SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,891 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 228 of 501

CVESummaryPriorityPublished
CVE-2008-6858Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.EXPLOIT ✓HIGH 7.5EPSS 2.51%14 July 2009
CVE-2008-6857Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.EXPLOIT ✓HIGH 7.5EPSS 2.59%14 July 2009
CVE-2008-6856Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.EXPLOIT ✓HIGH 7.5EPSS 2.54%14 July 2009
CVE-2008-6855Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.EXPLOIT ✓HIGH 7.5EPSS 2.51%14 July 2009
CVE-2008-6854Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.EXPLOIT ✓HIGH 7.5EPSS 2.54%14 July 2009
CVE-2009-2450The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Personal Firewall 3.5 before 3.5.0.14, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\OAmon…EXPLOIT ✓HIGH 7.2EPSS 0.77%13 July 2009
CVE-2009-2446Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other…EXPLOIT ✓HIGH 8.5EPSS 10.6%13 July 2009
CVE-2009-2443Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.EXPLOIT ✓MEDIUM 5.0EPSS 3.21%13 July 2009
CVE-2009-2442Cross-site scripting (XSS) vulnerability in public/index.php in Linea21 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a resultats-recherche action.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%13 July 2009
CVE-2009-2441Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%13 July 2009
CVE-2009-2440Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.66%13 July 2009
CVE-2009-2439Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.00%13 July 2009
CVE-2009-2438Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remote attackers to inject arbitrary web script or HTML via the text parameter in a list action.EXPLOIT ✓MEDIUM 4.3EPSS 1.64%13 July 2009
CVE-2009-2437Multiple cross-site scripting (XSS) vulnerabilities in index.php in Rentventory 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka Login) and (2) password parameters in a login action.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%13 July 2009
CVE-2009-2436SQL injection vulnerability in page.php in Online Dating Software MyPHPDating 1.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%13 July 2009
CVE-2009-2433Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.EXPLOIT ✓MEDIUM 4.3EPSS 18.9%10 July 2009
CVE-2009-2335WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.EXPLOITMEDIUM 5.0EPSS 85.0%10 July 2009
CVE-2009-2334wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive…EXPLOIT ✓MEDIUM 4.9EPSS 6.26%10 July 2009
CVE-2009-2428Multiple SQL injection vulnerabilities in Tausch Ticket Script 3 allow remote attackers to execute arbitrary SQL commands via the (1) userid parameter to suchauftraege_user.php and the (2) descr parameter to vote.php; and other unspecified vectors.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%10 July 2009
CVE-2009-2427SQL injection vulnerability in co-profile.php in Jobbr 2.2.7 allows remote attackers to execute arbitrary SQL commands via the emp_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.95%10 July 2009
CVE-2009-2424Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.24%10 July 2009
CVE-2009-2423SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action.EXPLOIT ✓HIGH 7.5EPSS 1.08%10 July 2009
CVE-2009-2386Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.EXPLOIT ✓HIGH 9.3EPSS 5.12%10 July 2009
CVE-2009-1724Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors…EXPLOIT ✓MEDIUM 4.3EPSS 6.21%9 July 2009
CVE-2009-2419Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document…EXPLOIT ✓MEDIUM 4.3EPSS 9.07%9 July 2009
CVE-2009-2403Heap-based buffer overflow in SCMPX 1.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a .m3u playlist file.EXPLOIT ✓HIGH 9.3EPSS 6.99%9 July 2009
CVE-2009-2402SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a thread action, a different vector than CVE-2008-0355.EXPLOIT ✓HIGH 7.5EPSS 0.95%9 July 2009
CVE-2009-2401Cross-site scripting (XSS) vulnerability in PHPEcho CMS 2.0-rc3 allows remote attackers to inject arbitrary web script or HTML via a forum post.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%9 July 2009
CVE-2009-2400SQL injection vulnerability in the PHP (com_php) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%9 July 2009
CVE-2009-2399PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.69%9 July 2009
CVE-2009-2398Directory traversal vulnerability in test/index.php in PHP-Sugar 0.80 allows remote attackers to read arbitrary files via a ..// (dot dot slash slash) in the t parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.81%9 July 2009
CVE-2009-2397Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.92%9 July 2009
CVE-2009-2396PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.EXPLOIT ✓HIGH 9.3EPSS 5.94%9 July 2009
CVE-2009-2395SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.EXPLOIT ✓HIGH 7.5EPSS 3.03%9 July 2009
CVE-2009-2394SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.92%9 July 2009
CVE-2009-2393admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to have an unknown impact via unspecified vectors.EXPLOIT ✓MEDIUM 6.5EPSS 2.06%9 July 2009
CVE-2009-2392SQL injection vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to execute arbitrary SQL commands via the tid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%9 July 2009
CVE-2009-2391Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to inject arbitrary web script or HTML via the tid parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%9 July 2009
CVE-2009-2390SQL injection vulnerability in the BookFlip (com_bookflip) component 2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.96%9 July 2009
CVE-2009-2389Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the…EXPLOIT ✓MEDIUM 6.8EPSS 0.85%9 July 2009
CVE-2009-2388SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtPassword parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.95%9 July 2009
CVE-2009-2385SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to…EXPLOIT ✓HIGH 7.5EPSS 0.97%8 July 2009
CVE-2009-2384Buffer overflow in amp.exe in Brothersoft PEamp 1.02b allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file.EXPLOIT ✓HIGH 9.3EPSS 5.86%8 July 2009
CVE-2009-2383SQL injection vulnerability in BTE_RW_webajax.php in the Related Sites plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the guid parameter.EXPLOIT ✓HIGH 7.5EPSS 2.80%8 July 2009
CVE-2009-2382admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin cookie to LOGGEDIN.EXPLOIT ✓CRITICAL 9.8EPSS 6.20%8 July 2009
CVE-2009-2379Directory traversal vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 5.56%8 July 2009
CVE-2009-2378PHP remote file inclusion vulnerability in formmailer.admin.inc.php in Jax FormMailer 3.0.0 allows remote attackers to execute arbitrary PHP code via a URL in the BASE_DIR[jax_formmailer] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.10%8 July 2009
CVE-2009-2377Buffer overflow in the Avax Vector ActiveX control in avPreview.ocx in AVAX-software Avax Vector ActiveX 1.3 allows remote attackers to cause a denial of service (application crash) via a long PrinterName property.EXPLOIT ✓MEDIUM 4.3EPSS 1.89%8 July 2009
CVE-2009-2375Stack-based buffer overflow in Photo DVD Maker 8.02, and possibly earlier versions, allows remote attackers to execute arbitrary code via a long File_Name parameter in a .pdm file.EXPLOIT ✓HIGH 9.3EPSS 5.13%8 July 2009
CVE-2009-2366SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers to execute arbitrary SQL commands via the (1) password parameter in 1.1 and (2) p_password parameter in 1.5.EXPLOIT ✓HIGH 7.5EPSS 1.15%8 July 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.