Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,465 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 219 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-7209 | Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbitrary code by uploading a file with an executable extension and using a safe content type such as… | EXPLOIT ✓HIGH 7.5EPSS 6.01% | 11 September 2009 |
| CVE-2008-7208 | Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username parameter ($usernameb variable) to a_login.php or (2) user parameter to staff.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.77% | 11 September 2009 |
| CVE-2008-7203 | Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets. | EXPLOIT ✓MEDIUM 5.0EPSS 2.61% | 11 September 2009 |
| CVE-2009-3076 | Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an… | EXPLOIT ✓HIGH 9.3EPSS 6.72% | 10 September 2009 |
| CVE-2009-3162 | Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI. | EXPLOIT ✓MEDIUM 4.3EPSS 1.27% | 10 September 2009 |
| CVE-2009-3158 | admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors. | EXPLOIT ✓HIGH 7.5EPSS 2.66% | 10 September 2009 |
| CVE-2009-3155 | Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 10 September 2009 |
| CVE-2009-3154 | SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than… | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 10 September 2009 |
| CVE-2009-3153 | Multiple cross-site scripting (XSS) vulnerabilities in x10 MP3 Search engine 1.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, id… | EXPLOIT ×8 ✓MEDIUM 4.3EPSS 1.52% | 10 September 2009 |
| CVE-2009-3152 | Multiple cross-site scripting (XSS) vulnerabilities in becommunity/community/index.php in NTSOFT BBS E-Market Professional allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) bt_code, and (3) b_no parameters in a board… | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 10 September 2009 |
| CVE-2009-3151 | Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.73% | 10 September 2009 |
| CVE-2009-3150 | SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands via the Browse parameter in a vote action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 10 September 2009 |
| CVE-2009-3149 | Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 2.83% | 10 September 2009 |
| CVE-2009-3148 | Multiple SQL injection vulnerabilities in PortalXP Teacher Edition 1.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) calendar.php, (2) news.php, and (3) links.php; and the (4) assignment_id parameter to… | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 10 September 2009 |
| CVE-2009-3124 | Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.99% | 9 September 2009 |
| CVE-2009-3123 | Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.74% | 9 September 2009 |
| CVE-2009-3119 | SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the view_id parameter. | EXPLOITHIGH 7.5EPSS 0.99% | 9 September 2009 |
| CVE-2009-3117 | SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 9 September 2009 |
| CVE-2009-3116 | SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the year parameter in a calendar action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 9 September 2009 |
| CVE-2009-3115 | SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a crafted Option Acknowledgement (OACK) request. | EXPLOIT ✓MEDIUM 5.0EPSS 10.7% | 9 September 2009 |
| CVE-2008-7192 | Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentication of users for requests that delete private messages via the pmID… | EXPLOIT ✓MEDIUM 6.8EPSS 0.82% | 9 September 2009 |
| CVE-2009-3111 | The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11. | EXPLOIT ✓MEDIUM 5.0EPSS 11.2% | 9 September 2009 |
| CVE-2008-7188 | ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a modified uid variable to siteadmin/useredit.php. | EXPLOIT ✓HIGH 7.5EPSS 2.30% | 9 September 2009 |
| CVE-2008-7185 | GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c. | EXPLOIT ✓MEDIUM 4.3EPSS 3.06% | 8 September 2009 |
| CVE-2008-7184 | Cross-site scripting (XSS) vulnerability in Diigo Toolbar and Diigolet allows remote attackers to inject arbitrary web script or HTML via a public comment. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 8 September 2009 |
| CVE-2009-3103 | Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system… | EXPLOIT ×6 ✓HIGH 10.0EPSS 92.3% | 8 September 2009 |
| CVE-2009-3099 | Unspecified vulnerability in HP OpenView Operations Manager 8.1 on Windows Server 2003 SP2 allows remote attackers to have an unknown impact, related to a "Remote exploit," as demonstrated by a certain module in VulnDisco Pack Professional 8.11, a… | EXPLOIT ✓HIGH 10.0EPSS 9.57% | 8 September 2009 |
| CVE-2008-7182 | Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long first argument to the APPEND… | EXPLOIT ✓MEDIUM 4.0EPSS 24.3% | 8 September 2009 |
| CVE-2008-7181 | Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter to category-delete.php with the is_js_confirmed parameter set to 1, or (2) delete arbitrary accounts via the mytable parameter to… | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 8 September 2009 |
| CVE-2008-7180 | del_query1.php in Telephone Directory 2008 allows remote attackers to delete arbitrary contacts via a direct request with a modified id variable. | EXPLOIT ✓MEDIUM 5.0EPSS 1.62% | 8 September 2009 |
| CVE-2008-7179 | OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN_Hora, ADMIN_Logado, and ADMIN_Nome cookies to certain values, as reachable in Admin/index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 8 September 2009 |
| CVE-2008-7178 | Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.17% | 8 September 2009 |
| CVE-2008-7176 | Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.97% | 8 September 2009 |
| CVE-2008-7172 | Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administrator privileges via direct requests to admin.php with the (1) potd_delete, (2) potd, (3) vote_update, (4)… | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 8 September 2009 |
| CVE-2008-7171 | Multiple cross-site scripting (XSS) vulnerabilities in Lightweight news portal (LNP) 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) photo parameter to show_photo.php, (2) potd parameter to show_potd.php, or (3) the… | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 8 September 2009 |
| CVE-2008-7170 | GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator commands via a crafted packet. | EXPLOITHIGH 10.0EPSS 9.95% | 8 September 2009 |
| CVE-2008-7169 | SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 8 September 2009 |
| CVE-2008-7168 | Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the Update method, as exploited in the wild in June 2009. | EXPLOIT ✓HIGH 9.3EPSS 5.65% | 8 September 2009 |
| CVE-2008-7167 | Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified… | EXPLOIT ✓HIGH 7.5EPSS 4.21% | 8 September 2009 |
| CVE-2009-3082 | SQL injection vulnerability in wcategory.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.89% | 4 September 2009 |
| CVE-2009-3081 | SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the month parameter in a calendar action. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 4 September 2009 |
| CVE-2009-3068 | Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a… | EXPLOIT ×2 ✓HIGH 9.3EPSS 78.2% | 4 September 2009 |
| CVE-2009-2521 | Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 82.3% | 4 September 2009 |
| CVE-2008-7165 | Cross-site request forgery in cp06_wifi_m_nocifr.cgi in the administrator panel in TELECOM ITALIA Alice Gate2 Plus Wi-Fi allows remote attackers to hijack the authentication of administrators for requests that disable Wi-Fi encryption via certain values… | EXPLOIT ✓MEDIUM 6.8EPSS 0.66% | 4 September 2009 |
| CVE-2008-7163 | Directory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the sine[config][index_main] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 4.08% | 4 September 2009 |
| CVE-2008-7162 | Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file. | EXPLOIT ✓HIGH 9.3EPSS 5.52% | 4 September 2009 |
| CVE-2008-7161 | Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via fragmented GET or POST requests that use HTTP/1.0 without the Host header. | EXPLOIT ✓HIGH 7.5EPSS 6.41% | 4 September 2009 |
| CVE-2009-3066 | Multiple cross-site scripting (XSS) vulnerabilities in PropertyWatchScript.com Property Watch 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) videoid parameter to tools/email.php and (2) redirect parameter to tools/login.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.29% | 3 September 2009 |
| CVE-2009-3065 | PHP remote file inclusion vulnerability in editor/edit_htmlarea.php in Ve-EDIT 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in the highlighter parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.19% | 3 September 2009 |
| CVE-2009-3064 | Directory traversal vulnerability in debugger/debug_php.php in Ve-EDIT 0.1.4 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.40% | 3 September 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.