 | SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL commands via the auction_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 24 September 2009 |
| CVE-2009-3335 | SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 24 September 2009 |
| CVE-2009-3334 | SQL injection vulnerability in the Lhacky! | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 23 September 2009 |
| CVE-2009-3333 | PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 23 September 2009 |
| CVE-2009-3332 | SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 23 September 2009 |
| CVE-2009-3331 | Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the wwwRoot parameter to (1) header.php, (2) submit.php, (3) submitted.php, and (4) autosubmitter/index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.10% | 23 September 2009 |
| CVE-2009-3330 | SQL injection vulnerability in index.php in cP Creator 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tickets parameter in a support ticket action. | EXPLOIT ✓MEDIUM 6.8EPSS 0.85% | 23 September 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.