Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,465 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 222 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-7044 | SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via the ques parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 24 August 2009 |
| CVE-2008-7043 | Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to inject arbitrary web script or HTML via the Email parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 24 August 2009 |
| CVE-2008-7042 | PHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the tmp_sid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.31% | 24 August 2009 |
| CVE-2008-7041 | AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php. | EXPLOIT ✓HIGH 7.5EPSS 2.77% | 24 August 2009 |
| CVE-2008-7040 | SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.80% | 24 August 2009 |
| CVE-2008-7038 | SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.15% | 24 August 2009 |
| CVE-2008-7036 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 24 August 2009 |
| CVE-2008-7033 | SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than… | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 August 2009 |
| CVE-2008-7032 | Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrators and execute shell… | EXPLOIT ✓MEDIUM 6.8EPSS 2.42% | 24 August 2009 |
| CVE-2008-7031 | Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SSH packets, a different vulnerability than CVE-2008-0151. | EXPLOIT ✓HIGH 10.0EPSS 8.25% | 24 August 2009 |
| CVE-2008-7030 | Multiple SQL injection vulnerabilities in Site2Nite Real Estate Web allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field to an unspecified component, possibly agentlist.asp. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 August 2009 |
| CVE-2009-2934 | Multiple stack-based buffer overflows in xaudio.dll in Programmed Integration PIPL 2.5.0 and 2.5.0D allow remote attackers to execute arbitrary code via a long string in a (1) .pls or (2) .pl playlist file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 10.2% | 21 August 2009 |
| CVE-2009-2930 | Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI. | EXPLOIT ✓MEDIUM 4.3EPSS 1.20% | 21 August 2009 |
| CVE-2009-2929 | Multiple SQL injection vulnerabilities in TGS Content Management 0.x allow remote attackers to execute arbitrary SQL commands via the (1) tgs_language_id, (2) tpl_dir, (3) referer, (4) user-agent, (5) site, (6) option, (7) db_optimization, (8) owner,… | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 21 August 2009 |
| CVE-2009-2928 | Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839. | EXPLOIT ✓MEDIUM 4.3EPSS 1.22% | 21 August 2009 |
| CVE-2009-2927 | SQL injection vulnerability in DetailFile.php in DigitalSpinners DS CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the nFileId parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 21 August 2009 |
| CVE-2009-2926 | Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) day parameter to show_matchs.php and (2) pageno parameter to persons.php. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 21 August 2009 |
| CVE-2009-2473 | neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number… | EXPLOIT ✓MEDIUM 4.3EPSS 8.44% | 21 August 2009 |
| CVE-2009-1879 | Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote attackers to… | EXPLOIT ✓LOW 2.6EPSS 8.25% | 21 August 2009 |
| CVE-2008-7028 | RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a certain value. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 21 August 2009 |
| CVE-2008-7027 | Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 21 August 2009 |
| CVE-2008-7026 | Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct… | EXPLOIT ✓MEDIUM 6.8EPSS 4.70% | 21 August 2009 |
| CVE-2008-7025 | TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response. | EXPLOIT ✓MEDIUM 4.3EPSS 2.02% | 21 August 2009 |
| CVE-2008-7024 | admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users." | EXPLOIT ✓MEDIUM 6.8EPSS 2.53% | 21 August 2009 |
| CVE-2008-7022 | Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote attackers to execute arbitrary programs via the LoadXmlEmail method. | EXPLOIT ✓HIGH 9.3EPSS 4.82% | 21 August 2009 |
| CVE-2008-7021 | Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an image or logo, then accessing it via a direct… | EXPLOIT ✓MEDIUM 6.0EPSS 2.73% | 21 August 2009 |
| CVE-2008-7019 | Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 21 August 2009 |
| CVE-2008-7017 | Cross-site scripting (XSS) vulnerability in analyse.php in CAcert 20080921, and possibly other versions before 20080928, allows remote attackers to inject arbitrary web script or HTML via the CN (CommonName) field in the subject of an X.509 certificate. | EXPLOIT ✓MEDIUM 4.3EPSS 0.90% | 21 August 2009 |
| CVE-2009-2925 | Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 3.47% | 21 August 2009 |
| CVE-2009-2924 | Multiple SQL injection vulnerabilities in Videos Broadcast Yourself 2 allow remote attackers to execute arbitrary SQL commands via the (1) UploadID parameter to videoint.php, and possibly the (2) cat_id parameter to catvideo.php and (3) uid parameter to… | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 21 August 2009 |
| CVE-2009-2923 | Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.99% | 21 August 2009 |
| CVE-2009-2922 | Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 through 2.3.5 allows remote attackers to read arbitrary files via a base64-encoded file parameter. | EXPLOIT ✓HIGH 7.8EPSS 2.59% | 21 August 2009 |
| CVE-2009-2921 | Multiple SQL injection vulnerabilities in login.php in MOC Designs PHP News 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) newsuser parameter (User field) and (2) newspassword parameter (Password field). | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 21 August 2009 |
| CVE-2009-2920 | Multiple cross-site scripting (XSS) vulnerabilities in Elvin 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) component and (2) priority parameters to buglist.php; and the (3) Username (4) E-mail, (5) Pass, and (6) Confirm… | EXPLOIT ✓MEDIUM 4.3EPSS 1.22% | 21 August 2009 |
| CVE-2009-2918 | The tgbvpn.sys driver in TheGreenBow IPSec VPN Client 4.61.003 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted request to the 0x80000034 IOCTL, probably involving an input or output buffer size… | EXPLOIT ✓LOW 2.1EPSS 0.85% | 21 August 2009 |
| CVE-2009-2917 | Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted string in a (1) .cue or (2) .m3u playlist file. | EXPLOIT ✓MEDIUM 4.3EPSS 3.39% | 21 August 2009 |
| CVE-2009-2915 | SQL injection vulnerability in 2fly_gift.php in 2FLY Gift Delivery System 6.0 allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a content action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 21 August 2009 |
| CVE-2009-2732 | The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded… | EXPLOIT ✓MEDIUM 5.0EPSS 7.27% | 21 August 2009 |
| CVE-2009-2694 | The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory… | EXPLOIT ✓HIGH 10.0EPSS 20.3% | 21 August 2009 |
| CVE-2009-2896 | Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. | EXPLOIT ✓HIGH 9.3EPSS 5.59% | 20 August 2009 |
| CVE-2009-2895 | SQL injection vulnerability in rss.php in Ultimate Regnow Affiliate (URA) 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 20 August 2009 |
| CVE-2009-2894 | Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to product_desc.php, and the cid parameter to (2) showcategory.php and (3) gallery.php. | EXPLOIT ✓HIGH 7.5EPSS 1.18% | 20 August 2009 |
| CVE-2009-2893 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 20 August 2009 |
| CVE-2009-2892 | Multiple SQL injection vulnerabilities in header.php in Scripteen Free Image Hosting Script 2.3 allow remote attackers to execute arbitrary SQL commands via a (1) cookid or (2) cookgid cookie. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 20 August 2009 |
| CVE-2009-2891 | SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 20 August 2009 |
| CVE-2009-2890 | Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via the searchquery parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.06% | 20 August 2009 |
| CVE-2009-2889 | Cross-site scripting (XSS) vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to inject arbitrary web script or HTML via the letters parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 20 August 2009 |
| CVE-2009-2888 | SQL injection vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to execute arbitrary SQL commands via the n parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 20 August 2009 |
| CVE-2009-2885 | SQL injection vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to execute arbitrary SQL commands via the rank parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 20 August 2009 |
| CVE-2009-2884 | Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 20 August 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.