SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,461 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 217 of 501

CVESummaryPriorityPublished
CVE-2009-3328Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field).EXPLOIT ✓MEDIUM 4.3EPSS 1.22%23 September 2009
CVE-2009-3327Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php.EXPLOIT ✓HIGH 7.5EPSS 0.93%23 September 2009
CVE-2009-3326SQL injection vulnerability in index.php in CMScontrol Content Management System 7.x allows remote attackers to execute arbitrary SQL commands via the id_menu parameter.EXPLOIT ✓HIGH 7.5EPSS 0.92%23 September 2009
CVE-2009-3325SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.96%23 September 2009
CVE-2009-3324PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sPath parameter.EXPLOIT ✓HIGH 7.5EPSS 2.09%23 September 2009
CVE-2009-3323Multiple PHP remote file inclusion vulnerabilities in BAnner ROtation System mini (BAROSmini) 0.32.595 allow remote attackers to execute arbitrary PHP code via a URL in the baros_path parameter to (1) include/common_functions.php, and the main_path…EXPLOIT ✓HIGH 7.5EPSS 2.10%23 September 2009
CVE-2009-3322The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port 1723.EXPLOIT ✓HIGH 7.8EPSS 3.48%23 September 2009
CVE-2009-3321SQL injection vulnerability in SaphpLesson 4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP HTTP header.EXPLOIT ✓MEDIUM 6.8EPSS 0.94%23 September 2009
CVE-2009-3320Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.EXPLOIT ✓MEDIUM 4.3EPSS 1.48%23 September 2009
CVE-2009-3318Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a ..EXPLOIT ✓HIGH 7.5EPSS 6.46%23 September 2009
CVE-2009-3317PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to execute arbitrary PHP code via a URL in the path parameter, a different vector than CVE-2008-0648.EXPLOIT ✓HIGH 7.5EPSS 2.50%23 September 2009
CVE-2009-3316SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.02%23 September 2009
CVE-2009-3315SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field.EXPLOIT ✓HIGH 7.5EPSS 0.96%23 September 2009
CVE-2009-3314SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL commands via the platform parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%23 September 2009
CVE-2009-3313Multiple SQL injection vulnerabilities in FMyClone 2.3 allow remote attackers to execute arbitrary SQL commands via the comp parameter to (1) index.php and (2) editComments.php, and (3) allow remote authenticated administrators to execute arbitrary SQL…EXPLOIT ✓MEDIUM 6.5EPSS 1.08%23 September 2009
CVE-2009-3312PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a crafted URL in the include_class parameter.EXPLOIT ✓MEDIUM 6.8EPSS 4.22%23 September 2009
CVE-2009-3311Cross-site scripting (XSS) vulnerability in index.php in RSSMediaScript allows remote attackers to inject arbitrary web script or HTML via the page parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%23 September 2009
CVE-2009-3310SQL injection vulnerability in index.php in Zainu 1.0 allows remote attackers to execute arbitrary SQL commands via the album_id parameter in an AlbumSongs action.EXPLOIT ✓HIGH 7.5EPSS 1.00%23 September 2009
CVE-2009-3309SQL injection vulnerability in index.cfm in CF ShopKart 5.4 beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a ViewDetails action, a different vector than CVE-2008-6320.EXPLOIT ✓HIGH 7.5EPSS 0.96%23 September 2009
CVE-2009-3308SQL injection vulnerability in show-cat.php in FanUpdate 2.2.1 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%23 September 2009
CVE-2009-3307Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code via a URL in the FSPHP_LIB parameter to (1) FSphp.php, (2) navigation.php, and (3) pathwrite.php in lib/.EXPLOIT ✓HIGH 7.5EPSS 4.92%23 September 2009
CVE-2009-3306PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbitrary PHP code via a URL in the cs_base_path parameter.EXPLOIT ✓HIGH 7.5EPSS 6.12%23 September 2009
CVE-2009-3272Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls eval on a long string…EXPLOIT ✓MEDIUM 5.0EPSS 6.44%21 September 2009
CVE-2009-3271Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element.EXPLOIT ✓MEDIUM 4.3EPSS 4.21%21 September 2009
CVE-2009-3270Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.EXPLOIT ✓MEDIUM 5.0EPSS 28.2%18 September 2009
CVE-2009-2793The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is…EXPLOIT ✓MEDIUM 4.6EPSS 0.52%18 September 2009
CVE-2008-7246Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.EXPLOIT ✓MEDIUM 5.0EPSS 2.36%18 September 2009
CVE-2008-7245Opera 9.52 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.EXPLOIT ✓MEDIUM 5.0EPSS 6.26%18 September 2009
CVE-2008-7244Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.EXPLOIT ✓MEDIUM 5.0EPSS 4.47%18 September 2009
CVE-2009-3260Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the header of the topic in a comment.EXPLOIT ✓MEDIUM 4.3EPSS 1.27%18 September 2009
CVE-2009-3256Cross-site scripting (XSS) vulnerability in include/ajax/blogInfo.php in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the URI, as demonstrated by a SCRIPT element in an arbitrary parameter such as the asd parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.25%18 September 2009
CVE-2009-3254Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .upl playlist file.EXPLOIT ✓HIGH 9.3EPSS 4.77%18 September 2009
CVE-2009-3253Stack-based buffer overflow in TriceraSoft Swift Ultralite 1.032 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.EXPLOIT ✓HIGH 9.3EPSS 4.90%18 September 2009
CVE-2009-3252Multiple SQL injection vulnerabilities in news.php in Rock Band CMS 0.10 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) id parameters.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.02%18 September 2009
CVE-2009-3250The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based…EXPLOIT ✓HIGH 9.0EPSS 10.9%18 September 2009
CVE-2009-3249Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ×2 ✓HIGH 7.5EPSS 9.59%18 September 2009
CVE-2009-3248Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.EXPLOIT ✓MEDIUM 6.8EPSS 1.26%18 September 2009
CVE-2009-3247Cross-site scripting (XSS) vulnerability in the Activities module in vtiger CRM 5.0.4 allows remote attackers to inject arbitrary web script or HTML via the action parameter to phprint.php.EXPLOIT ✓MEDIUM 4.3EPSS 3.46%18 September 2009
CVE-2009-3246SQL injection vulnerability in spnews.php in MyBuxScript PTC-BUX allows remote attackers to execute arbitrary SQL commands via the id parameter in an spnews action to the default URI.EXPLOIT ✓HIGH 7.5EPSS 0.99%18 September 2009
CVE-2009-3244Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value.EXPLOIT ×2 ✓HIGH 9.3EPSS 20.4%18 September 2009
CVE-2009-3243Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations.EXPLOIT ✓MEDIUM 5.0EPSS 7.24%18 September 2009
CVE-2009-3242Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to "an uninitialized dissector handle," which triggers an…EXPLOIT ✓MEDIUM 5.0EPSS 7.78%18 September 2009
CVE-2009-3241Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets.EXPLOIT ✓HIGH 7.8EPSS 9.70%18 September 2009
CVE-2009-2937Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed.EXPLOIT ✓MEDIUM 4.3EPSS 4.50%18 September 2009
CVE-2008-7242Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, and (4) messagebody parameters to certain pages as…EXPLOIT ✓MEDIUM 4.3EPSS 1.51%17 September 2009
CVE-2008-7240Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to include and execute arbitrary local files via the template parameter.EXPLOIT ✓HIGH 7.5EPSS 6.34%17 September 2009
CVE-2009-3234Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a "big size data" to the perf_counter_open system call.EXPLOIT ✓MEDIUM 4.9EPSS 1.80%17 September 2009
CVE-2009-3233changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.EXPLOIT ✓HIGH 7.2EPSS 0.95%17 September 2009
CVE-2009-3226SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action.EXPLOIT ✓HIGH 7.5EPSS 1.13%16 September 2009
CVE-2009-3225Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter in a browse…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.51%16 September 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.