Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,461 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 217 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-3328 | Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). | EXPLOIT ✓MEDIUM 4.3EPSS 1.22% | 23 September 2009 |
| CVE-2009-3327 | Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 23 September 2009 |
| CVE-2009-3326 | SQL injection vulnerability in index.php in CMScontrol Content Management System 7.x allows remote attackers to execute arbitrary SQL commands via the id_menu parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 23 September 2009 |
| CVE-2009-3325 | SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 23 September 2009 |
| CVE-2009-3324 | PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sPath parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.09% | 23 September 2009 |
| CVE-2009-3323 | Multiple PHP remote file inclusion vulnerabilities in BAnner ROtation System mini (BAROSmini) 0.32.595 allow remote attackers to execute arbitrary PHP code via a URL in the baros_path parameter to (1) include/common_functions.php, and the main_path… | EXPLOIT ✓HIGH 7.5EPSS 2.10% | 23 September 2009 |
| CVE-2009-3322 | The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port 1723. | EXPLOIT ✓HIGH 7.8EPSS 3.48% | 23 September 2009 |
| CVE-2009-3321 | SQL injection vulnerability in SaphpLesson 4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP HTTP header. | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 23 September 2009 |
| CVE-2009-3320 | Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 23 September 2009 |
| CVE-2009-3318 | Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. | EXPLOIT ✓HIGH 7.5EPSS 6.46% | 23 September 2009 |
| CVE-2009-3317 | PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to execute arbitrary PHP code via a URL in the path parameter, a different vector than CVE-2008-0648. | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 23 September 2009 |
| CVE-2009-3316 | SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 23 September 2009 |
| CVE-2009-3315 | SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 23 September 2009 |
| CVE-2009-3314 | SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL commands via the platform parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 23 September 2009 |
| CVE-2009-3313 | Multiple SQL injection vulnerabilities in FMyClone 2.3 allow remote attackers to execute arbitrary SQL commands via the comp parameter to (1) index.php and (2) editComments.php, and (3) allow remote authenticated administrators to execute arbitrary SQL… | EXPLOIT ✓MEDIUM 6.5EPSS 1.08% | 23 September 2009 |
| CVE-2009-3312 | PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a crafted URL in the include_class parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 4.22% | 23 September 2009 |
| CVE-2009-3311 | Cross-site scripting (XSS) vulnerability in index.php in RSSMediaScript allows remote attackers to inject arbitrary web script or HTML via the page parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 23 September 2009 |
| CVE-2009-3310 | SQL injection vulnerability in index.php in Zainu 1.0 allows remote attackers to execute arbitrary SQL commands via the album_id parameter in an AlbumSongs action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 23 September 2009 |
| CVE-2009-3309 | SQL injection vulnerability in index.cfm in CF ShopKart 5.4 beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a ViewDetails action, a different vector than CVE-2008-6320. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 23 September 2009 |
| CVE-2009-3308 | SQL injection vulnerability in show-cat.php in FanUpdate 2.2.1 allows remote attackers to execute arbitrary SQL commands via the listingid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 23 September 2009 |
| CVE-2009-3307 | Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code via a URL in the FSPHP_LIB parameter to (1) FSphp.php, (2) navigation.php, and (3) pathwrite.php in lib/. | EXPLOIT ✓HIGH 7.5EPSS 4.92% | 23 September 2009 |
| CVE-2009-3306 | PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbitrary PHP code via a URL in the cs_base_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 6.12% | 23 September 2009 |
| CVE-2009-3272 | Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls eval on a long string… | EXPLOIT ✓MEDIUM 5.0EPSS 6.44% | 21 September 2009 |
| CVE-2009-3271 | Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element. | EXPLOIT ✓MEDIUM 4.3EPSS 4.21% | 21 September 2009 |
| CVE-2009-3270 | Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821. | EXPLOIT ✓MEDIUM 5.0EPSS 28.2% | 18 September 2009 |
| CVE-2009-2793 | The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is… | EXPLOIT ✓MEDIUM 4.6EPSS 0.52% | 18 September 2009 |
| CVE-2008-7246 | Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821. | EXPLOIT ✓MEDIUM 5.0EPSS 2.36% | 18 September 2009 |
| CVE-2008-7245 | Opera 9.52 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821. | EXPLOIT ✓MEDIUM 5.0EPSS 6.26% | 18 September 2009 |
| CVE-2008-7244 | Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821. | EXPLOIT ✓MEDIUM 5.0EPSS 4.47% | 18 September 2009 |
| CVE-2009-3260 | Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the header of the topic in a comment. | EXPLOIT ✓MEDIUM 4.3EPSS 1.27% | 18 September 2009 |
| CVE-2009-3256 | Cross-site scripting (XSS) vulnerability in include/ajax/blogInfo.php in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the URI, as demonstrated by a SCRIPT element in an arbitrary parameter such as the asd parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.25% | 18 September 2009 |
| CVE-2009-3254 | Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .upl playlist file. | EXPLOIT ✓HIGH 9.3EPSS 4.77% | 18 September 2009 |
| CVE-2009-3253 | Stack-based buffer overflow in TriceraSoft Swift Ultralite 1.032 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file. | EXPLOIT ✓HIGH 9.3EPSS 4.90% | 18 September 2009 |
| CVE-2009-3252 | Multiple SQL injection vulnerabilities in news.php in Rock Band CMS 0.10 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) id parameters. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.02% | 18 September 2009 |
| CVE-2009-3250 | The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based… | EXPLOIT ✓HIGH 9.0EPSS 10.9% | 18 September 2009 |
| CVE-2009-3249 | Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ×2 ✓HIGH 7.5EPSS 9.59% | 18 September 2009 |
| CVE-2009-3248 | Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.26% | 18 September 2009 |
| CVE-2009-3247 | Cross-site scripting (XSS) vulnerability in the Activities module in vtiger CRM 5.0.4 allows remote attackers to inject arbitrary web script or HTML via the action parameter to phprint.php. | EXPLOIT ✓MEDIUM 4.3EPSS 3.46% | 18 September 2009 |
| CVE-2009-3246 | SQL injection vulnerability in spnews.php in MyBuxScript PTC-BUX allows remote attackers to execute arbitrary SQL commands via the id parameter in an spnews action to the default URI. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 18 September 2009 |
| CVE-2009-3244 | Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value. | EXPLOIT ×2 ✓HIGH 9.3EPSS 20.4% | 18 September 2009 |
| CVE-2009-3243 | Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations. | EXPLOIT ✓MEDIUM 5.0EPSS 7.24% | 18 September 2009 |
| CVE-2009-3242 | Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to "an uninitialized dissector handle," which triggers an… | EXPLOIT ✓MEDIUM 5.0EPSS 7.78% | 18 September 2009 |
| CVE-2009-3241 | Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets. | EXPLOIT ✓HIGH 7.8EPSS 9.70% | 18 September 2009 |
| CVE-2009-2937 | Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed. | EXPLOIT ✓MEDIUM 4.3EPSS 4.50% | 18 September 2009 |
| CVE-2008-7242 | Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, and (4) messagebody parameters to certain pages as… | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 17 September 2009 |
| CVE-2008-7240 | Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to include and execute arbitrary local files via the template parameter. | EXPLOIT ✓HIGH 7.5EPSS 6.34% | 17 September 2009 |
| CVE-2009-3234 | Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a "big size data" to the perf_counter_open system call. | EXPLOIT ✓MEDIUM 4.9EPSS 1.80% | 17 September 2009 |
| CVE-2009-3233 | changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack. | EXPLOIT ✓HIGH 7.2EPSS 0.95% | 17 September 2009 |
| CVE-2009-3226 | SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 16 September 2009 |
| CVE-2009-3225 | Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter in a browse… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.51% | 16 September 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.