SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,465 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 218 of 501

CVESummaryPriorityPublished
CVE-2009-3224SQL injection vulnerability in index.php in Super Mod System, when using the 68 Classifieds 3.1 Core System, allows remote attackers to execute arbitrary SQL commands via the s parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%16 September 2009
CVE-2009-3223SQL injection vulnerability in ppc-add-keywords.php in Inout Adserver allows remote authenticated users to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓MEDIUM 6.5EPSS 0.90%16 September 2009
CVE-2009-3222Cross-site scripting (XSS) vulnerability in index.php in FreeWebScriptz Honest Traffic (FWSHT) 1.x allows remote attackers to inject arbitrary web script or HTML via the msg parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.54%16 September 2009
CVE-2009-3221Stack-based buffer overflow in Audio Lib Player (ALP) allows remote attackers to execute arbitrary code via a long URL in a .m3u playlist file.EXPLOIT ✓HIGH 9.3EPSS 5.81%16 September 2009
CVE-2009-3220PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.EXPLOIT ✓HIGH 7.5EPSS 2.05%16 September 2009
CVE-2009-3219Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 4.07%16 September 2009
CVE-2009-3218SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.98%16 September 2009
CVE-2009-3217SQL injection vulnerability in the admin module in iWiccle 1.01 allows remote attackers to execute arbitrary SQL commands via the member_id parameter in an edit_user action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.95%16 September 2009
CVE-2009-3216Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 2.29%16 September 2009
CVE-2009-3215SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla!EXPLOIT ✓HIGH 7.5EPSS 1.06%16 September 2009
CVE-2009-3214Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code via a crafted Slideshow project (.psh) file, related to the (1) cell[n].images[m].image and (2) cell[n].sound.file fields.EXPLOIT ×3 ✓HIGH 9.3EPSS 30.8%16 September 2009
CVE-2009-3213Stack-based buffer overflow in broid 1.0 Beta 3a allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .mp3 file.EXPLOIT ✓HIGH 9.3EPSS 4.87%16 September 2009
CVE-2009-3211Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.92%16 September 2009
CVE-2009-3209SQL injection vulnerability in remove.php in PHP eMail Manager 3.3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%16 September 2009
CVE-2009-3208Multiple SQL injection vulnerabilities in phpfreeBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to permalink.php and (2) year parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.95%16 September 2009
CVE-2009-3205SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_product action.EXPLOIT ✓HIGH 7.5EPSS 0.99%16 September 2009
CVE-2009-3203SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%16 September 2009
CVE-2009-3202Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.48%16 September 2009
CVE-2009-3201Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed header, which triggers a buffer overflow, a different vulnerability than…EXPLOIT ✓MEDIUM 4.3EPSS 1.92%15 September 2009
CVE-2009-2629Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.EXPLOIT ✓HIGH 7.5EPSS 75.1%15 September 2009
CVE-2009-3199Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf.EXPLOIT ✓MEDIUM 5.0EPSS 2.23%15 September 2009
CVE-2009-3196Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arbitrary web script or HTML via the key parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%15 September 2009
CVE-2009-3195Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) rss.php and (2) search.php.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.52%15 September 2009
CVE-2009-3194Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject arbitrary web script or HTML via the search parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%15 September 2009
CVE-2009-3193SQL injection vulnerability in the DigiFolio (com_digifolio) component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.92%15 September 2009
CVE-2009-3191Multiple cross-site scripting (XSS) vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to inject arbitrary web script or HTML via the cat parameter to (1) rss.php and (2) opml.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.22%15 September 2009
CVE-2009-3190Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.EXPLOIT ✓HIGH 7.5EPSS 0.93%15 September 2009
CVE-2009-3189Cross-site scripting (XSS) vulnerability in search.php in DigiOz Guestbook 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%15 September 2009
CVE-2009-3188PHP remote file inclusion vulnerability in save.php in phpSANE 0.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the file_save parameter.EXPLOIT ✓HIGH 7.5EPSS 6.05%15 September 2009
CVE-2009-3187Cross-site scripting (XSS) vulnerability in gamelist.php in Stand Alone Arcade 1.1 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%15 September 2009
CVE-2009-3186Multiple cross-site scripting (XSS) vulnerabilities in VideoGirls BiZ allow remote attackers to inject arbitrary web script or HTML via the (1) t parameter to forum.php, (2) profile_name parameter to profile.php, and (3) p parameter to view.php.EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.51%15 September 2009
CVE-2009-3185SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQL commands via the fmid parameter in a view action.EXPLOIT ✓HIGH 7.5EPSS 0.97%15 September 2009
CVE-2009-3184Multiple SQL injection vulnerabilities in index.php in Pirates of The Caribbean in the E-Gold Game Series allow remote attackers to execute arbitrary SQL commands via the (1) x and (2) y parameters.EXPLOIT ✓HIGH 7.5EPSS 1.13%15 September 2009
CVE-2008-7232Buffer overflow in the report function in xtacacsd 4.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted CONNECT TACACS command.EXPLOIT ✓HIGH 10.0EPSS 24.5%14 September 2009
CVE-2008-7226SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the recipeid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%14 September 2009
CVE-2008-7222Cross-site scripting (XSS) vulnerability in system/admin.php in RunCMS 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the rank_title parameter in a RankForumAdd action.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%14 September 2009
CVE-2007-6731Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow.EXPLOIT ✓HIGH 10.0EPSS 14.1%13 September 2009
CVE-2009-3182Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to…EXPLOIT ×2 ✓MEDIUM 6.8EPSS 3.29%11 September 2009
CVE-2009-3181Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.04%11 September 2009
CVE-2009-3180Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php.EXPLOIT ✓HIGH 7.5EPSS 2.08%11 September 2009
CVE-2009-3175Multiple SQL injection vulnerabilities in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allow remote attackers to execute arbitrary SQL commands via the user_id parameter to (1) view.php, (2) photos.php, and (3) motm.php;…EXPLOIT ✓HIGH 7.5EPSS 0.92%11 September 2009
CVE-2009-3174PHP remote file inclusion vulnerability in fonctions_racine.php in OBOphiX 2.7.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin_lib parameter.EXPLOIT ✓HIGH 7.5EPSS 2.09%11 September 2009
CVE-2009-3173Unrestricted file upload vulnerability in admin/add_album.php in The Rat CMS Alpha 2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.EXPLOIT ✓MEDIUM 6.8EPSS 3.47%11 September 2009
CVE-2009-3171Multiple cross-site scripting (XSS) vulnerabilities in Anantasoft Gazelle CMS 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter to user.php or (2) lookup parameter to search.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.53%11 September 2009
CVE-2009-3170Stack-based buffer overflow in AIMP2 Audio Converter 2.53 (build 330) and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long File1 argument in a (1) .pls or (2) .m3u playlist file.EXPLOIT ×3 ✓HIGH 9.3EPSS 15.4%11 September 2009
CVE-2009-3167Directory traversal vulnerability in index.php in Anantasoft Gazelle CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a ..EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.35%11 September 2009
CVE-2008-7216Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any additional distortion, which allows remote attackers to bypass CAPTCHA protection by reading certain bytes from the…EXPLOIT ✓MEDIUM 4.3EPSS 5.85%11 September 2009
CVE-2008-7213Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to inject arbitrary web script or HTML…EXPLOIT ✓MEDIUM 4.3EPSS 2.15%11 September 2009
CVE-2008-7211CreativeLabs es1371mp.sys 5.1.3612.0 WDM audio driver, as used in Ensoniq PCI 1371 sound cards and when running on Windows Vista, does not create a Functional Device Object (FDO) to prevent user-moade access to the Physical Device Object (PDO), which…EXPLOITMEDIUM 6.9EPSS 0.78%11 September 2009
CVE-2008-7210directory.php in AJchat 0.10 allows remote attackers to bypass input validation and conduct SQL injection attacks via a numeric parameter with a value matching the s parameter's hash value, which prevents the associated $_GET["s"] variable from being…EXPLOIT ✓HIGH 7.5EPSS 1.14%11 September 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.