Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,891 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 232 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-2107 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remote attackers to inject arbitrary web script or HTML via event handlers such as onmouseover in the (1) search or (2) tag parameters;… | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 17 June 2009 |
| CVE-2009-2102 | SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote attackers to execute arbitrary SQL commands via the fileid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.04% | 17 June 2009 |
| CVE-2009-2101 | Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote attackers to delete arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.92% | 17 June 2009 |
| CVE-2009-2100 | Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php. | EXPLOIT ✓MEDIUM 5.0EPSS 8.23% | 17 June 2009 |
| CVE-2009-2099 | SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in an xml action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 17 June 2009 |
| CVE-2009-2098 | SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 17 June 2009 |
| CVE-2009-2096 | SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute arbitrary SQL commands via the itemnr parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 17 June 2009 |
| CVE-2009-2095 | PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the top parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.74% | 17 June 2009 |
| CVE-2009-1391 | Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a… | EXPLOIT ✓MEDIUM 6.8EPSS 7.44% | 16 June 2009 |
| CVE-2009-2011 | Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute… | EXPLOIT ×2 ✓HIGH 9.3EPSS 40.2% | 16 June 2009 |
| CVE-2009-2081 | Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 2.52% | 16 June 2009 |
| CVE-2009-2080 | admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig action or (2) change the administrator's password via the id parameter in… | EXPLOIT ✓HIGH 7.5EPSS 2.69% | 16 June 2009 |
| CVE-2009-2044 | Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via a URI for a large GIF image in the BACKGROUND attribute of a BODY element. | EXPLOIT ✓MEDIUM 4.3EPSS 5.89% | 12 June 2009 |
| CVE-2009-2043 | nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to interaction with TinyMCE. | EXPLOIT ✓MEDIUM 4.3EPSS 4.36% | 12 June 2009 |
| CVE-2009-1839 | Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a… | EXPLOIT ✓MEDIUM 5.4EPSS 7.12% | 12 June 2009 |
| CVE-2009-1834 | Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as… | EXPLOIT ✓MEDIUM 4.3EPSS 3.23% | 12 June 2009 |
| CVE-2009-2040 | admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative accounts via a manage_admin action in a direct request. | EXPLOIT ✓HIGH 7.5EPSS 2.93% | 12 June 2009 |
| CVE-2009-2037 | Multiple directory traversal vulnerabilities in Online Grades & Attendance 3.2.5 and earlier, and possibly 3.2.6, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.12% | 12 June 2009 |
| CVE-2009-2036 | SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 12 June 2009 |
| CVE-2009-2034 | SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authenticated users to execute arbitrary SQL commands via the original parameter. | EXPLOIT ✓MEDIUM 6.0EPSS 0.82% | 12 June 2009 |
| CVE-2009-2033 | Cross-site scripting (XSS) vulnerability in index.php in Yogurt 0.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 12 June 2009 |
| CVE-2009-1140 | Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote attackers to… | EXPLOIT ✓HIGH 7.1EPSS 24.8% | 10 June 2009 |
| CVE-2009-1122 | The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS… | EXPLOIT ✓HIGH 7.5EPSS 98.4% | 10 June 2009 |
| CVE-2009-1699 | The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via… | EXPLOIT ✓HIGH 7.5EPSS 29.1% | 10 June 2009 |
| CVE-2009-0565 | Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats… | EXPLOIT ×2HIGH 9.3EPSS 40.5% | 10 June 2009 |
| CVE-2009-1684 | Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via an event handler that triggers… | EXPLOIT ✓MEDIUM 4.3EPSS 8.66% | 10 June 2009 |
| CVE-2009-1535 | The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary… | EXPLOIT ×2 ✓HIGH 7.5EPSS 98.1% | 10 June 2009 |
| CVE-2009-2025 | admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values. | EXPLOIT ✓HIGH 7.5EPSS 2.61% | 9 June 2009 |
| CVE-2009-2024 | Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain usernames and passwords via a direct request for zHk8dEes3.txt. | EXPLOIT ✓MEDIUM 5.0EPSS 2.29% | 9 June 2009 |
| CVE-2009-2023 | SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the current_currency parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.95% | 9 June 2009 |
| CVE-2009-2022 | fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain sensitive information via a direct request for _fipsdb/db.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 5.16% | 9 June 2009 |
| CVE-2009-2021 | SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL commands via the category parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 9 June 2009 |
| CVE-2009-2020 | Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arbitrary web script or HTML via the nid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.27% | 9 June 2009 |
| CVE-2009-2019 | SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 9 June 2009 |
| CVE-2009-2018 | SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authuserid parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.95% | 9 June 2009 |
| CVE-2009-2017 | SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 9 June 2009 |
| CVE-2009-2016 | SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 9 June 2009 |
| CVE-2009-2015 | Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 6.51% | 9 June 2009 |
| CVE-2009-2014 | SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the classid parameter in a showclass action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 9 June 2009 |
| CVE-2009-2013 | SQL injection vulnerability in bin/aps_browse_sources.php in Frontis 3.9.01.24 allows remote attackers to execute arbitrary SQL commands via the source_class parameter in a browse_classes action. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 9 June 2009 |
| CVE-2009-0949 | The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler… | EXPLOIT ✓HIGH 7.5EPSS 19.6% | 9 June 2009 |
| CVE-2009-2010 | Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) thread parameter to messageboard.php, (2) member parameter to… | EXPLOIT ✓MEDIUM 6.5EPSS 0.90% | 8 June 2009 |
| CVE-2009-2003 | Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal and (2) cookname cookies to "admin." | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.51% | 8 June 2009 |
| CVE-2008-6829 | VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (forward slash, backward slash, forward slash). | EXPLOIT ✓MEDIUM 5.0EPSS 37.6% | 8 June 2009 |
| CVE-2008-6826 | dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter, as demonstrated using the (1) advert_top.htm or (2) advert_login.htm pages. | EXPLOIT ✓HIGH 10.0EPSS 4.60% | 8 June 2009 |
| CVE-2009-1961 | The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of… | EXPLOIT ✓MEDIUM 4.7EPSS 0.59% | 8 June 2009 |
| CVE-2009-1960 | inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. | EXPLOIT ×2 ✓HIGH 9.3EPSS 23.2% | 8 June 2009 |
| CVE-2009-1959 | Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow. | EXPLOIT ✓MEDIUM 5.0EPSS 8.38% | 8 June 2009 |
| CVE-2009-1955 | The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a… | EXPLOIT ✓HIGH 7.5EPSS 53.0% | 8 June 2009 |
| CVE-2009-1952 | Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 0.89% | 5 June 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.