Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,465 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 218 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-3224 | SQL injection vulnerability in index.php in Super Mod System, when using the 68 Classifieds 3.1 Core System, allows remote attackers to execute arbitrary SQL commands via the s parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 16 September 2009 |
| CVE-2009-3223 | SQL injection vulnerability in ppc-add-keywords.php in Inout Adserver allows remote authenticated users to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 0.90% | 16 September 2009 |
| CVE-2009-3222 | Cross-site scripting (XSS) vulnerability in index.php in FreeWebScriptz Honest Traffic (FWSHT) 1.x allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.54% | 16 September 2009 |
| CVE-2009-3221 | Stack-based buffer overflow in Audio Lib Player (ALP) allows remote attackers to execute arbitrary code via a long URL in a .m3u playlist file. | EXPLOIT ✓HIGH 9.3EPSS 5.81% | 16 September 2009 |
| CVE-2009-3220 | PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.05% | 16 September 2009 |
| CVE-2009-3219 | Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 4.07% | 16 September 2009 |
| CVE-2009-3218 | SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 16 September 2009 |
| CVE-2009-3217 | SQL injection vulnerability in the admin module in iWiccle 1.01 allows remote attackers to execute arbitrary SQL commands via the member_id parameter in an edit_user action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 16 September 2009 |
| CVE-2009-3216 | Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 2.29% | 16 September 2009 |
| CVE-2009-3215 | SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 16 September 2009 |
| CVE-2009-3214 | Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code via a crafted Slideshow project (.psh) file, related to the (1) cell[n].images[m].image and (2) cell[n].sound.file fields. | EXPLOIT ×3 ✓HIGH 9.3EPSS 30.8% | 16 September 2009 |
| CVE-2009-3213 | Stack-based buffer overflow in broid 1.0 Beta 3a allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .mp3 file. | EXPLOIT ✓HIGH 9.3EPSS 4.87% | 16 September 2009 |
| CVE-2009-3211 | Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.92% | 16 September 2009 |
| CVE-2009-3209 | SQL injection vulnerability in remove.php in PHP eMail Manager 3.3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 16 September 2009 |
| CVE-2009-3208 | Multiple SQL injection vulnerabilities in phpfreeBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to permalink.php and (2) year parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 16 September 2009 |
| CVE-2009-3205 | SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_product action. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 16 September 2009 |
| CVE-2009-3203 | SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 16 September 2009 |
| CVE-2009-3202 | Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 16 September 2009 |
| CVE-2009-3201 | Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed header, which triggers a buffer overflow, a different vulnerability than… | EXPLOIT ✓MEDIUM 4.3EPSS 1.92% | 15 September 2009 |
| CVE-2009-2629 | Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests. | EXPLOIT ✓HIGH 7.5EPSS 75.1% | 15 September 2009 |
| CVE-2009-3199 | Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf. | EXPLOIT ✓MEDIUM 5.0EPSS 2.23% | 15 September 2009 |
| CVE-2009-3196 | Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 15 September 2009 |
| CVE-2009-3195 | Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) rss.php and (2) search.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.52% | 15 September 2009 |
| CVE-2009-3194 | Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject arbitrary web script or HTML via the search parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 15 September 2009 |
| CVE-2009-3193 | SQL injection vulnerability in the DigiFolio (com_digifolio) component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 15 September 2009 |
| CVE-2009-3191 | Multiple cross-site scripting (XSS) vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to inject arbitrary web script or HTML via the cat parameter to (1) rss.php and (2) opml.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.22% | 15 September 2009 |
| CVE-2009-3190 | Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 15 September 2009 |
| CVE-2009-3189 | Cross-site scripting (XSS) vulnerability in search.php in DigiOz Guestbook 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 15 September 2009 |
| CVE-2009-3188 | PHP remote file inclusion vulnerability in save.php in phpSANE 0.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the file_save parameter. | EXPLOIT ✓HIGH 7.5EPSS 6.05% | 15 September 2009 |
| CVE-2009-3187 | Cross-site scripting (XSS) vulnerability in gamelist.php in Stand Alone Arcade 1.1 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 15 September 2009 |
| CVE-2009-3186 | Multiple cross-site scripting (XSS) vulnerabilities in VideoGirls BiZ allow remote attackers to inject arbitrary web script or HTML via the (1) t parameter to forum.php, (2) profile_name parameter to profile.php, and (3) p parameter to view.php. | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.51% | 15 September 2009 |
| CVE-2009-3185 | SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQL commands via the fmid parameter in a view action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 15 September 2009 |
| CVE-2009-3184 | Multiple SQL injection vulnerabilities in index.php in Pirates of The Caribbean in the E-Gold Game Series allow remote attackers to execute arbitrary SQL commands via the (1) x and (2) y parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 15 September 2009 |
| CVE-2008-7232 | Buffer overflow in the report function in xtacacsd 4.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted CONNECT TACACS command. | EXPLOIT ✓HIGH 10.0EPSS 24.5% | 14 September 2009 |
| CVE-2008-7226 | SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the recipeid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 14 September 2009 |
| CVE-2008-7222 | Cross-site scripting (XSS) vulnerability in system/admin.php in RunCMS 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the rank_title parameter in a RankForumAdd action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 14 September 2009 |
| CVE-2007-6731 | Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow. | EXPLOIT ✓HIGH 10.0EPSS 14.1% | 13 September 2009 |
| CVE-2009-3182 | Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 3.29% | 11 September 2009 |
| CVE-2009-3181 | Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.04% | 11 September 2009 |
| CVE-2009-3180 | Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php. | EXPLOIT ✓HIGH 7.5EPSS 2.08% | 11 September 2009 |
| CVE-2009-3175 | Multiple SQL injection vulnerabilities in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allow remote attackers to execute arbitrary SQL commands via the user_id parameter to (1) view.php, (2) photos.php, and (3) motm.php;… | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 11 September 2009 |
| CVE-2009-3174 | PHP remote file inclusion vulnerability in fonctions_racine.php in OBOphiX 2.7.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin_lib parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.09% | 11 September 2009 |
| CVE-2009-3173 | Unrestricted file upload vulnerability in admin/add_album.php in The Rat CMS Alpha 2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/. | EXPLOIT ✓MEDIUM 6.8EPSS 3.47% | 11 September 2009 |
| CVE-2009-3171 | Multiple cross-site scripting (XSS) vulnerabilities in Anantasoft Gazelle CMS 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter to user.php or (2) lookup parameter to search.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.53% | 11 September 2009 |
| CVE-2009-3170 | Stack-based buffer overflow in AIMP2 Audio Converter 2.53 (build 330) and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long File1 argument in a (1) .pls or (2) .m3u playlist file. | EXPLOIT ×3 ✓HIGH 9.3EPSS 15.4% | 11 September 2009 |
| CVE-2009-3167 | Directory traversal vulnerability in index.php in Anantasoft Gazelle CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.35% | 11 September 2009 |
| CVE-2008-7216 | Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any additional distortion, which allows remote attackers to bypass CAPTCHA protection by reading certain bytes from the… | EXPLOIT ✓MEDIUM 4.3EPSS 5.85% | 11 September 2009 |
| CVE-2008-7213 | Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to inject arbitrary web script or HTML… | EXPLOIT ✓MEDIUM 4.3EPSS 2.15% | 11 September 2009 |
| CVE-2008-7211 | CreativeLabs es1371mp.sys 5.1.3612.0 WDM audio driver, as used in Ensoniq PCI 1371 sound cards and when running on Windows Vista, does not create a Functional Device Object (FDO) to prevent user-moade access to the Physical Device Object (PDO), which… | EXPLOITMEDIUM 6.9EPSS 0.78% | 11 September 2009 |
| CVE-2008-7210 | directory.php in AJchat 0.10 allows remote attackers to bypass input validation and conduct SQL injection attacks via a numeric parameter with a value matching the s parameter's hash value, which prevents the associated $_GET["s"] variable from being… | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 11 September 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.