Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,465 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 220 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-3063 | SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 3 September 2009 |
| CVE-2009-3062 | SQL injection vulnerability in message_box.php in OSI Codes PHP Live! | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 3 September 2009 |
| CVE-2009-3061 | SQL injection vulnerability in lesson.php in Alqatari Q R Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOITHIGH 7.5EPSS 0.97% | 3 September 2009 |
| CVE-2009-3059 | Multiple SQL injection vulnerabilities in Joker Board (aka JBoard) 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) core/select.php or (2) the city parameter to top_add.inc.php, reachable through sboard.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 3 September 2009 |
| CVE-2009-3058 | Stack-based buffer overflow in akPlayer 1.9.0 allows remote attackers to execute arbitrary code via a long string in a .plt playlist file. | EXPLOIT ✓HIGH 9.3EPSS 5.59% | 3 September 2009 |
| CVE-2009-3057 | Multiple cross-site scripting (XSS) vulnerabilities in AOM Software Beex 3 allow remote attackers to inject arbitrary web script or HTML via the navaction parameter to (1) news.php and (2) partneralle.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.29% | 3 September 2009 |
| CVE-2009-3056 | PHP remote file inclusion vulnerability in include/engine/content/elements/menu.php in KingCMS 0.6.0 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[AdminPath] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.09% | 3 September 2009 |
| CVE-2009-3055 | PHP remote file inclusion vulnerability in engine/api/api.class.php in DataLife Engine (DLE) 8.2 allows remote attackers to execute arbitrary PHP code via a URL in the dle_config_api parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 3 September 2009 |
| CVE-2009-3054 | SQL injection vulnerability in the Artetics.com Art Portal (com_artportal) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 3 September 2009 |
| CVE-2009-3053 | Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through… | EXPLOIT ✓MEDIUM 6.8EPSS 5.92% | 3 September 2009 |
| CVE-2009-3052 | SQL injection vulnerability in root/includes/prime_quick_style.php in the Prime Quick Style addon before 1.2.3 for phpBB 3 allows remote authenticated users to execute arbitrary SQL commands via the prime_quick_style parameter to ucp.php. | EXPLOIT ✓MEDIUM 6.5EPSS 0.88% | 3 September 2009 |
| CVE-2009-3043 | The tty_ldisc_hangup function in drivers/char/tty_ldisc.c in the Linux kernel 2.6.31-rc before 2.6.31-rc8 allows local users to cause a denial of service (system crash, sometimes preceded by a NULL pointer dereference) or possibly gain privileges via… | EXPLOIT ✓MEDIUM 4.9EPSS 0.85% | 2 September 2009 |
| CVE-2008-7157 | Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an avatar file with an executable extension followed by a safe extension, then accessing it via a direct request to the… | EXPLOIT ✓MEDIUM 6.8EPSS 3.33% | 2 September 2009 |
| CVE-2008-7156 | EkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator privileges by setting the _groups[] parameter to 2, as demonstrated via backup.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.91% | 2 September 2009 |
| CVE-2008-7155 | NetRisk 1.9.7 does not properly restrict access to admin/change_submit.php, which allows remote attackers to change the password of arbitrary users via a direct request. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 2 September 2009 |
| CVE-2008-7154 | Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) class.module/class.event_manager.php, (3) lib/lib.domxml5.php, or (4) menu/menu_over.php in doceboCore/; or (5)… | EXPLOIT ✓MEDIUM 5.0EPSS 2.54% | 2 September 2009 |
| CVE-2008-7153 | SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.39% | 2 September 2009 |
| CVE-2009-2958 | The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option. | EXPLOIT ✓MEDIUM 4.3EPSS 10.4% | 2 September 2009 |
| CVE-2009-2957 | Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request. | EXPLOIT ✓MEDIUM 6.8EPSS 12.7% | 2 September 2009 |
| CVE-2009-3042 | SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040. | EXPLOIT ✓HIGH 7.5EPSS 2.96% | 1 September 2009 |
| CVE-2009-3041 | SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as… | EXPLOIT ✓HIGH 7.5EPSS 6.59% | 1 September 2009 |
| CVE-2009-3040 | Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID… | EXPLOIT ✓HIGH 7.5EPSS 1.42% | 1 September 2009 |
| CVE-2009-3038 | A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBerry Desktop Manager 5.0.0.11 allows remote attackers to cause a denial of service (Internet Explorer crash) by referencing the… | EXPLOIT ✓MEDIUM 4.3EPSS 3.46% | 1 September 2009 |
| CVE-2008-7152 | Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) client.php or (2) taxonservice.php. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.92% | 1 September 2009 |
| CVE-2008-7145 | Multiple SQL injection vulnerabilities in index.php in CoronaMatrix phpAddressBook 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) parameters. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 1 September 2009 |
| CVE-2008-7142 | Absolute path traversal vulnerability in the Disk Usage module (frontend/x/diskusage/index.html) in cPanel 11.18.3 allows remote attackers to list arbitrary directories via the showtree parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.60% | 1 September 2009 |
| CVE-2008-7141 | Cross-site scripting (XSS) vulnerability in setup.php in @lex Poll 2.1 allows remote attackers to inject arbitrary web script or HTML via the language_setup parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 1 September 2009 |
| CVE-2008-7140 | Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) language_setup parameter to setup.php or (2) test parameter to index.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.48% | 1 September 2009 |
| CVE-2008-7136 | toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the (1) RequestURL, (2) GetPropertyById, or (3) SetPropertyById method, different vectors than CVE-2008-7135. | EXPLOIT ✓MEDIUM 4.3EPSS 4.24% | 1 September 2009 |
| CVE-2008-7135 | toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the IsChecked method, a different vector than CVE-2008-7136. | EXPLOIT ✓MEDIUM 4.3EPSS 2.15% | 1 September 2009 |
| CVE-2008-7134 | Multiple cross-site scripting (XSS) vulnerabilities in the default URI in Chris LaPointe RedGalaxy Download Center 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter, (2) message parameter in a login action, (3)… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.52% | 1 September 2009 |
| CVE-2008-7133 | Multiple cross-site scripting (XSS) vulnerabilities in onlinetools.org EasyImageCatalogue 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search and (2) d index.php parameters to index.php, (3) dir parameter to… | EXPLOIT ×4 ✓MEDIUM 4.3EPSS 1.46% | 1 September 2009 |
| CVE-2009-3023 | Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka… | EXPLOIT ×3 ✓HIGH 9.0EPSS 90.9% | 31 August 2009 |
| CVE-2009-3020 | win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly… | EXPLOIT ✓HIGH 7.1EPSS 16.7% | 31 August 2009 |
| CVE-2009-3019 | Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls createElement to create an instance of the LI element, and… | EXPLOIT ✓MEDIUM 5.0EPSS 17.4% | 31 August 2009 |
| CVE-2008-7126 | Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet with a large string length value to UDP… | EXPLOIT ✓HIGH 10.0EPSS 10.0% | 31 August 2009 |
| CVE-2008-7124 | zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator. | EXPLOIT ×2 ✓HIGH 7.5EPSS 8.61% | 31 August 2009 |
| CVE-2008-7123 | Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attackers to inject arbitrary PHP code into fichiers/config.php via a null byte (%00) in the login parameter in an ajout action, which… | EXPLOIT ✓MEDIUM 6.8EPSS 4.06% | 31 August 2009 |
| CVE-2009-3002 | The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the… | EXPLOIT ×2 ✓MEDIUM 4.9EPSS 1.03% | 28 August 2009 |
| CVE-2009-3001 | The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC… | EXPLOIT ✓MEDIUM 4.9EPSS 1.02% | 28 August 2009 |
| CVE-2008-7120 | SQL injection vulnerability in Mr. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 28 August 2009 |
| CVE-2008-7119 | SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 28 August 2009 |
| CVE-2008-7118 | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log. | EXPLOIT ✓MEDIUM 5.0EPSS 2.44% | 28 August 2009 |
| CVE-2008-7117 | eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with the file parameter set to style.css. | EXPLOIT ✓MEDIUM 5.0EPSS 1.73% | 28 August 2009 |
| CVE-2008-7116 | SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 28 August 2009 |
| CVE-2008-7115 | The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication and gain administrator privileges via a direct request to (1) statusprocess.exe, (2) system_all.exe, or… | EXPLOIT ✓HIGH 10.0EPSS 4.11% | 28 August 2009 |
| CVE-2008-7114 | SQL injection vulnerability in members_search.php in iFusion Services iFdate 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the name field. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 28 August 2009 |
| CVE-2008-7110 | Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to upload files to arbitrary locations via a .. | EXPLOIT ✓HIGH 7.8EPSS 2.88% | 28 August 2009 |
| CVE-2008-7107 | easdrv.sys in ESET Smart Security 3.0.667.0 allows local users to cause a denial of service (crash) via a crafted IOCTL 0x222003 request to the \\.\easdrv device interface. | EXPLOIT ✓HIGH 7.2EPSS 0.83% | 28 August 2009 |
| CVE-2008-7103 | Stack-based buffer overflow in an ActiveX control in najdisitoolbar.dll in Najdi.si Toolbar 2.0.4.1 allows remote attackers to cause a denial of service (browser crash) or execute arbitrary code via a long Document.Location property value. | EXPLOIT ✓HIGH 9.3EPSS 9.75% | 27 August 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.