Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,891 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 229 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-2365 | SQL injection vulnerability in login.asp in DataCheck Solutions GalleryPal FE 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | EXPLOITHIGH 7.5EPSS 0.95% | 8 July 2009 |
| CVE-2009-2364 | Stack-based buffer overflow in Mp3-Nator 2.0 allows remote attackers to execute arbitrary code via (1) a long string in a .plf file and (2) a long string in the listdata.dat file, possibly related to a track entry. | EXPLOIT ×3 ✓HIGH 9.3EPSS 10.1% | 8 July 2009 |
| CVE-2009-2363 | Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls playlist file with a playlist entry containing a long File1 argument. | EXPLOIT ×3 ✓HIGH 9.3EPSS 6.10% | 8 July 2009 |
| CVE-2009-2362 | Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.0.0.215 allows remote attackers to execute arbitrary code via a long string in a (1) .lst or (2) .m3u playlist file. | EXPLOIT ×3 ✓HIGH 9.3EPSS 7.23% | 8 July 2009 |
| CVE-2009-2361 | SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter. | EXPLOIT ✓HIGH 7.5EPSS 5.21% | 8 July 2009 |
| CVE-2009-2360 | Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 5.06% | 8 July 2009 |
| CVE-2009-2352 | Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2)… | EXPLOIT ✓MEDIUM 4.3EPSS 2.05% | 7 July 2009 |
| CVE-2009-2350 | Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header… | EXPLOIT ✓MEDIUM 4.3EPSS 14.4% | 7 July 2009 |
| CVE-2008-0015 | Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability | KEVEXPLOIT ×2 ✓HIGH 8.8EPSS 76.7% | 7 July 2009 |
| CVE-2009-2344 | The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified… | EXPLOIT ✓HIGH 9.0EPSS 9.25% | 7 July 2009 |
| CVE-2009-2341 | SQL injection vulnerability in albumdetail.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the albumid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 7 July 2009 |
| CVE-2009-2340 | SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtUserName (aka User Name) parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 7 July 2009 |
| CVE-2009-2339 | SQL injection vulnerability in index.php in Rentventory allows remote attackers to execute arbitrary SQL commands via the product parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 7 July 2009 |
| CVE-2009-2338 | Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 7 July 2009 |
| CVE-2009-2337 | SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the spam_id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.23% | 7 July 2009 |
| CVE-2008-6853 | SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arbitrary SQL commands via the PollID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 7 July 2009 |
| CVE-2008-6852 | SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 7 July 2009 |
| CVE-2008-6851 | SQL injection vulnerability in page.php in PHP Link Directory (phpLD) 3.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the name parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 0.88% | 7 July 2009 |
| CVE-2008-6849 | Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a via a link that is listed by… | EXPLOIT ✓MEDIUM 6.8EPSS 2.33% | 7 July 2009 |
| CVE-2008-6848 | Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary web script or HTML via the category parameter in a select action. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.75% | 7 July 2009 |
| CVE-2009-2333 | Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 5.93% | 5 July 2009 |
| CVE-2009-2332 | CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to index.php or (2) a nonexistent folder name in the id parameter to admin/admin_delete.php, which reveals the installation path in an… | EXPLOIT ✓MEDIUM 5.0EPSS 2.43% | 5 July 2009 |
| CVE-2009-2331 | Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary PHP code (1) into settings.php via the menu parameter to admin_settings.php or (2) into a content/=NUMBER.php file via the title… | EXPLOIT ✓HIGH 7.5EPSS 2.40% | 5 July 2009 |
| CVE-2009-2330 | Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in CMS Chainuk 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the menu parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.33% | 5 July 2009 |
| CVE-2009-2329 | KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin/head.php, or (2) voting_diagram.php, (3) voting.php, (4) topics_search.php, (5) topics_list.php, (6) top_part.php, (7)… | EXPLOIT ✓MEDIUM 5.0EPSS 2.22% | 5 July 2009 |
| CVE-2009-2328 | admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitrary accounts and conduct SQL injection attacks via the del_user_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 5 July 2009 |
| CVE-2009-2327 | Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the v_variant1 parameter. | EXPLOIT ✓LOW 3.5EPSS 2.54% | 5 July 2009 |
| CVE-2009-2326 | Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) an enter_parol cookie to index.php in an auto action or (2) the topic parameter to message.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 5 July 2009 |
| CVE-2009-2325 | Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.01% | 5 July 2009 |
| CVE-2009-2265 | Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild… | EXPLOIT ×2 ✓HIGH 7.5EPSS 83.7% | 5 July 2009 |
| CVE-2009-2313 | Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.39% | 2 July 2009 |
| CVE-2009-2311 | SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to execute arbitrary SQL commands via the userID parameter in the RGalleryUserGallery page to index.php, a different vector than… | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 2 July 2009 |
| CVE-2009-2310 | SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 2 July 2009 |
| CVE-2009-2309 | SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via the tag parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 2 July 2009 |
| CVE-2009-2308 | Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote attackers to execute arbitrary SQL commands via the (1) in or (2) out parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.18% | 2 July 2009 |
| CVE-2009-2307 | SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter in a viewrecords action to modules.php. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 2 July 2009 |
| CVE-2009-2306 | The ARD-9808 DVR card security camera stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing usernames and passwords via a direct request for dvr.ini. | EXPLOIT ✓HIGH 7.5EPSS 2.08% | 2 July 2009 |
| CVE-2009-2305 | The ARD-9808 DVR card security camera allows remote attackers to cause a denial of service via a long URI composed of //.\ (slash slash dot backslash) sequences. | EXPLOIT ✓HIGH 7.8EPSS 2.34% | 2 July 2009 |
| CVE-2009-2302 | Cross-site scripting (XSS) vulnerability in index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.73% | 2 July 2009 |
| CVE-2008-6847 | Cross-site scripting (XSS) vulnerability in Employee/emp_login.asp in Pre ASP Job Board allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 2 July 2009 |
| CVE-2008-6844 | The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote attackers to gain privileges as other users via modified ContentObjectAttribute_data_user_login_30,… | EXPLOIT ✓HIGH 7.5EPSS 2.97% | 2 July 2009 |
| CVE-2008-6843 | Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 6.70% | 2 July 2009 |
| CVE-2008-6842 | Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.86% | 2 July 2009 |
| CVE-2009-2293 | Optimum Web Design Tutorial Share 3.5.0 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the usernamed cookie parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 1 July 2009 |
| CVE-2009-2290 | SQL injection vulnerability in the Boy Scout Advancement (com_bsadv) component 0.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) account or (2) event task to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 1 July 2009 |
| CVE-2009-2289 | Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade Script 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the q parameter in a gamelist action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 1 July 2009 |
| CVE-2009-2288 | statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters. | EXPLOIT ×3 ✓HIGH 7.5EPSS 83.5% | 1 July 2009 |
| CVE-2009-2286 | Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a long declaration in a .xbm file. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.08% | 1 July 2009 |
| CVE-2009-2285 | Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 8.95% | 1 July 2009 |
| CVE-2009-2276 | SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the out parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 1 July 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.