Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,512 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 224 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-2779 | SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 17 August 2009 |
| CVE-2009-2778 | Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 14 August 2009 |
| CVE-2009-2777 | SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL commands via the key parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 14 August 2009 |
| CVE-2009-2776 | SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 14 August 2009 |
| CVE-2009-2775 | SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 14 August 2009 |
| CVE-2009-2774 | SQL injection vulnerability in paidbanner.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 14 August 2009 |
| CVE-2009-2773 | PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.89% | 14 August 2009 |
| CVE-2009-2772 | Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via the part parameter to (1) quick_search.php and (2) viewprofile.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.79% | 14 August 2009 |
| CVE-2009-2770 | PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname cookie. | EXPLOIT ✓HIGH 7.5EPSS 2.57% | 14 August 2009 |
| CVE-2009-2769 | PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.69% | 14 August 2009 |
| CVE-2009-2767 | The init_posix_timers function in kernel/posix-timers.c in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (OOPS) or possibly gain privileges via a CLOCK_MONOTONIC_RAW clock_nanosleep call that triggers a NULL pointer… | EXPLOIT ✓HIGH 7.2EPSS 0.74% | 14 August 2009 |
| CVE-2009-2766 | httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests. | EXPLOIT ✓HIGH 7.5EPSS 5.13% | 14 August 2009 |
| CVE-2009-2765 | httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI. | EXPLOIT ×3 ✓HIGH 8.3EPSS 82.5% | 14 August 2009 |
| CVE-2009-2764 | Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference… | EXPLOIT ✓MEDIUM 5.0EPSS 11.0% | 14 August 2009 |
| CVE-2009-2692 | The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using… | EXPLOIT ×8 ✓HIGH 7.8EPSS 14.6% | 14 August 2009 |
| CVE-2008-6975 | Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the ping_ip parameter; (2) change the… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.31% | 14 August 2009 |
| CVE-2008-6974 | Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the ping_ip parameter; (2)… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.45% | 14 August 2009 |
| CVE-2009-2762 | wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes… | EXPLOIT ×3 ✓HIGH 7.5EPSS 19.6% | 13 August 2009 |
| CVE-2008-6971 | The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator state within a hidden form field and generates predictable validation… | EXPLOIT ✓HIGH 7.5EPSS 7.13% | 13 August 2009 |
| CVE-2008-6970 | SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter. | EXPLOIT ✓HIGH 7.5EPSS 7.25% | 13 August 2009 |
| CVE-2008-6968 | Multiple SQL injection vulnerabilities in submit.php in Pligg CMS 9.9.5 allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 13 August 2009 |
| CVE-2008-6966 | AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass authentication via a direct request to admin/user.php. | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 13 August 2009 |
| CVE-2008-6965 | AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2)… | EXPLOIT ✓HIGH 7.5EPSS 2.57% | 13 August 2009 |
| CVE-2008-6964 | SQL injection vulnerability in the login page in X7 Chat 2.0.5 allows remote attackers to execute arbitrary SQL commands via the password field. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 13 August 2009 |
| CVE-2008-6963 | admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct request. | EXPLOIT ✓HIGH 7.5EPSS 2.45% | 13 August 2009 |
| CVE-2009-2195 | Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers. | EXPLOIT ✓HIGH 9.3EPSS 13.3% | 12 August 2009 |
| CVE-2009-1534 | Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code… | EXPLOIT ✓HIGH 9.3EPSS 51.6% | 12 August 2009 |
| CVE-2008-6960 | download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php. | EXPLOIT ✓MEDIUM 5.0EPSS 6.97% | 12 August 2009 |
| CVE-2008-6959 | Insecure method vulnerability in the Chilkat Socket ActiveX control (ChilkatSocket.ChilkatSocket.1) in ChilkatSocket.dll 2.3.1.1 allows remote attackers to overwrite arbitrary files via the SaveLastError method. | EXPLOIT ✓HIGH 9.3EPSS 5.73% | 12 August 2009 |
| CVE-2008-6958 | Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 5.77% | 12 August 2009 |
| CVE-2008-6957 | Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.84% | 12 August 2009 |
| CVE-2008-6956 | Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. | EXPLOIT ✓MEDIUM 6.5EPSS 4.81% | 12 August 2009 |
| CVE-2008-6955 | mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini. | EXPLOIT ✓HIGH 7.5EPSS 6.36% | 12 August 2009 |
| CVE-2008-6953 | Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long oovoo: URI. | EXPLOIT ✓HIGH 9.3EPSS 8.60% | 12 August 2009 |
| CVE-2008-6952 | SQL injection vulnerability in Rss.php in MauryCMS 0.53.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.27% | 12 August 2009 |
| CVE-2008-6950 | Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 August 2009 |
| CVE-2008-6949 | Multiple cross-site request forgery (CSRF) vulnerabilities in Collabtive 0.4.8 allow remote attackers to hijack the authentication of administrators for requests that (1) submit or edit a new project, or (2) upload files to a project, or (3) attach… | EXPLOIT ✓MEDIUM 6.8EPSS 1.79% | 12 August 2009 |
| CVE-2008-6948 | Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and using a text/plain MIME type, then accessing it via a direct request to the file… | EXPLOIT ✓MEDIUM 6.5EPSS 7.87% | 12 August 2009 |
| CVE-2008-6947 | Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via unspecified vectors associated with the added mode in a users action to admin.php. | EXPLOIT ✓HIGH 7.5EPSS 7.87% | 12 August 2009 |
| CVE-2008-6946 | Cross-site scripting (XSS) vulnerability in manageproject.php in Collabtive 0.4.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via the project Name, which is not properly handled when the administrator performs an… | EXPLOIT ✓MEDIUM 4.3EPSS 3.44% | 12 August 2009 |
| CVE-2008-6944 | Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in… | EXPLOIT ×3 ✓MEDIUM 6.5EPSS 3.95% | 12 August 2009 |
| CVE-2008-6943 | Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the… | EXPLOIT ×3 ✓MEDIUM 6.5EPSS 3.95% | 12 August 2009 |
| CVE-2008-6942 | Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing… | EXPLOIT ×3 ✓MEDIUM 6.5EPSS 3.95% | 12 August 2009 |
| CVE-2008-6941 | SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQL commands via the password field. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 12 August 2009 |
| CVE-2008-6940 | TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain a database backup via a direct request to admin/backup/db. | EXPLOIT ✓HIGH 7.5EPSS 2.84% | 12 August 2009 |
| CVE-2008-6939 | TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cookie to the target username. | EXPLOIT ✓HIGH 7.5EPSS 3.12% | 12 August 2009 |
| CVE-2008-6938 | Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a… | EXPLOIT ✓MEDIUM 4.3EPSS 26.5% | 11 August 2009 |
| CVE-2008-6937 | Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an xmpp:// URI, a different vector than CVE-2008-6935 and… | EXPLOIT ×2 ✓HIGH 10.0EPSS 3.21% | 11 August 2009 |
| CVE-2008-6936 | Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in a pres:// URI, a different vector than CVE-2008-6935. | EXPLOIT ×2 ✓HIGH 9.3EPSS 3.12% | 11 August 2009 |
| CVE-2008-6935 | Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an im:// URI. | EXPLOIT ×2 ✓HIGH 10.0EPSS 5.38% | 11 August 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.