SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,512 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 226 of 501

CVESummaryPriorityPublished
CVE-2008-6884Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 5.62%31 July 2009
CVE-2009-1869Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly…EXPLOIT ✓HIGH 9.3EPSS 19.7%31 July 2009
CVE-2009-1868Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors…EXPLOIT ✓HIGH 9.3EPSS 21.4%31 July 2009
CVE-2008-6883SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%30 July 2009
CVE-2009-2650Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .m3u or possibly (2) .pst file.EXPLOIT ×3 ✓HIGH 9.3EPSS 30.7%30 July 2009
CVE-2009-2649The IATA (ata) driver in FreeBSD 6.0 and 8.0, when read access to /dev is available, allows local users to cause a denial of service (kernel panic) via a certain IOCTL request with a large count, which triggers a malloc call with a large value.EXPLOIT ✓MEDIUM 4.7EPSS 0.78%30 July 2009
CVE-2008-6882Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.EXPLOIT ✓HIGH 7.5EPSS 2.29%30 July 2009
CVE-2008-6881Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to (1) getChat.php, (2) getChatRoom.php, and (3) getSavedChatRooms.php.EXPLOIT ✓HIGH 7.5EPSS 1.03%30 July 2009
CVE-2008-6880SQL injection vulnerability in joke.php in EasySiteNetwork Free Jokes Website allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%30 July 2009
CVE-2009-2620src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that…EXPLOIT ✓MEDIUM 5.0EPSS 8.63%29 July 2009
CVE-2009-0696The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit)…EXPLOIT ✓MEDIUM 4.3EPSS 12.6%29 July 2009
CVE-2009-2642index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to 1 and the uid cookie to an integer value, as demonstrated by a value of 13.EXPLOIT ✓HIGH 7.5EPSS 2.42%28 July 2009
CVE-2009-2641PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.68%28 July 2009
CVE-2009-2640Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.EXPLOIT ✓HIGH 7.5EPSS 1.04%28 July 2009
CVE-2009-2639SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewticket action.EXPLOIT ✓HIGH 7.5EPSS 0.92%28 July 2009
CVE-2009-2638SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a reply action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.91%28 July 2009
CVE-2009-2637PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.29%28 July 2009
CVE-2009-2635PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.09%28 July 2009
CVE-2009-2634PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.09%28 July 2009
CVE-2009-2633PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.09%28 July 2009
CVE-2009-2619SQL injection vulnerability in login.asp in DataCheck Solutions V-SpacePal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.EXPLOITHIGH 7.5EPSS 1.02%27 July 2009
CVE-2009-2618SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results action to modules.php.EXPLOIT ✓HIGH 7.5EPSS 0.96%27 July 2009
CVE-2009-2617Stack-based buffer overflow in medialib.dll in BaoFeng Storm 3.9.62 allows remote attackers to execute arbitrary code via a long pathname in the source attribute of an item element in a .smpl playlist file.EXPLOIT ✓HIGH 9.3EPSS 5.59%27 July 2009
CVE-2009-2614SQL injection vulnerability in z_admin_login.asp in DataCheck Solutions LinkPal 1.x allows remote attackers to execute arbitrary SQL commands via unspecified vectors.EXPLOIT ✓HIGH 7.5EPSS 0.89%27 July 2009
CVE-2009-2611Directory traversal vulnerability in infusions/last_seen_users_panel/last_seen_users_panel.php in MyFusion (aka MyF) 6 Beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.97%27 July 2009
CVE-2009-2609SQL injection vulnerability in the amoCourse (com_amocourse) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.96%27 July 2009
CVE-2009-2608Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%27 July 2009
CVE-2009-2607SQL injection vulnerability in the com_pinboard component for Joomla! allows remote attackers to execute arbitrary SQL commands via the task parameter in a showpic action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.99%27 July 2009
CVE-2009-2606ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for NFL.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.23%27 July 2009
CVE-2009-2605Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser and (2) truppassword cookies to uploadcp/index.php.EXPLOIT ✓MEDIUM 6.8EPSS 1.98%27 July 2009
CVE-2009-2604Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp.EXPLOIT ✓HIGH 7.5EPSS 0.93%27 July 2009
CVE-2009-2603Multiple SQL injection vulnerabilities in index.php in Escon SupportPortal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) tid parameters.EXPLOIT ✓HIGH 7.5EPSS 1.00%27 July 2009
CVE-2009-2602R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.23%27 July 2009
CVE-2009-2601SQL injection vulnerability in the Joomlaequipment (aka JUser or com_juser) component 2.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_profile action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.93%27 July 2009
CVE-2009-2600Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a ..EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.08%27 July 2009
CVE-2009-2599SQL injection vulnerability in index.php in RadCLASSIFIEDS Gold 2.0 allows remote attackers to execute arbitrary SQL commands via the seller parameter in a search action.EXPLOIT ✓HIGH 7.5EPSS 1.00%27 July 2009
CVE-2009-2598Multiple SQL injection vulnerabilities in Online Grades & Attendance 3.2.6 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the key parameter in a resetpass action to index.php and (2) remote authenticated users to execute…EXPLOIT ×2 ✓MEDIUM 6.5EPSS 0.89%27 July 2009
CVE-2009-2595Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.EXPLOITMEDIUM 4.3EPSS 1.73%24 July 2009
CVE-2009-2594Cross-site scripting (XSS) vulnerability in censura.php in Censura 1.16.04 allows remote attackers to inject arbitrary web script or HTML via the itemid parameter in a details action.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%24 July 2009
CVE-2009-2593SQL injection vulnerability in censura.php in Censura 1.16.04 allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a details action.EXPLOIT ✓HIGH 7.5EPSS 1.00%24 July 2009
CVE-2009-2591SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.96%24 July 2009
CVE-2009-2588Multiple cross-site scripting (XSS) vulnerabilities in Hotscripts Type PHP Clone Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php.EXPLOIT ×3 ✓MEDIUM 4.3EPSS 2.21%24 July 2009
CVE-2009-2587Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to assets/js/ddcart.php, the (2) prefix parameter to includes/ajax/getstate.php, the search…EXPLOIT ×6 ✓MEDIUM 4.3EPSS 2.26%24 July 2009
CVE-2009-2586Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP EZArticles allows remote attackers to inject arbitrary web script or HTML via the title parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.48%24 July 2009
CVE-2009-2585SQL injection vulnerability in index.php in Mlffat 2.2 allows remote attackers to execute arbitrary SQL commands via a member cookie in an account editprofile action, a different vector than CVE-2009-1731.EXPLOIT ✓HIGH 7.5EPSS 1.01%24 July 2009
CVE-2008-6875SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.EXPLOIT ✓HIGH 7.5EPSS 1.15%24 July 2009
CVE-2008-6874Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQL commands via the iType parameter in (1) Auto1/type.asp or (2) auto2/type.asp.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 July 2009
CVE-2008-6873SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx.EXPLOIT ✓HIGH 7.5EPSS 1.00%23 July 2009
CVE-2008-6872ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/aspthaiForum.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 5.91%23 July 2009
CVE-2008-6871Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive information via a direct request.EXPLOIT ✓MEDIUM 5.0EPSS 2.46%23 July 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.