Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,512 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 227 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-6870 | Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp. | EXPLOIT ✓MEDIUM 5.0EPSS 2.73% | 23 July 2009 |
| CVE-2008-6869 | Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for config/oramon.ini. | EXPLOIT ✓MEDIUM 5.0EPSS 6.20% | 23 July 2009 |
| CVE-2009-2464 | The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute… | EXPLOIT ✓HIGH 10.0EPSS 13.2% | 22 July 2009 |
| CVE-2009-2574 | index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via an opt action. | EXPLOIT ✓MEDIUM 6.5EPSS 1.94% | 22 July 2009 |
| CVE-2009-2573 | Multiple SQL injection vulnerabilities in MiniTwitter 0.2 beta, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via the (1) user parameter to (a) index.php and (b) rss.php. | EXPLOIT ✓MEDIUM 6.0EPSS 0.82% | 22 July 2009 |
| CVE-2009-2571 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in VerliAdmin 0.3.7 and 0.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the URI, (2) the q parameter, (3) the nick parameter, or (4) the nick parameter in a… | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 22 July 2009 |
| CVE-2009-2570 | Stack-based buffer overflow in the Symantec.FaxViewerControl.1 ActiveX control in WinFax\DCCFAXVW.DLL in Symantec WinFax Pro 10.03 allows remote attackers to execute arbitrary code via a long argument to the AppendFax method. | EXPLOIT ✓HIGH 9.3EPSS 11.9% | 22 July 2009 |
| CVE-2009-2569 | Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to… | EXPLOIT ✓MEDIUM 4.3EPSS 1.76% | 22 July 2009 |
| CVE-2009-2568 | Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 6.18% | 22 July 2009 |
| CVE-2009-2567 | SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 5.6.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 22 July 2009 |
| CVE-2009-2566 | Stack-based buffer overflow in TFM MMPlayer 2.0, and possibly 2.0.0.30, allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file. | EXPLOIT ✓HIGH 9.3EPSS 31.1% | 21 July 2009 |
| CVE-2009-2564 | NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions… | EXPLOIT ×2 ✓HIGH 7.2EPSS 5.64% | 21 July 2009 |
| CVE-2009-2558 | system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct request. | EXPLOIT ✓HIGH 7.5EPSS 2.42% | 21 July 2009 |
| CVE-2009-2557 | Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 6.78% | 21 July 2009 |
| CVE-2009-2554 | SQL injection vulnerability in the search method in jobline.class.php in Jobline (com_jobline) 1.1.2.2, 1.3.1, and possibly earlier versions, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the search parameter in… | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 20 July 2009 |
| CVE-2009-2553 | Multiple SQL injection vulnerabilities in comments.php in Super Simple Blog Script 2.5.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the entry parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.95% | 20 July 2009 |
| CVE-2009-2552 | Multiple directory traversal vulnerabilities in comments.php in Super Simple Blog Script 2.5.4 allow remote attackers to overwrite, include, and execute arbitrary local files via the entry parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 20 July 2009 |
| CVE-2009-2551 | Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web script or HTML via the id parameter in a detail action to (1) main.php and possibly (2) demo_page.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.53% | 20 July 2009 |
| CVE-2009-2550 | Stack-based buffer overflow in Hamster Audio Player 0.3a allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .hpl playlist file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 8.66% | 20 July 2009 |
| CVE-2009-2544 | Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! | EXPLOIT ✓MEDIUM 6.8EPSS 3.43% | 20 July 2009 |
| CVE-2009-2535 | Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a… | EXPLOIT ✓MEDIUM 5.0EPSS 9.36% | 20 July 2009 |
| CVE-2009-2534 | RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the URI. | EXPLOIT ✓MEDIUM 5.0EPSS 8.83% | 20 July 2009 |
| CVE-2009-2533 | rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SET_PARAMETER requests with empty DataConvertBuffer headers. | EXPLOIT ✓MEDIUM 5.0EPSS 3.40% | 20 July 2009 |
| CVE-2009-1897 | The tun_chr_poll function in drivers/net/tun.c in the tun subsystem in the Linux kernel 2.6.30 and 2.6.30.1, when the -fno-delete-null-pointer-checks gcc option is omitted, allows local users to gain privileges via vectors involving a NULL pointer… | EXPLOIT ×2 ✓MEDIUM 6.9EPSS 1.52% | 20 July 2009 |
| CVE-2009-1894 | Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe… | EXPLOIT ×2 ✓HIGH 7.2EPSS 0.74% | 17 July 2009 |
| CVE-2009-2485 | Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a .ht3 file. | EXPLOIT ×3 ✓HIGH 9.3EPSS 58.1% | 16 July 2009 |
| CVE-2009-2484 | Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute… | EXPLOIT ×2 ✓HIGH 9.3EPSS 35.1% | 16 July 2009 |
| CVE-2009-2479 | Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. | EXPLOIT ✓HIGH 7.8EPSS 12.1% | 16 July 2009 |
| CVE-2009-2478 | Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, related to a "flash bug." | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 7.81% | 16 July 2009 |
| CVE-2009-2477 | js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory… | EXPLOIT ×4 ✓HIGH 9.3EPSS 42.7% | 15 July 2009 |
| CVE-2009-1136 | The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007… | EXPLOIT ×2 ✓HIGH 9.3EPSS 62.0% | 15 July 2009 |
| CVE-2009-1978 | Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ✓HIGH 9.0EPSS 64.7% | 14 July 2009 |
| CVE-2009-1977 | Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ✓HIGH 10.0EPSS 72.6% | 14 July 2009 |
| CVE-2009-1975 | Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality, integrity, and availability, related to the WLS Console Package. | EXPLOIT ✓MEDIUM 6.8EPSS 2.70% | 14 July 2009 |
| CVE-2009-1970 | Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-0991. | EXPLOIT ✓MEDIUM 5.0EPSS 12.2% | 14 July 2009 |
| CVE-2009-1968 | Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. | EXPLOIT ✓MEDIUM 4.3EPSS 40.1% | 14 July 2009 |
| CVE-2009-1963 | Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows remote authenticated users to affect integrity and availability via unknown vectors. | EXPLOIT ✓HIGH 7.5EPSS 8.73% | 14 July 2009 |
| CVE-2009-1020 | Unspecified vulnerability in the Network Foundation component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ✓HIGH 9.0EPSS 10.3% | 14 July 2009 |
| CVE-2009-1019 | Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | EXPLOIT ✓HIGH 7.5EPSS 10.5% | 14 July 2009 |
| CVE-2009-1422 | Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to gain privileges via unknown vectors, aka PR_41209. | EXPLOIT ✓HIGH 10.0EPSS 5.08% | 14 July 2009 |
| CVE-2009-0692 | Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted… | EXPLOIT ✓HIGH 10.0EPSS 25.8% | 14 July 2009 |
| CVE-2009-0192 | Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based… | EXPLOIT ✓MEDIUM 5.0EPSS 12.3% | 14 July 2009 |
| CVE-2009-2451 | Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters in a calendar action, or (3) a search term in the… | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 14 July 2009 |
| CVE-2008-6867 | SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbitrary SQL commands via the topic parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 14 July 2009 |
| CVE-2008-6864 | Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | EXPLOIT ✓HIGH 7.5EPSS 2.51% | 14 July 2009 |
| CVE-2008-6863 | Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | EXPLOIT ✓HIGH 7.5EPSS 2.51% | 14 July 2009 |
| CVE-2008-6862 | Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | EXPLOIT ✓HIGH 7.5EPSS 2.51% | 14 July 2009 |
| CVE-2008-6861 | Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | EXPLOIT ✓HIGH 7.5EPSS 2.51% | 14 July 2009 |
| CVE-2008-6860 | Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | EXPLOIT ✓HIGH 7.5EPSS 2.52% | 14 July 2009 |
| CVE-2008-6859 | Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | EXPLOIT ✓HIGH 7.5EPSS 2.51% | 14 July 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.