Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,512 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 226 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-6884 | Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 5.62% | 31 July 2009 |
| CVE-2009-1869 | Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly… | EXPLOIT ✓HIGH 9.3EPSS 19.7% | 31 July 2009 |
| CVE-2009-1868 | Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors… | EXPLOIT ✓HIGH 9.3EPSS 21.4% | 31 July 2009 |
| CVE-2008-6883 | SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 30 July 2009 |
| CVE-2009-2650 | Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .m3u or possibly (2) .pst file. | EXPLOIT ×3 ✓HIGH 9.3EPSS 30.7% | 30 July 2009 |
| CVE-2009-2649 | The IATA (ata) driver in FreeBSD 6.0 and 8.0, when read access to /dev is available, allows local users to cause a denial of service (kernel panic) via a certain IOCTL request with a large count, which triggers a malloc call with a large value. | EXPLOIT ✓MEDIUM 4.7EPSS 0.78% | 30 July 2009 |
| CVE-2008-6882 | Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 30 July 2009 |
| CVE-2008-6881 | Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to (1) getChat.php, (2) getChatRoom.php, and (3) getSavedChatRooms.php. | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 30 July 2009 |
| CVE-2008-6880 | SQL injection vulnerability in joke.php in EasySiteNetwork Free Jokes Website allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 30 July 2009 |
| CVE-2009-2620 | src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that… | EXPLOIT ✓MEDIUM 5.0EPSS 8.63% | 29 July 2009 |
| CVE-2009-0696 | The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit)… | EXPLOIT ✓MEDIUM 4.3EPSS 12.6% | 29 July 2009 |
| CVE-2009-2642 | index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to 1 and the uid cookie to an integer value, as demonstrated by a value of 13. | EXPLOIT ✓HIGH 7.5EPSS 2.42% | 28 July 2009 |
| CVE-2009-2641 | PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.68% | 28 July 2009 |
| CVE-2009-2640 | Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 28 July 2009 |
| CVE-2009-2639 | SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewticket action. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 28 July 2009 |
| CVE-2009-2638 | SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a reply action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 28 July 2009 |
| CVE-2009-2637 | PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 28 July 2009 |
| CVE-2009-2635 | PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.09% | 28 July 2009 |
| CVE-2009-2634 | PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.09% | 28 July 2009 |
| CVE-2009-2633 | PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.09% | 28 July 2009 |
| CVE-2009-2619 | SQL injection vulnerability in login.asp in DataCheck Solutions V-SpacePal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | EXPLOITHIGH 7.5EPSS 1.02% | 27 July 2009 |
| CVE-2009-2618 | SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results action to modules.php. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 27 July 2009 |
| CVE-2009-2617 | Stack-based buffer overflow in medialib.dll in BaoFeng Storm 3.9.62 allows remote attackers to execute arbitrary code via a long pathname in the source attribute of an item element in a .smpl playlist file. | EXPLOIT ✓HIGH 9.3EPSS 5.59% | 27 July 2009 |
| CVE-2009-2614 | SQL injection vulnerability in z_admin_login.asp in DataCheck Solutions LinkPal 1.x allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 0.89% | 27 July 2009 |
| CVE-2009-2611 | Directory traversal vulnerability in infusions/last_seen_users_panel/last_seen_users_panel.php in MyFusion (aka MyF) 6 Beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.97% | 27 July 2009 |
| CVE-2009-2609 | SQL injection vulnerability in the amoCourse (com_amocourse) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 27 July 2009 |
| CVE-2009-2608 | Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 27 July 2009 |
| CVE-2009-2607 | SQL injection vulnerability in the com_pinboard component for Joomla! allows remote attackers to execute arbitrary SQL commands via the task parameter in a showpic action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 27 July 2009 |
| CVE-2009-2606 | ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for NFL.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.23% | 27 July 2009 |
| CVE-2009-2605 | Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser and (2) truppassword cookies to uploadcp/index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 27 July 2009 |
| CVE-2009-2604 | Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 27 July 2009 |
| CVE-2009-2603 | Multiple SQL injection vulnerabilities in index.php in Escon SupportPortal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) tid parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 27 July 2009 |
| CVE-2009-2602 | R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.23% | 27 July 2009 |
| CVE-2009-2601 | SQL injection vulnerability in the Joomlaequipment (aka JUser or com_juser) component 2.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_profile action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 27 July 2009 |
| CVE-2009-2600 | Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.08% | 27 July 2009 |
| CVE-2009-2599 | SQL injection vulnerability in index.php in RadCLASSIFIEDS Gold 2.0 allows remote attackers to execute arbitrary SQL commands via the seller parameter in a search action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 27 July 2009 |
| CVE-2009-2598 | Multiple SQL injection vulnerabilities in Online Grades & Attendance 3.2.6 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the key parameter in a resetpass action to index.php and (2) remote authenticated users to execute… | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 0.89% | 27 July 2009 |
| CVE-2009-2595 | Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action. | EXPLOITMEDIUM 4.3EPSS 1.73% | 24 July 2009 |
| CVE-2009-2594 | Cross-site scripting (XSS) vulnerability in censura.php in Censura 1.16.04 allows remote attackers to inject arbitrary web script or HTML via the itemid parameter in a details action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 24 July 2009 |
| CVE-2009-2593 | SQL injection vulnerability in censura.php in Censura 1.16.04 allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a details action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 24 July 2009 |
| CVE-2009-2591 | SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 24 July 2009 |
| CVE-2009-2588 | Multiple cross-site scripting (XSS) vulnerabilities in Hotscripts Type PHP Clone Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php. | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 2.21% | 24 July 2009 |
| CVE-2009-2587 | Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to assets/js/ddcart.php, the (2) prefix parameter to includes/ajax/getstate.php, the search… | EXPLOIT ×6 ✓MEDIUM 4.3EPSS 2.26% | 24 July 2009 |
| CVE-2009-2586 | Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP EZArticles allows remote attackers to inject arbitrary web script or HTML via the title parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 24 July 2009 |
| CVE-2009-2585 | SQL injection vulnerability in index.php in Mlffat 2.2 allows remote attackers to execute arbitrary SQL commands via a member cookie in an account editprofile action, a different vector than CVE-2009-1731. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 24 July 2009 |
| CVE-2008-6875 | SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 24 July 2009 |
| CVE-2008-6874 | Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQL commands via the iType parameter in (1) Auto1/type.asp or (2) auto2/type.asp. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 July 2009 |
| CVE-2008-6873 | SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 23 July 2009 |
| CVE-2008-6872 | ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/aspthaiForum.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 5.91% | 23 July 2009 |
| CVE-2008-6871 | Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive information via a direct request. | EXPLOIT ✓MEDIUM 5.0EPSS 2.46% | 23 July 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.