Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,891 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 230 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-2275 | Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.72% | 1 July 2009 |
| CVE-2009-2269 | SQL injection vulnerability in Empire CMS 5.1 allows remote attackers to execute arbitrary SQL commands via the bid parameter to the default URI under e/tool/gbook/. | EXPLOIT ✓HIGH 7.5EPSS 0.89% | 1 July 2009 |
| CVE-2009-0689 | Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD… | EXPLOIT ×11 ✓MEDIUM 6.8EPSS 28.1% | 1 July 2009 |
| CVE-2008-6841 | PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_dbquery) component 1.4.1.1 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the… | EXPLOIT ✓HIGH 7.5EPSS 5.72% | 1 July 2009 |
| CVE-2008-6840 | Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[pear_dir] parameter to (a) Mail/RFC822.php, (b) Net/Socket.php, (c) XML/Parser.php, (d) XML/Tree.php,… | EXPLOIT ×13 ✓MEDIUM 6.8EPSS 1.94% | 1 July 2009 |
| CVE-2009-2263 | Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.44% | 30 June 2009 |
| CVE-2009-2261 | PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .zip archive with a .txt file whose name contains | (pipe) characters and a command. | EXPLOIT ×2 ✓HIGH 9.3EPSS 41.4% | 30 June 2009 |
| CVE-2009-2259 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 30 June 2009 |
| CVE-2009-2258 | Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary directories via a .. | EXPLOIT ✓HIGH 7.8EPSS 6.69% | 30 June 2009 |
| CVE-2009-2257 | The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconfig.html, and (2) stattbl.htm, (3) modemmenu.htm, (4) onload.htm, (5)… | EXPLOIT ✓HIGH 7.8EPSS 7.18% | 30 June 2009 |
| CVE-2009-2256 | The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an HTTP POST request to cgi-bin/firmwarecfg. | EXPLOIT ✓HIGH 7.8EPSS 7.44% | 30 June 2009 |
| CVE-2009-2255 | Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to execute arbitrary code by uploading a .php file via the record_company_image parameter in conjunction with… | EXPLOIT ✓MEDIUM 6.8EPSS 31.0% | 30 June 2009 |
| CVE-2009-2254 | Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute arbitrary SQL commands via the query_string parameter in an execute action, in conjunction with a… | EXPLOIT ✓HIGH 7.5EPSS 10.9% | 30 June 2009 |
| CVE-2009-2243 | SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the sortby parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 27 June 2009 |
| CVE-2009-2242 | SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the order parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 27 June 2009 |
| CVE-2009-2241 | Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 27 June 2009 |
| CVE-2009-2239 | SQL injection vulnerability in the (1) casinobase (com_casinobase), (2) casino_blackjack (com_casino_blackjack), and (3) casino_videopoker (com_casino_videopoker) components 0.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via… | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 27 June 2009 |
| CVE-2009-2238 | Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXReady Registration Manager 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then… | EXPLOIT ✓MEDIUM 6.8EPSS 3.51% | 27 June 2009 |
| CVE-2009-2236 | SQL injection vulnerability in yad-admin/login.php in Your Article Directory allows remote attackers to execute arbitrary SQL commands via the txtAdminEmail parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 June 2009 |
| CVE-2009-2235 | SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 27 June 2009 |
| CVE-2009-2234 | Multiple SQL injection vulnerabilities in admin.php in VICIDIAL Call Center Suite 2.0.5-173 allow remote attackers to execute arbitrary SQL commands via the (1) Username parameter ($PHP_AUTH_USER) and (2) Password parameter ($PHP_AUTH_PW). | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 27 June 2009 |
| CVE-2008-6839 | Multiple cross-site scripting (XSS) vulnerabilities in TGS Content Management 0.3.2r2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg and (2) goodmsg parameters to (a) login.php and (b) index.php, and the (3) dir and (4) id… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.46% | 27 June 2009 |
| CVE-2008-6838 | Cross-site scripting (XSS) vulnerability in search.php in Zoph 0.7.2.1 allows remote attackers to inject arbitrary web script or HTML via the _off parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.75% | 27 June 2009 |
| CVE-2008-6837 | SQL injection vulnerability in Zoph 0.7.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different issue than CVE-2008-3258. | EXPLOIT ✓HIGH 7.5EPSS 2.37% | 27 June 2009 |
| CVE-2009-2233 | The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the awse_logged cookie to 1. | EXPLOIT ✓HIGH 7.5EPSS 2.63% | 26 June 2009 |
| CVE-2009-2231 | MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie. | EXPLOIT ✓HIGH 7.5EPSS 2.63% | 26 June 2009 |
| CVE-2009-2230 | SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 26 June 2009 |
| CVE-2009-2229 | Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.53% | 26 June 2009 |
| CVE-2009-2228 | Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS allows remote attackers to inject arbitrary web script or HTML via the url parameter in a redirect action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 26 June 2009 |
| CVE-2009-2227 | Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request to TCP port 19810. | EXPLOIT ×3 ✓HIGH 10.0EPSS 68.6% | 26 June 2009 |
| CVE-2009-1394 | Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand named pipe. | EXPLOIT ✓HIGH 9.3EPSS 33.3% | 26 June 2009 |
| CVE-2009-2223 | Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 9.3EPSS 3.76% | 26 June 2009 |
| CVE-2009-2220 | Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and possibly execute arbitrary files via directory traversal sequences in the… | EXPLOIT ✓MEDIUM 5.1EPSS 1.97% | 26 June 2009 |
| CVE-2009-2219 | Multiple cross-site scripting (XSS) vulnerabilities in phpCollegeExchange 0.1.5c allow remote attackers to inject arbitrary web script or HTML via the (1) _SESSION[handle] parameter to (a) home.php, (b) books/allbooks.php, or (c) books/home.php; or the… | EXPLOIT ✓MEDIUM 4.3EPSS 1.22% | 25 June 2009 |
| CVE-2009-2218 | Multiple PHP remote file inclusion vulnerabilities in phpCollegeExchange 0.1.5c, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the home parameter to (1) i_head.php, (2) i_nav.php, (3) user_new_2.php,… | EXPLOIT ✓MEDIUM 6.8EPSS 1.57% | 25 June 2009 |
| CVE-2009-2216 | Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=advanced request. | EXPLOIT ✓MEDIUM 6.1EPSS 1.52% | 25 June 2009 |
| CVE-2009-1203 | WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login screen from the login screens it produces for third-party (1) FTP and (2) CIFS servers, which makes it… | EXPLOIT ✓MEDIUM 6.0EPSS 3.78% | 25 June 2009 |
| CVE-2009-1201 | Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site… | EXPLOIT ✓MEDIUM 4.3EPSS 8.83% | 25 June 2009 |
| CVE-2009-2209 | SQL injection vulnerability in rscms_mod_newsview.php in RS-CMS 2.1 allows remote attackers to execute arbitrary SQL commands via the key parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 25 June 2009 |
| CVE-2009-1886 | Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename. | EXPLOIT ✓HIGH 9.3EPSS 12.2% | 25 June 2009 |
| CVE-2009-2184 | Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to read arbitrary files via an encoded "/" (slash) in the file parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.75% | 23 June 2009 |
| CVE-2009-2183 | Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possibly execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 5.69% | 23 June 2009 |
| CVE-2009-2182 | Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[g_campsiteDir] parameter to (1) ad_popup.php, (2) camp_html.php, (3) init_content.php, (4) logout.php,… | EXPLOIT ✓MEDIUM 6.8EPSS 1.72% | 23 June 2009 |
| CVE-2009-2181 | Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the listbasedir parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.39% | 23 June 2009 |
| CVE-2009-2180 | Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. | EXPLOIT ✓MEDIUM 5.0EPSS 6.14% | 23 June 2009 |
| CVE-2009-2179 | SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands via the sform[day] parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 23 June 2009 |
| CVE-2009-2178 | Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.25% | 23 June 2009 |
| CVE-2009-2177 | code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary files via a "....//" (dot dot) in the s parameter, which is collapsed into a… | EXPLOIT ✓MEDIUM 6.8EPSS 4.19% | 23 June 2009 |
| CVE-2009-2176 | Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) list parameter to… | EXPLOIT ✓HIGH 7.5EPSS 7.39% | 23 June 2009 |
| CVE-2009-2174 | GUPnP 0.12.7 allows remote attackers to cause a denial of service (crash) via an empty (1) subscription or (2) control message. | EXPLOIT ✓MEDIUM 5.0EPSS 4.88% | 23 June 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.