SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,465 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 223 of 501

CVESummaryPriorityPublished
CVE-2009-2883SQL injection vulnerability in admin/login.php in SaphpLesson 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cp_username parameter, related to an error in the CleanVar function in…EXPLOIT ✓MEDIUM 6.8EPSS 0.90%20 August 2009
CVE-2009-2882Multiple cross-site scripting (XSS) vulnerabilities in PG MatchMaking allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) browse_ladies.php and (2) browse_men.php, the (3) gender parameter to search.php, and the…EXPLOIT ×4 ✓MEDIUM 4.3EPSS 1.67%20 August 2009
CVE-2009-2881Multiple SQL injection vulnerabilities in Basilic 1.5.13 allow remote attackers to execute arbitrary SQL commands via the idAuthor parameter to (1) index.php and possibly (2) allpubs.php in publications/.EXPLOIT ✓HIGH 7.5EPSS 1.15%20 August 2009
CVE-2008-7015Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure.EXPLOIT ✓MEDIUM 5.0EPSS 2.77%19 August 2009
CVE-2008-7014fhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an invalid character after the Basic value.EXPLOIT ✓MEDIUM 5.0EPSS 2.61%19 August 2009
CVE-2008-7012courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email…EXPLOIT ✓HIGH 7.8EPSS 6.67%19 August 2009
CVE-2008-7011The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads…EXPLOIT ✓MEDIUM 4.0EPSS 2.17%19 August 2009
CVE-2008-7010Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/register.php.EXPLOIT ✓HIGH 10.0EPSS 3.70%19 August 2009
CVE-2008-7009Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute arbitrary code via a file or directory with a long path.EXPLOIT ✓MEDIUM 6.9EPSS 1.06%19 August 2009
CVE-2008-7008HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db.EXPLOIT ✓MEDIUM 5.0EPSS 2.82%19 August 2009
CVE-2008-7007Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin_pass cookie values to 1.EXPLOIT ✓HIGH 7.5EPSS 2.59%19 August 2009
CVE-2008-7006Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.EXPLOIT ✓MEDIUM 5.0EPSS 6.64%19 August 2009
CVE-2008-7005include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary PHP code via the quotes_to_edit parameter.EXPLOIT ✓HIGH 7.5EPSS 9.11%19 August 2009
CVE-2008-7003Multiple SQL injection vulnerabilities in login.php in The Rat CMS Alpha 2 allow remote attackers to execute arbitrary SQL commands via the (1) user_id and (2) password parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%19 August 2009
CVE-2008-7002PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2)…EXPLOIT ✓HIGH 7.2EPSS 0.83%19 August 2009
CVE-2008-7001Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary code via unknown vectors.EXPLOIT ✓HIGH 7.5EPSS 3.55%19 August 2009
CVE-2008-7000PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter.EXPLOIT ✓HIGH 7.5EPSS 2.05%19 August 2009
CVE-2008-6998Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assisted remote attackers to execute arbitrary code via a link target (href attribute) with a large number…EXPLOIT ✓HIGH 9.3EPSS 9.68%19 August 2009
CVE-2008-6997Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG tag with a long src attribute, which triggers the crash when the victim performs an "Inspect Element" action.EXPLOIT ✓MEDIUM 4.3EPSS 3.68%19 August 2009
CVE-2008-6996Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that references…EXPLOIT ✓MEDIUM 5.0EPSS 6.42%19 August 2009
CVE-2008-6995Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a "%" (percent) character, which triggers a buffer…EXPLOIT ✓MEDIUM 4.3EPSS 4.80%19 August 2009
CVE-2008-6994Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in Google Chrome 0.2.149.27 allows user-assisted remote attackers to execute arbitrary code via a web page with a long TITLE element, which triggers the…EXPLOIT ✓HIGH 9.3EPSS 10.2%19 August 2009
CVE-2008-6992GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL.EXPLOIT ✓HIGH 7.5EPSS 1.38%19 August 2009
CVE-2008-6991SQL injection vulnerability in public/page.php in Websens CMSbright allows remote attackers to execute arbitrary SQL commands via the id_rub_page parameter.EXPLOIT ✓HIGH 7.5EPSS 2.06%19 August 2009
CVE-2008-6990SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.EXPLOIT ✓HIGH 7.5EPSS 1.03%19 August 2009
CVE-2008-6989SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%19 August 2009
CVE-2008-6988Multiple cross-site scripting (XSS) vulnerabilities in Easy Photo Gallery (aka Ezphotogallery) 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) galleryid parameter to gallery.php, and the (2) size or (3) imageid parameters…EXPLOIT ✓MEDIUM 4.3EPSS 1.86%19 August 2009
CVE-2008-6985Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter when (1) adding or (2)…EXPLOITMEDIUM 6.8EPSS 1.58%19 August 2009
CVE-2008-6983modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file specified in the gv_folder_data parameter, as demonstrated by modifying modules/tool/url2header.php.EXPLOIT ✓HIGH 7.5EPSS 5.79%19 August 2009
CVE-2008-6982Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentpath parameter.EXPLOIT ✓MEDIUM 4.3EPSS 5.73%19 August 2009
CVE-2008-6979Cross-site scripting (XSS) vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to inject arbitrary web script or HTML via the results_per_page parameter to index.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.00%19 August 2009
CVE-2008-6978Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in pics/, related to the…EXPLOIT ×2 ✓MEDIUM 6.8EPSS 4.29%19 August 2009
CVE-2008-6977Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a summary action.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.75%19 August 2009
CVE-2008-6976MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.EXPLOIT ✓MEDIUM 6.4EPSS 9.18%19 August 2009
CVE-2009-1873Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authenticated users to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.0EPSS 4.70%18 August 2009
CVE-2009-1872Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query…EXPLOIT ×4 ✓MEDIUM 4.3EPSS 16.1%18 August 2009
CVE-2009-2852WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via the test_filter[wp_head] array parameter to test/index.php, which is used in a call to the call_user_func_array…EXPLOIT ✓MEDIUM 6.8EPSS 4.81%18 August 2009
CVE-2009-2851Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.EXPLOIT ✓MEDIUM 4.3EPSS 7.90%18 August 2009
CVE-2009-2847The do_sigaltstack function in kernel/signal.c in Linux kernel 2.4 through 2.4.37 and 2.6 before 2.6.31-rc5, when running on 64-bit systems, does not clear certain padding bytes from a structure, which allows local users to obtain sensitive information…EXPLOIT ✓MEDIUM 4.9EPSS 0.94%18 August 2009
CVE-2009-2792Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.33%17 August 2009
CVE-2009-2791PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the offset parameter.EXPLOIT ✓HIGH 7.5EPSS 2.10%17 August 2009
CVE-2009-2790SQL injection vulnerability in cat_products.php in SoftBiz Dating Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.98%17 August 2009
CVE-2009-2788Multiple SQL injection vulnerabilities in Mobilelib GOLD 3 allow remote attackers to execute arbitrary SQL commands via the (1) adminName parameter to cp/auth.php, (2) cid parameter to artcat.php, and (3) catid parameter to show.php.EXPLOIT ✓HIGH 7.5EPSS 0.91%17 August 2009
CVE-2009-2787Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and…EXPLOIT ✓MEDIUM 6.8EPSS 4.17%17 August 2009
CVE-2009-2786SQL injection vulnerability in reputation.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the poster parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%17 August 2009
CVE-2009-2784Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 9.3EPSS 3.72%17 August 2009
CVE-2009-2783Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile/user.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.94%17 August 2009
CVE-2009-2782SQL injection vulnerability in the JFusion (com_jfusion) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.91%17 August 2009
CVE-2009-2781SQL injection vulnerability in forum.php in Arab Portal 2.x, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the qc parameter in an addcomment action, a different vector than CVE-2006-1666.EXPLOIT ✓MEDIUM 6.0EPSS 0.73%17 August 2009
CVE-2009-2780Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to category.php, view parameter to (2) login.php and (3) viewlisting.php, page parameter to…EXPLOIT ×6 ✓MEDIUM 4.3EPSS 2.24%17 August 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.