SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,891 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 231 of 501

CVESummaryPriorityPublished
CVE-2009-2173The LAN game feature in Carom3D 5.06 allows remote authenticated users to cause a denial of service (application hang) via a crafted HTTP request to TCP port 28012.EXPLOIT ✓LOW 3.5EPSS 1.95%23 June 2009
CVE-2009-2172Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.16%23 June 2009
CVE-2009-2169Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows remote attackers to create and overwrite arbitrary files via a URL argument to the FtpConnect argument…EXPLOIT ✓HIGH 9.3EPSS 4.50%22 June 2009
CVE-2009-2168cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are incorrect, which allows remote attackers to bypass authentication by providing arbitrary username and…EXPLOIT ✓CRITICAL 9.8EPSS 11.8%22 June 2009
CVE-2009-2167Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.95%22 June 2009
CVE-2009-2166Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.EXPLOIT ✓MEDIUM 5.0EPSS 3.19%22 June 2009
CVE-2009-2164Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the code parameter to activate.php or (2) the dest parameter to index.php.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 0.95%22 June 2009
CVE-2009-2163Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remote attackers to inject arbitrary web script or HTML via the sc_error parameter.EXPLOIT ✓MEDIUM 4.3EPSS 2.99%22 June 2009
CVE-2008-6834Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 10.0EPSS 4.04%22 June 2009
CVE-2008-6833Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 10.0EPSS 8.56%22 June 2009
CVE-2009-2161Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.1EPSS 2.43%22 June 2009
CVE-2009-2160TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function; and allows remote attackers to (2) obtain other potentially sensitive information via a…EXPLOIT ✓MEDIUM 5.0EPSS 3.20%22 June 2009
CVE-2009-2159backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a direct request and then retrieving a .gz file from backups/.EXPLOIT ✓MEDIUM 6.4EPSS 2.70%22 June 2009
CVE-2009-2158account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a brute-force attack.EXPLOIT ✓HIGH 7.5EPSS 4.52%22 June 2009
CVE-2009-2157Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitrary SQL commands via (1) the origmsg parameter to account-inbox.php; the categ parameter to (2) delreq.php and (3) admin-delreq.php;…EXPLOIT ✓MEDIUM 6.5EPSS 1.73%22 June 2009
CVE-2009-2156Multiple cross-site scripting (XSS) vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Title field to requests.php, related to viewrequests.php; and (2) the Torrent Name…EXPLOIT ✓LOW 3.5EPSS 1.52%22 June 2009
CVE-2009-2154SQL injection vulnerability in admin/login.php in Impleo Music Collection 2.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.87%22 June 2009
CVE-2009-2153Cross-site scripting (XSS) vulnerability in index.php in Impleo Music Collection 2.0 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.26%22 June 2009
CVE-2009-2152SQL injection vulnerability in a_index.php in AdaptWeb 0.9.2 allows remote attackers to execute arbitrary SQL commands via the CodigoDisciplina parameter in a TopicosCadastro1 action.EXPLOIT ✓HIGH 7.5EPSS 0.95%22 June 2009
CVE-2009-2151Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.71%22 June 2009
CVE-2009-2150Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack the authentication of arbitrary users for requests that terminate a session via login/logout.php, and might allow remote attackers to…EXPLOIT ✓MEDIUM 6.8EPSS 0.89%22 June 2009
CVE-2009-2149Multiple cross-site scripting (XSS) vulnerabilities in Campus Virtual-LMS allow remote attackers to inject arbitrary web script or HTML via the (1) courseid parameter to enrolments/step1.php, or the (2) search or (3) siteid parameter to…EXPLOIT ✓MEDIUM 4.3EPSS 1.27%22 June 2009
CVE-2009-2148SQL injection vulnerability in news/index.php in Campus Virtual-LMS allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%22 June 2009
CVE-2009-2147SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 2.04%22 June 2009
CVE-2009-2146Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its…EXPLOIT ✓MEDIUM 6.0EPSS 21.5%22 June 2009
CVE-2009-2145Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the…EXPLOIT ✓MEDIUM 4.3EPSS 1.56%22 June 2009
CVE-2009-2142Multiple SQL injection vulnerabilities in admin/index.asp in Zip Store Chat 4.0 and 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) senha parameters.EXPLOIT ✓HIGH 7.5EPSS 1.01%22 June 2009
CVE-2009-2141Multiple cross-site scripting (XSS) vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to inject arbitrary web script or HTML via (1) the returnto parameter to makepoll.php, (2) the returnto parameter in a delete action to polls.php, or the…EXPLOIT ✓MEDIUM 4.3EPSS 1.48%22 June 2009
CVE-2009-2138Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the returnto parameter to login.php or (2) the returnto parameter in a delete action to…EXPLOIT ✓MEDIUM 4.3EPSS 1.26%19 June 2009
CVE-2009-2134pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url parameter, which reveals the installation path in an error message.EXPLOIT ✓MEDIUM 5.0EPSS 2.50%19 June 2009
CVE-2009-2133Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrary web script or HTML via the (1) menu or (2) sort parameter to pivot/index.php, (3) the value of a check array parameter in a delete…EXPLOIT ✓MEDIUM 4.3EPSS 4.09%19 June 2009
CVE-2009-2132Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.10%19 June 2009
CVE-2009-2131Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member.php, and then posting a comment associated with a…EXPLOIT ✓LOW 3.5EPSS 1.60%19 June 2009
CVE-2009-2130Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.ei in inc/ via a direct request.EXPLOIT ✓MEDIUM 5.0EPSS 2.27%19 June 2009
CVE-2009-2129Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authentication of arbitrary users via a logout action.EXPLOIT ✓MEDIUM 6.8EPSS 0.89%19 June 2009
CVE-2009-2127Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.22%19 June 2009
CVE-2009-2124Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.35%19 June 2009
CVE-2009-2123Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/login.ei, reachable through login.php; and the (3) id…EXPLOIT ✓HIGH 7.5EPSS 1.01%19 June 2009
CVE-2009-2122SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 2.74%19 June 2009
CVE-2009-0961The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another alert appears, which might allow remote attackers to force the iPhone to place a call without user…EXPLOIT ×3 ✓MEDIUM 5.0EPSS 6.38%19 June 2009
CVE-2009-2120Multiple SQL injection vulnerabilities in TekBase All-in-One 3.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) ids parameter to admin.php, the (2) y parameter to members.php, and other unspecified vectors.EXPLOIT ✓MEDIUM 6.5EPSS 1.78%18 June 2009
CVE-2009-2117uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username.EXPLOIT ✓HIGH 7.5EPSS 2.40%18 June 2009
CVE-2009-2116Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a ..EXPLOIT ✓MEDIUM 4.0EPSS 2.39%18 June 2009
CVE-2009-2114Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web script or HTML via the (1) mgroup, (2) mgr, (3) objtype, (4) id, and (5) dir parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%18 June 2009
CVE-2009-2113Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.php and the (2) hash parameter to song.php.EXPLOIT ✓HIGH 7.5EPSS 2.56%18 June 2009
CVE-2009-2112Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _FORUM[settings_design_style] parameter.EXPLOIT ✓HIGH 7.5EPSS 5.69%18 June 2009
CVE-2009-2111Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and (2) location parameter.EXPLOIT ✓HIGH 10.0EPSS 3.75%18 June 2009
CVE-2009-2110Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.6EPSS 8.45%18 June 2009
CVE-2009-2109Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified…EXPLOIT ✓MEDIUM 5.0EPSS 9.48%18 June 2009
CVE-2009-2108git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request containing extra unrecognized arguments.EXPLOIT ✓MEDIUM 5.0EPSS 5.82%18 June 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.